Important
There are two versions of IAM. If the URL you use to access the IAM UI ends with
fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends withtrellix.com, see the Trellix IAM Guide for information regarding IAM.
User types
An IAM user account is an entity defined by a username that is an email address, a password created by the user, and permissions that grant users access to specific resources and allow specific actions. The IAM organization administrator, created by Trellix along with your IAM organization, is initially the only user account in the IAM organization. The organization account administrator is responsible for provisioning other Trellix Cloud IAM user accounts in the organization.
Important
IAM Cloud users are not identical to Email Security - Cloud non-admin users.
A user's profile data (such as timezone and phone number) is saved in the primary user record. A user can access and update profile data from the organization where this user is a primary user. A user's profile data is not available in organizations where the user is an external user.
There are two types of user accounts. A user account can be internal or external within an organization.
Internal user
A user is considered a primary user in the organization where their identity is defined. All data for the user exists and is accessible within the organization.
External user
An external user must be invited into an organization that is not their primary organization.
For example, one use-case of an external user is adding a Trellix Support engineer into a customer organization. In this case, the Trellix engineer has a primary account in the Trellix organization and is an external user in the customer organization.
User roles and entitlements
IAM is the identity provider service from Trellix, which provides an enhanced authentication and authorization experience to you and your organization. IAM uses roles to control what users can see and do. A role specifies permissions. To allow a user to have certain access permissions, an administrator assigns a role to the user account.
A role is a collection of entitlements; each entitlement is a privilege that allows a user to perform a particular action.
There are two roles available for user assignment and management.
IAM admin
An IAM admin has the capability to invite other admins to the organization and manage the authentication policies for the organization. They can add and manage end users in the organization.
IAM user
An IAM user has capabilities limited to browsing others.
Email admin specific roles
Email Security — Cloud provides email admin specific roles. They are:
ETP org admin
An ETP org admin has full read-write capability over all the functionality of Email Security — Cloud.
ETP org read-only admin
An ETP org read-only admin only has read capability over all the data of Email Security — Cloud.
Entitlements
The tables in this section list all of the Email Security - Cloud (formerly known as ETP) entitlements. Entitlements are the privileges assigned to specific roles. You can create custom roles and add entitlements to them as needed for granular control and security. For information about creating a custom role, see Creating a Custom Role.
For example, a user with a custom role that grants the etp.alerts.read entitlement but not the etp.alerts.update entitlement can view individual alerts, but cannot edit them.
If a user lacks the entitlements to view data or perform actions in the Email Security — Cloud Web UI, the data or action will not be available or an error message will be returned.
Alerts | |
|---|---|
etp.alerts.create | Whether a user can create new alerts |
etp.alerts.delete | Whether a user can delete alerts |
etp.alerts.read | Whether a user can view all individual alerts and their notes |
etp.alerts.update | Whether a user can edit alerts and their notes |
Clients | |
|---|---|
etp.clients.read | Whether a user can view all clients and their notes |
Configuring Alert Notifications | |
|---|---|
etp.config.alert_notifications.create | Whether a user can add new alert notifications |
etp.config.alert_notifications.delete | Whether a user can delete alert notifications |
etp.config.alert_notifications.read | Whether a user can view all alert notifications and their notes |
etp.config.alert_notifications.update | Whether a user can edit alert notifications and their notes |
Configuring Cache Settings | |
|---|---|
etp.config.cache_settings.read | Whether a user can view all alert notifications and their notes |
etp.config.cache_settings.update | Whether a user can edit alert notifications and their notes |
Configuring Domains | |
|---|---|
etp.config.domains.create | Whether a user can add new domains |
etp.config.domains.delete | Whether a user can delete domains |
etp.config.domains.read | Whether a user can view all domains and their notes |
etp.config.domains.update | Whether a user can edit domains and their notes |
Configuring Policies | |
|---|---|
etp.config.policies.create | Whether a user can add new policies |
etp.config.policies.delete | Whether a user can delete policies |
etp.config.policies.read | Whether a user can view all policies and their notes |
etp.config.policies.update | Whether a user can edit polices and their notes |
Configuring Portal Access | |
|---|---|
etp.config.portal_access.create | Whether a user can grant portal access |
etp.config.portal_access.delete | Whether a user can restrict portal access |
etp.config.portal_access.read | Whether a user can view portal access statuses and their notes |
etp.config.portal_access.update | Whether a user can configure portal access |
Configuring Quarantine Reports | |
|---|---|
etp.config.quarantine_reports.create | Whether a user can add new quarantine reports |
etp.config.quarantine_report.delete | Whether a user can delete quarantine reports |
etp.config.quarantine_report.read | Whether a user can view all quarantine_report and their notes |
etp.config.quarantine_report.update | Whether a user can edit quarantine_report and their notes |
Configuration | |
|---|---|
etp.config.read | Whether a user can view all configurations and their notes |
Dashboards | |
|---|---|
etp.dashboard.create | Whether a user can add new dashboards |
etp.dashboard.delete | Whether a user can delete dashboards |
etp.dashboard.read | Whether a user can view all dashboards and their notes |
etp.dashboard.update | Whether a user can edit dashboards |
Email Trace | |
|---|---|
etp.email_trace.create | Whether a user can configure the email trace |
etp.email_trace.delete | Whether a user can delete email trace |
etp.email_trace.read | Whether a user can view the email trace and notes |
etp.email_trace.update | Whether a user can edit the email trace |
Manage Notifications | |
|---|---|
etp.notifications.manage.read | Whether a user can view notifications |
etp.notifications.manage.update | Whether a user can manage notifications |
Quarantine | |
|---|---|
etp.quarantine.create | Whether a user can add quarantine ?? |
etp.quarantine.delete | Whether a user can delete quarantine entries |
etp.quarantine.read | Whether a user can view the quarantine and notes |
etp.quarantine.update | Whether a user can edit quarantine settings |
Reports | |
|---|---|
etp.reports.create | Whether a user can add new reports |
etp.reports.delete | Whether a user can delete reports |
etp.reports.read | Whether a user can view all reports and their notes |
etp.reports.update | Whether a user can edit reports |
Stats | |
|---|---|
etp.stats.nonpii.read | Whether a user can view non pii stats |
etp.stats.pii.read | Whether a user can view pii stats |
Users | |
|---|---|
etp.users.create | Whether a user can add new users |
etp.users.delete | Whether a user can delete users |
etp.users.read | Whether a user can view all users and their notes |
etp.users.update | Whether a user can edit user profiles |
IAM entitlements
API Keys | |
|---|---|
iam.apikeys.add | Whether a user can create api keys |
iam.apikeys.browse | Whether a user can view all api keys and their notes |
iam.apikeys.delete | Whether a user can delete api keys |
iam.apikeys.edit | Whether a user can edit api keys |