Manage SaaS Security Inline Administrators
Focus
Focus
SaaS Security

Manage SaaS Security Inline Administrators

Table of Contents

Manage SaaS Security Inline Administrators

Learn how to manage SaaS Security Inline administrators.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Panorama or Strata Cloud Manager)
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • SaaS Security Inline license
  • NGFW or Prisma Access license
Or any of the following licenses that include the SaaS Security Inline license:
  • CASB-X
  • CASB-PA
Depending on the size of your organization and the number of SaaS apps you want to block, you can create more than one administrative account with access to all capabilities within SaaS Security web interface, including creating SaaS policy rule recommendations, tagging SaaS apps, and accessing reports and analytics.
  • Permissions and Predefined Roles for SaaS Security Inline
    Role-Based Access Control (RBAC) is a security mechanism in Strata Cloud Manager that restricts access to authorized users only. The permissions described in the following table control access to various SaaS Security Inline views and capabilities.
    Strata Cloud Manager includes predefined roles, which are essentially "out-of-the-box" permission sets designed to cover the most common administrative job functions. The following predefined roles offer full read and write access or read-only access to SaaS Security Inline.
    • SaaS Inline Administrator
      This predefined role grants full read and write access to all SaaS Security Inline features, including application visibility, policy management, and integration functionality. This role grants permission only to SaaS Security Inline and does not include permissions for other applications and services within Strata Cloud Manager.
    • Superuser
      Provides read and write access to all available system-wide functions across Strata Cloud Manager. This complete, unrestricted access includes full read and write access to all SaaS Security Inline features.
    • View Only Administrator
      Provides read-only access to all available system-wide functions across Strata Cloud Manager. This read-only access includes read-only access to SaaS Security Inline.
    If you want to define more granular access permissions than what the predefined roles provide, you can create a custom role. Custom roles enable you to choose the specific permissions that you want to assign to the custom role. For each permission, you can specify whether the role has full read and write access, read-only access, or no access. The SaaS Security Inline permissions are grouped into a hierarchy. Permissions that you set on a parent permission are inherited by the child permissions, unless specifically overridden by the child permisison.
    The following RBAC permissions control access to SaaS Security Inline for the predefined roles and for any custom roles that you create.
    The SaaS Security Inline Reports page described in the following table is deprecated and will be removed. SaaS Security reports are now available on the Reports page in Strata Cloud Manager. In addition to the permissions for SaaS Security Inline described in the following table, you can control access to Strata Cloud Manager reports by setting the Visibility and Reporting > Reports permission.
    PermissionDescriptionRead AccessRead and Write AccessNo Access
    Inline SecurityControls access to SaaS Security Inline. Settings are inherited by all child permissions unless specifically overridden.Grants read-only access to all child permissions in the Inline Security permission hierarchy. Child permissions can override this setting to allow full read and write access.Grants full read and write access to all child permissions in the Inline Security permission hierarchy.Prevents access to SaaS Security Inline. Individual child permissions can override this setting to allow read and write or read-only access.
    IntegrationsControls management of all supported SaaS Security Inline integrations.Allows users to view integration details. Grants read access to all child permissions in the Integrations hierarchy. Child permissions can override this setting to allow full read and write access.Allows users to view and modify integration settings. Grants read and write access to all child permissions in the Integrations hierarchy.Users cannot view integration information.
    Integrations > Syslog/API ClientControls access to Syslog and API client integrations. Requires at least read access to the parent Integrations permission.Allows users to view Syslog and API client integrations on the SettingsDirectory & External Services page.Allows users to create and update Syslog and API client integrations.Users cannot view Syslog and API client integrations.
    Integrations > Active DirectoryControls access to Active Directory integrations. Requires at least read access to the parent Integrations permission.Allows users to view Active Directory integrations on the SettingsDirectory & External Services page.Allows users to update Active Directory integration settings.Users cannot view Active Directory integrations.
    Policy ManagementControls access to policy recommendations.Allows users to view policy recommendations and details.Allows users to create, edit, enable, disable, and delete policy recommendations.Users cannot view policy recommendations.
    VisibilityControls access to various pages, including the dashboard, Discovered Applications, Discovered Users, and Application Dictionary pages.Allows users to view pages in SaaS Security Inline. Grants read access to all child permissions in the Visibility hierarchy. Child permissions can override this setting to allow full read and write access.Allows users to view pages in SSaaS Security Inline. Grants write access to all child permissions in the Visibility hierarchy.Users cannot view pages in SaaS Security Inline.
    Visibility > On-Demand ScanControls the ability to run on-demand scans. Requires at least read access to the parent Visibility permission.Users cannot run on-demand scans.Allows users to run on-demand scans from the SettingsServices page.Users cannot run on-demand scans.
    Visibility > ReportsControls access to the Reports page in SaaS Security Inline. Requires at least read access to the parent Visibility permission.
    The Reports page is deprecated and will be removed from SaaS Security Inline.
    Allows users to generate, schedule, and download reports.Allows users to generate, schedule, and download reports (same as Read access).The Reports page in SaaS Security Inline is not available.
    Visibility > Risk ManagementControls the ability to manage risk scores. Requires at least read access to the parent Visibility permission.Allows users to view risk scores for discovered applications, but not modify them.Allows users to assign custom risk scores and configure global risk score weights.Risk score information is not available.
    Visibility > Tag ManagementControls the ability to tag discovered applications and create custom tags. Requires at least read access to the parent Visibility permission.Allows users to view tags on discovered apps, but not apply or create them.Allows users to tag applications and to create, modify, or delete custom tags.Users cannot view tags applied to discovered applications.
  • Create a Custom Role for SaaS Security Inline Permissions
    Custom roles enable you to choose the privileges associated with the role so that you can restrict access to specific pages or actions in SaaS Security Inline. For example, you might have users who need to monitor discovered apps and view policy recommendations. However, you want to prevent these users from making configuration changes. In this case, you could create a custom role that allows read-only access to the Visibility and Policy Management permissions.
    1. Log in to Strata Cloud Manager as a Super User.
    2. To navigate to the Identity & Access page, select System Settings Identity & Access.
    3. On the Identity & Access page, select RolesCustom RolesAdd Custom Role.
    4. Add a Name and a Description for the role.
    5. Specify the permissions for SaaS Security Inline access. These permissions are located under Next-Generation CASBInline Security.
      For each permission within a category, specify the level of access you want to assign to the role. You can specify that the role has no access, read-only access, or read and write access.
    6. (Optional) Specify the Reports permission for Strata Cloud Manager report access. This permission is located under Visibility and Reporting and controls access to all reports, including the SaaS Security report.
    7. Save your changes.
    8. After creating the custom admin role, assign it to specific users.
      Any actions that are not permitted for a user based on their role will not be available in the SaaS Security Inline interface.
  • View Administrator Activity on SaaS Security Inline
    SaaS Security captures actions performed by each administrator and records them in an audit log so you can audit activity and track changes. Role permissions on SaaS Security Inline dictate what activity is accessible to you from the log.
    You can audit activity by:
    • Specific administrator
    • All administrators combined
    To do this:
    1. Log in to Strata Cloud Manager.
    2. To open the administrator audit logs, select ConfigurationSaaS SecuritySettingsAdmin Audit LogsMonitor actions taken by SaaS Security administrators.
    3. Apply one or more filters to query administrator activity. You can filter the audit log by user role, user email, logged events, or a date range.
    4. (Optional) Click the download icon to save the search results to a CSV file.