Role-Based Access Control for Secure Agentless Access
Focus
Focus
Prisma Access

Role-Based Access Control for Secure Agentless Access

Table of Contents

Role-Based Access Control for Secure Agentless Access

Control who can view, create, modify, or delete Secure Agentless Access configurations by assigning granular permissions through predefined or custom roles.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access license with a Mobile User subscription
  • Secure Agentless Access add-on license
Role-based access control (RBAC) for Secure Agentless Access lets you control who can view, create, modify, or delete Secure Agentless Access configurations in Strata Cloud Manager. By assigning granular permissions through custom roles, you ensure that users can perform only the tasks necessary for their job without granting unnecessary privileges across other features.
To access Secure Agentless Access, users must have role assignments in both All Apps & Services and Cloud Identity Engine (CIE). If either assignment is missing, Secure Agentless Access is not visible to the user.
  • All Apps & Services: A predefined role that includes Secure Agentless Access permissions OR a custom role configured with Secure Agentless Access access.
  • Cloud Identity Engine (CIE): Deployment Administrator, Multitenant Super User, Super User, or View Only Administrator.
Both role assignments are required. The All Apps & Services role controls what the user can do within Secure Agentless Access, while the CIE role provides the underlying identity infrastructure access needed for the feature to function. Without the CIE role assignment, Secure Agentless Access does not appear in the navigation regardless of the All Apps & Services role.
Existing predefined roles now include Secure Agentless Access permissions automatically. You do not need to create custom roles if the predefined permissions meet your needs.
RoleSecure Agentless Access Permissions
Security AdministratorFull read and write access
Super UserFull read and write access
Multitenant Super UserFull read and write access
View Only AdministratorRead-only access
When you need more control than predefined roles provide, create a custom role with granular Secure Agentless Access permissions. For each functional area, you can assign one of three permission levels: Read Write, Read Only, or No Access. For example, a role might allow users to view application configurations and monitor access activity without being able to modify application settings or policies.

Add Custom Role

  1. In Strata Cloud Manager, select Identity & Access.
  2. Select Custom Roles.
  3. Select Web UIConfigurationSecure Agentless Access.
  4. For each functional area, choose the permission level (Read Write, Read Only, or No Access).
  5. Save the role and assign it to the appropriate users.
When a user has multiple roles assigned, Strata Cloud Manager applies the union of those roles: the effective permission on each area is the most permissive level granted by any assigned role. A user assigned No Access on a functional area does not see that area in the Secure Agentless Access navigation.