Logging into Email Security - Cloud in a federated organization

Prev Next

Important

IAM support for federated organizations is available to U.S. Government users only.

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

A federated organization is an organization whose Identity Provider (IDP) is not managed by Trellix. This section includes steps for setting up a new federated organization account and migrating from an existing account to a federated organization account.

Email Security - Cloud and IAM roles in federated organizations are strictly determined by configured mapping in the organizations. Roles cannot be explicitly assigned to users, as they can in other non-federated organizations. Mapping the users in an existing IDP to Email Security - Cloud and IAM roles should be agreed upon with the Email Security - Cloud provisioning team prior to provisioning in IAM and Email Security - Cloud. Inform the Email Security - Cloud provisioning team of your desired user mapping before provisioning. For more information on the roles available, see Cloud IAM user types and roles.

Note

Time zone settings for federated organizations are determined by the third-party IDP, not Email Security - Cloud or IAM. If a third-party IDP does not provide time zone settings, Email Security - Cloud defaults to Eastern Standard Time, North America (UTC-5).

Logging in using a third-party IDP

  1. Go to the Email Security - Cloud login page.

  2. Enter the email address used for your Email Security - Cloud account. You are redirected to the login page for your IDP.

  3. Enter your password and log in. You are redirected to the Email Security - Cloud dashboard.

Setting up a new federated organization account

To set up a new federated organization account:

  1. Contact Trellix Support to request that users from a group in the current IDP be mapped to either the Email Security - Cloud Org Admin role or the Email Security - Cloud Read Only Org Admin role.

  2. Go to the Email Security - Cloud login page. See Accessing the Email Security - Cloud dashboard.

  3. Enter your username. Click Next.

  4. You are redirected to the third-party IDP. Enter your password.

Migrating from an existing account to a federated organization account

To migrate to a federated organization account:

  1. Contact Trellix Support to request to be migrated to Federated Mode.

  2. Request that users from a group in the current IDP be mapped to either the Email Security - Cloud Org Admin role or the Email Security - Cloud Read Only Org Admin role. The Federated Organization account will be created with the required mapping.

  3. Go to the Email Security - Cloud login page. See Accessing the Email Security - Cloud dashboard.

  4. Enter your username. Click Next.

  5. You are redirected to the third-party IDP. Enter your password.

If your IDP does not provide time zone settings, the time zone will be set to the default time zone after the migration is complete.

If you have invited external users to manage Email Security - Cloud, you will need to invite the external users again once the migration is complete.

A new activity log will be created for users when the migration is complete. You will not be able to see activity from before the migration.