Role-Based Access Control for Secure Agentless Access
Control who can view, create, modify, or delete Secure Agentless Access configurations by
assigning granular permissions through predefined or custom roles.
| Where Can I Use This? | What Do I Need? |
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
|
- Prisma Access license with a Mobile User subscription
- Secure Agentless Access add-on license
|
Role-based access control (RBAC) for Secure Agentless Access lets you control who can view,
create, modify, or delete Secure Agentless Access configurations in Strata Cloud Manager. By
assigning granular permissions through custom roles, you ensure that users can perform
only the tasks necessary for their job without granting unnecessary privileges across
other features.
To access Secure Agentless Access, users must have role assignments in both All Apps
& Services and Cloud Identity Engine (CIE). If either assignment is missing,
Secure Agentless Access is not visible to the user.
- All Apps & Services: A predefined role that includes Secure Agentless Access
permissions OR a custom role configured with Secure Agentless Access access.
- Cloud Identity Engine (CIE): Deployment Administrator, Multitenant Super
User, Super User, or View Only Administrator.
Both role assignments are required. The All Apps & Services role controls what the
user can do within Secure Agentless Access, while the CIE role provides the underlying
identity infrastructure access needed for the feature to function. Without the CIE role
assignment, Secure Agentless Access does not appear in the navigation regardless of the All
Apps & Services role.
Existing predefined roles now include Secure Agentless Access permissions automatically. You
do not need to create custom roles if the predefined permissions meet your needs.
| Role | Secure Agentless Access Permissions |
| Security Administrator | Full read and write access |
| Super User | Full read and write access |
| Multitenant Super User | Full read and write access |
| View Only Administrator | Read-only access |
When you need more control than predefined roles provide, create a
custom role with
granular
Secure Agentless Access permissions. For each functional area, you can assign one of
three permission levels: Read Write, Read Only, or No Access. For example, a role might
allow users to view application configurations and monitor access activity without being
able to modify application settings or policies.
Add Custom Role
- In Strata Cloud Manager, select .
- Select Custom Roles.
- Select .
- For each functional area, choose the permission level
(Read Write, Read Only, or
No Access).
- Save the role and assign it to the appropriate users.
When a user has multiple roles assigned, Strata Cloud Manager applies the union of
those roles: the effective permission on each area is the most permissive level
granted by any assigned role. A user assigned No Access on a functional area does
not see that area in the Secure Agentless Access navigation.