IAM user types and roles

Prev Next

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

User types

An IAM user account is an entity defined by a username that is an email address, a password created by the user, and permissions that grant users access to specific resources and allow specific actions. The IAM organization administrator, created by Trellix along with your IAM organization, is initially the only user account in the IAM organization. The organization account administrator is responsible for provisioning other Trellix Cloud IAM user accounts in the organization.

Important

IAM Cloud users are not identical to Email Security - Cloud non-admin users.

A user's profile data (such as timezone and phone number) is saved in the primary user record. A user can access and update profile data from the organization where this user is a primary user. A user's profile data is not available in organizations where the user is an external user.

There are two types of user accounts. A user account can be internal or external within an organization.

Internal user

A user is considered a primary user in the organization where their identity is defined. All data for the user exists and is accessible within the organization.

External user

An external user must be invited into an organization that is not their primary organization.

For example, one use-case of an external user is adding a Trellix Support engineer into a customer organization. In this case, the Trellix engineer has a primary account in the Trellix organization and is an external user in the customer organization.

User roles and entitlements

IAM is the identity provider service from Trellix, which provides an enhanced authentication and authorization experience to you and your organization. IAM uses roles to control what users can see and do. A role specifies permissions. To allow a user to have certain access permissions, an administrator assigns a role to the user account.

A role is a collection of entitlements; each entitlement is a privilege that allows a user to perform a particular action.

There are two roles available for user assignment and management.

IAM admin

An IAM admin has the capability to invite other admins to the organization and manage the authentication policies for the organization. They can add and manage end users in the organization.

IAM user

An IAM user has capabilities limited to browsing others.

Email admin specific roles

Email Security — Cloud provides email admin specific roles. They are:

ETP org admin

An ETP org admin has full read-write capability over all the functionality of Email Security — Cloud.

ETP org read-only admin

An ETP org read-only admin only has read capability over all the data of Email Security — Cloud.

Entitlements

The tables in this section list all of the Email Security - Cloud (formerly known as ETP) entitlements. Entitlements are the privileges assigned to specific roles. You can create custom roles and add entitlements to them as needed for granular control and security. For information about creating a custom role, see Creating a Custom Role.

For example, a user with a custom role that grants the etp.alerts.read entitlement but not the etp.alerts.update entitlement can view individual alerts, but cannot edit them.

If a user lacks the entitlements to view data or perform actions in the Email Security — Cloud Web UI, the data or action will not be available or an error message will be returned.

Alerts

etp.alerts.create

Whether a user can create new alerts

etp.alerts.delete

Whether a user can delete alerts

etp.alerts.read

Whether a user can view all individual alerts and their notes

etp.alerts.update

Whether a user can edit alerts and their notes

Clients

etp.clients.read

Whether a user can view all clients and their notes

Configuring Alert Notifications

etp.config.alert_notifications.create

Whether a user can add new alert notifications

etp.config.alert_notifications.delete

Whether a user can delete alert notifications

etp.config.alert_notifications.read

Whether a user can view all alert notifications and their notes

etp.config.alert_notifications.update

Whether a user can edit alert notifications and their notes

Configuring Cache Settings

etp.config.cache_settings.read

Whether a user can view all alert notifications and their notes

etp.config.cache_settings.update

Whether a user can edit alert notifications and their notes

Configuring Domains

etp.config.domains.create

Whether a user can add new domains

etp.config.domains.delete

Whether a user can delete domains

etp.config.domains.read

Whether a user can view all domains and their notes

etp.config.domains.update

Whether a user can edit domains and their notes

Configuring Policies

etp.config.policies.create

Whether a user can add new policies

etp.config.policies.delete

Whether a user can delete policies

etp.config.policies.read

Whether a user can view all policies and their notes

etp.config.policies.update

Whether a user can edit polices and their notes

Configuring Portal Access

etp.config.portal_access.create

Whether a user can grant portal access

etp.config.portal_access.delete

Whether a user can restrict portal access

etp.config.portal_access.read

Whether a user can view portal access statuses and their notes

etp.config.portal_access.update

Whether a user can configure portal access

Configuring Quarantine Reports

etp.config.quarantine_reports.create

Whether a user can add new quarantine reports

etp.config.quarantine_report.delete

Whether a user can delete quarantine reports

etp.config.quarantine_report.read

Whether a user can view all quarantine_report and their notes

etp.config.quarantine_report.update

Whether a user can edit quarantine_report and their notes

Configuration

etp.config.read

Whether a user can view all configurations and their notes

Dashboards

etp.dashboard.create

Whether a user can add new dashboards

etp.dashboard.delete

Whether a user can delete dashboards

etp.dashboard.read

Whether a user can view all dashboards and their notes

etp.dashboard.update

Whether a user can edit dashboards

Email Trace

etp.email_trace.create

Whether a user can configure the email trace

etp.email_trace.delete

Whether a user can delete email trace

etp.email_trace.read

Whether a user can view the email trace and notes

etp.email_trace.update

Whether a user can edit the email trace

Manage Notifications

etp.notifications.manage.read

Whether a user can view notifications

etp.notifications.manage.update

Whether a user can manage notifications

Quarantine

etp.quarantine.create

Whether a user can add quarantine ??

etp.quarantine.delete

Whether a user can delete quarantine entries

etp.quarantine.read

Whether a user can view the quarantine and notes

etp.quarantine.update

Whether a user can edit quarantine settings

Reports

etp.reports.create

Whether a user can add new reports

etp.reports.delete

Whether a user can delete reports

etp.reports.read

Whether a user can view all reports and their notes

etp.reports.update

Whether a user can edit reports

Stats

etp.stats.nonpii.read

Whether a user can view non pii stats

etp.stats.pii.read

Whether a user can view pii stats

Users

etp.users.create

Whether a user can add new users

etp.users.delete

Whether a user can delete users

etp.users.read

Whether a user can view all users and their notes

etp.users.update

Whether a user can edit user profiles

IAM entitlements

API Keys

iam.apikeys.add

Whether a user can create api keys

iam.apikeys.browse

Whether a user can view all api keys and their notes

iam.apikeys.delete

Whether a user can delete api keys

iam.apikeys.edit

Whether a user can edit api keys