| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Panorama or Strata Cloud Manager)
- Prisma Access (Managed by Panorama or Strata Cloud Manager)
|
- SaaS Security Inline license
- NGFW or Prisma Access license
Or any of the following licenses that include the SaaS Security Inline license:
|
Depending on the size of your organization and the number of SaaS apps you want to block, you can
create more than one administrative account with access to all capabilities within
SaaS Security web interface, including creating SaaS policy rule recommendations,
tagging SaaS apps, and accessing reports and analytics.
Permissions and Predefined Roles for SaaS Security Inline
Role-Based Access Control (RBAC) is a security mechanism in Strata Cloud Manager that restricts access to authorized users only. The
permissions described in the following table control access to various SaaS Security Inline views and capabilities.
Strata Cloud Manager includes predefined roles, which are essentially
"out-of-the-box" permission sets designed to cover the most common
administrative job functions. The following predefined roles offer full read
and write access or read-only access to SaaS Security Inline.
SaaS Inline Administrator
This predefined role grants full read and write access to all SaaS Security Inline features, including application
visibility, policy management, and integration functionality. This
role grants permission only to SaaS Security Inline and does
not include permissions for other applications and services within
Strata Cloud Manager.
Superuser
Provides read and write access to all available system-wide functions
across Strata Cloud Manager. This complete, unrestricted access
includes full read and write access to all SaaS Security Inline features.
View Only Administrator
Provides read-only access to all available system-wide functions
across Strata Cloud Manager. This read-only access includes
read-only access to SaaS Security Inline.
If you want to define more granular access permissions than what the
predefined roles provide, you can create a custom role. Custom roles enable
you to choose the specific permissions that you want to assign to the custom
role. For each permission, you can specify whether the role has full read
and write access, read-only access, or no access. The SaaS Security Inline permissions are grouped into a hierarchy.
Permissions that you set on a parent permission are inherited by the child
permissions, unless specifically overridden by the child permisison.
The following RBAC permissions control access to SaaS Security Inline
for the predefined roles and for any custom roles that you create.
The SaaS Security Inline Reports page
described in the following table is deprecated and will be removed. SaaS
Security reports are now available on the Reports page in Strata Cloud
Manager. In addition to the permissions for SaaS Security Inline
described in the following table, you can control access to Strata Cloud
Manager reports by setting the Visibility and Reporting > Reports
permission.
| Permission | Description | Read Access | Read and Write Access | No Access |
| Inline Security | Controls access to SaaS Security Inline. Settings
are inherited by all child permissions unless specifically
overridden. | Grants read-only access to all child permissions in the
Inline Security permission hierarchy. Child permissions can
override this setting to allow full read and write
access. | Grants full read and write access to all child
permissions in the Inline Security permission
hierarchy. | Prevents access to SaaS Security Inline. Individual
child permissions can override this setting to allow read
and write or read-only access. |
| Integrations | Controls management of all supported SaaS Security Inline integrations. | Allows users to view integration details. Grants read
access to all child permissions in the Integrations
hierarchy. Child permissions can override this setting to
allow full read and write access. | Allows users to view and modify integration settings.
Grants read and write access to all child permissions in the
Integrations hierarchy. | Users cannot view integration information. |
| Integrations > Syslog/API Client | Controls access to Syslog and API client integrations.
Requires at least read access to the parent Integrations
permission. | Allows users to view Syslog and API client integrations
on the page. | Allows users to create and update Syslog and API client
integrations. | Users cannot view Syslog and API client
integrations. |
| Integrations > Active Directory | Controls access to Active Directory integrations.
Requires at least read access to the parent Integrations
permission. | Allows users to view Active Directory integrations on the page. | Allows users to update Active Directory integration
settings. | Users cannot view Active Directory integrations. |
| Policy Management | Controls access to policy recommendations. | Allows users to view policy recommendations and
details. | Allows users to create, edit, enable, disable, and delete
policy recommendations. | Users cannot view policy recommendations. |
| Visibility | Controls access to various pages, including the
dashboard, Discovered Applications, Discovered Users, and
Application Dictionary pages. | Allows users to view pages in SaaS Security Inline.
Grants read access to all child permissions in the
Visibility hierarchy. Child permissions can override this
setting to allow full read and write access. | Allows users to view pages in SSaaS Security Inline. Grants write access to all child permissions in the
Visibility hierarchy. | Users cannot view pages in SaaS Security Inline. |
| Visibility > On-Demand Scan | Controls the ability to run on-demand scans. Requires at
least read access to the parent Visibility
permission. | Users cannot run on-demand scans. | Allows users to run on-demand scans from the page. | Users cannot run on-demand scans. |
| Visibility > Reports | Controls access to the Reports page in SaaS Security Inline. Requires at least read access to
the parent Visibility permission. The Reports page is
deprecated and will be removed from SaaS Security Inline. | Allows users to generate, schedule, and download
reports. | Allows users to generate, schedule, and download reports
(same as Read access). | The Reports page in SaaS Security Inline is not
available. |
| Visibility > Risk Management | Controls the ability to manage risk scores. Requires at
least read access to the parent Visibility
permission. | Allows users to view risk scores for discovered
applications, but not modify them. | Allows users to assign custom risk scores and configure
global risk score weights. | Risk score information is not available. |
| Visibility > Tag Management | Controls the ability to tag discovered applications and
create custom tags. Requires at least read access to the
parent Visibility permission. | Allows users to view tags on discovered apps, but not
apply or create them. | Allows users to tag applications and to create, modify,
or delete custom tags. | Users cannot view tags applied to discovered
applications. |
Create a Custom Role for SaaS Security Inline Permissions
Custom roles enable you to choose the privileges associated with the role so
that you can restrict access to specific pages or actions in
SaaS Security Inline. For example, you might have users who need to
monitor discovered apps and view policy recommendations. However, you want
to prevent these users from making configuration changes. In this case, you
could
create a custom role that allows
read-only access to the Visibility and Policy Management permissions.
- Log in to
Strata Cloud Manager as a Super User.
- To navigate to the Identity & Access page, select .
- On the Identity & Access page, select .
- Add a Name and a
Description for the role.
- Specify the permissions for SaaS Security Inline access. These
permissions are located under .
For each permission within a category, specify the level of
access you want to assign to the role. You can specify that the role
has no access, read-only access, or read and write access.
- (Optional) Specify the Reports
permission for Strata Cloud Manager report access. This permission is
located under Visibility and Reporting and controls access to all
reports, including the SaaS Security report.
- Save your changes.
- After creating the custom admin role, assign it to specific
users.
Any actions that are not permitted for a user based
on their role will not be available in the SaaS Security Inline interface.
View Administrator Activity on SaaS Security Inline
SaaS Security captures actions performed by each administrator and records
them in an audit log so you can audit activity and track changes.
Role permissions on
SaaS Security Inline dictate what activity is accessible to you from
the log.
You can audit activity by:
To do this:
- Log in to
Strata Cloud Manager.
- To open the administrator audit logs, select .
- Apply one or more filters to query administrator activity. You can
filter the audit log by user role, user email, logged events, or a
date range.
- (Optional) Click the download icon to save the search
results to a CSV file.