| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise,
OT, or Medical)
Device Security X subscription
|
Configure scope-based access control (SBAC) for Device Security in
Identity & Access Management (IAM) in Strata Cloud Manager, not within
Device Security itself. The workflow has two parts: creating a scope that
defines a set of sites, and then assigning that scope to users. Scope assignments
take effect after a user logs out and then logs back in.
Before you configure SBAC, verify the following:
You manage your Device Security solution in Strata Cloud Manager.
You have the Superuser role in Strata Cloud Manager. Only
superuser administrators can create, edit, and delete scopes
and assign them to users.
You've fully configured your organization's
sites and site groups
in
Device Security. Scopes depend on sites from this organization tree,
so having sites reflect the levels of visiblity users need for their roles
ensures that scopes grant proper access.