Prisma SD-WAN
Create Custom Roles
Table of Contents
Expand All
|
Collapse All
Prisma SD-WAN Docs
-
-
-
- CloudBlade Integrations
- CloudBlades Integration with Prisma Access
-
-
-
-
- 6.5
- 6.4
- 6.3
- 6.2
- 6.1
- 5.6
- New Features Guide
- On-Premises Controller
- Prisma SD-WAN CloudBlades
- Prisma Access CloudBlade Cloud Managed
- Prisma Access CloudBlade Panorama Managed
Create Custom Roles
Learn how to create custom roles before assigning a role to an administrator using System
Administration.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Create custom roles before assigning the role to an administrator using the System
Administration screen. You can create them by assembling a set of
system permissions or by adding or removing permissions from system roles.
- Select ManageSystemAccess ManagementUser AccessCustom RolesCreate Custom Roles.Add a Name and a Description for the role.Add permissions. The permissions are split between web interface and API.If you select API: Any permissions that you had set using Web Interface are visible. You can't remove them from here, but you can remove them by changing them in Web Interface.
- Select Add Permissions to open the permissions modal. Permissions are listed in a hierarchy.Expand Prisma SD-WAN and search for relevant API’s. Type in an API resource to search. Type in an API resource to search. For eg. to modify Path policies, search for “networkpolicysets” You can find the API resources from Unified SASE SD-WAN APIs.To allow or disallow specific actions for each resource, you'll need to expand each one and explicitly select "get," "post," "put," "delete," and "query" options. Simply choosing a resource from the initial screen won't be enough, as each resource offers both "allow" and "disallow" sub-options for fine-grained control.To manage permissions, explicitly select the "put," "post," and "delete" allow options for specific API actions, such as creating or deleting Path Policy sets (networkpolicysets). You do not need to select "get" because a base role like "view_only" will automatically allow get actions.Click Save the new custom role is created.
Related CLIs
- config banner
- debug log agent eal file log
- debug logging facility
- debug logs dump
- debug logs follow
- debug logs tail
- debug process
- debug reboot
- debug service link logging
- debug time sync
- file export
- file remove
- file space available
- file tailf log
- file view log
- inspect certificate
- inspect cgnx infra role
- inspect connection
- inspect process status
- inspect switch mac address table
- dump auth config
- dump auth status
- dump banner config
- dump device accessconfig
- dump device conntrack count
- dump device date
- dump device Info
- dump device status
- dump radius config
- dump radius statistics
- dump radius status
- dump sensor type
- dump sensor type summary
- dump time config
- dump time log
- dump time status
- dump troubleshoot message
- clear switch mac address entries
- clear device account login