Manage Device Security Role Assignments
Focus
Focus
Device Security

Manage Device Security Role Assignments

Table of Contents

Manage Device Security Role Assignments

Assign, change, and revoke Device Security roles on users in Strata Cloud Manager to grant or update their permissions.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
One of the following subscriptions:
  • Device Security subscription
  • Precision AI bundle subscription
  • Device Security X subscription
Assign Device Security role-based access control roles to users in the Access Management panel in Strata Cloud Manager. A user can be assigned one predefined role, one or more custom roles, or a combination. When a user has multiple roles, Device Security applies the union of their permissions on each entity. Role assignments take effect after the user logs out of Strata Cloud Manager and logs back in.
Before you assign a Device Security role, verify the following:
  • You manage your Device Security solution in Strata Cloud Manager.
  • You have the Superuser role in Strata Cloud Manager. Only superuser administrators can assign or revoke Device Security roles.
  • You have at least one predefined or custom Device Security role ready to assign. To create a custom role, see Define Device Security Roles.
  1. In Strata Cloud Manager, select System SettingsIdentity & Access ManagementAccess Management.
    The Access Management panel shows the tenants available to you.
  2. Optional Select the tenant that you want to manage role assignments for.
  3. Select the users you want to assign a role to, and click Assign Roles.
    If you want to assign a role to a single user, you can find the user in the table, and click Edit (pencil icon) next to the user's name to bring up View Identity for that user. Select Assign Roles.
  4. Set the Apps & Services to Device Security and select the Role that you want to assign to these users.
    You can assign more than one role to a user. When a user has multiple roles, Device Security applies the union of the roles: the effective permission on each entity is the most permissive permission granted by any assigned role. To add more roles, repeat this step for each additional role.
    Service accounts inherit the roles you assign to them and are subject to the same per-entity permission checks as user accounts when making API calls.
  5. Save the role assignment.
  6. Ask the user to log out of Strata Cloud Manager and log back in.
    Role assignments do not take effect during an active session. The user must fully log out and log back in for Device Security to enforce the new role.
  7. Optional Change or revoke a role from a user by returning to System SettingsIdentity & Access ManagementAccess Management, selecting the user, and updating or removing the role.
    Ask the user to log out of Strata Cloud Manager and log back in for the change to take effect.
  8. Optional Verify the assignment by opening View Identity for the user and confirming the Device Security role is listed under Apps & Services.