The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure user groups

Prev Next

Group settings allow you to control user settings and access once for all users who are part of that group.

  1. Note

    User permissions take precedence over group permissions. For example, if a user has only Read access to resources, but their group has Modify access, the user can only Read selected items.

    On the system navigation tree, click System Properties Users and Groups, and enter the password.

  2. Select group permissions. Only the item's creator can change permissions for read-only custom items.

    • (Views only) - Users in the group inherit settings from the parent folder (default).

    • (Reports and watchlists only) - Users in the group inherit change settings (default).

    • Indicate the group's access settings:Read only, Modify, or neither. If you don't select Read only or Modify, the group has deny rights. If you select Modify, the system selects Read only automatically.

      Note

      A pseudo group called Default appears for master or administrative users. Groups created in the future get this privilege.

    • Indicate individual user access settings: Read only, Modify, or neither. If you don't select Read only or Modify, the user has deny rights. If you select Modify, the system selects Read only automatically.

      Important

      User settings take precedence over group settings. For example, if a user has only Read access to resources, but their group has Modify access, the user can only Read selected items.

      • If a user is not on the group list, the system uses the group settings for that user.

      • If a user is on the group list but doesn't have Read or Modify checked, that user has explicit deny rights to that resource.

  3. To the right of the Groups table, click Add.

    • Enter the group name and description.

    • Add users to the group.

    • Set the group's access permissions.

    • Apply IP address filters to the group to limit data users see when executing reports or selecting users as report or alarm recipients.

    • Select the event forwarding destinations this group can access. This option defines the devices a user can forward events from and the filters that specify the types of events that can be forwarded.

      Note

      If an event forwarding destination does not belong to an access group, it has access to all devices.

    • Limit when this group can access Trellix ESM. Users receive visual notification that their session is going to time out 15, 5, and 1 minute before the time expires.

    • Select the reports, views, and watchlists this group can view, change, or share with other users and groups. You can also set the filters the group can view and change.

    Note

    If you select more than one view, watchlist, or report, a checkbox in the Read or Modify column indicates a conflict. You can't save and close the page until you resolve the conflict. To resolve the setting for all selected items, click the checkbox.

  4. Click OK and enter the password again.