Accessing Trellix Threat Intelligence Exchange - SaaS
To start using Trellix Threat Intelligence Exchange - SaaS, you must first sign up for an Trellix ePolicy Orchestrator - SaaS account and activate it.
After you log on to Trellix ePO - SaaS, you can access the TIE Reputations page if you have a valid TIE license.
You need to deploy Trellix Endpoint Security (ENS) Adaptive Threat Protection on endpoints to manage TIE reputations on Trellix ePO - SaaS platform.
Note
For information about the features of Trellix Threat Intelligence Exchange - SaaS, see Trellix Threat Intelligence Exchange - SaaS Product Guide.
System requirements
For details about system requirements of client Endpoint Security Adaptive Threat Protection, see Trellix Endpoint Security (ENS) Installation Guide and KB82761.
You can download the latest versions of Trellix Agent and Trellix Data Exchange Layer from Trellix ePO - SaaS.
Assign roles to users
You can limit or extend users' access to Trellix TIE - SaaS by assigning or unassigning roles. All roles have specific permission sets assigned to them.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select a user from the Users pane.
The user details, assigned roles, and unassigned roles for the selected user appears on the right pane.
Select the required roles from the Unassigned Roles list. The Roles pane lists the created roles.
Click Save Changes.
Invite users to manage Trellix TIE - SaaS
You can add users and assign specific roles to them to use Trellix TIE - SaaS.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, click Invite User.
On the Invite new user page, type the first name, last name, and the email address of the user you want to invite.
Click Invite.
Results
An invitation email is sent to the user with activation instructions. This invitation is valid for 7 days. After you add the user, their names appear on the Users pane.
Create a role
You can use the default permissions for Trellix threat intelligence service and Trellix ePO - SaaS to create a customized role for your user.
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, click Add Role.
Enter a name for the role.
Roles Trellix Threat Intelligence Administrator and Trellix Threat Intelligence Viewer are available to duplicate to users.
From the below products, select the required permissions:
From the Trellix Threat Intelligence Service drop-down list, user administrator can select Manage Reputations with administrator permissions to manage reputations and View Reputations with view only permissions to view reputations.
From the Trellix ePolicy Orchestrator - SaaS drop-down list, select the required permissions.
The selected permissions appear in Assigned Permissions.
Results
The created role appears in the Roles pane. You can now assign this role to selected users.
Delete users and roles
You can remove all roles and users when they are no longer in use. The default roles can't be deleted.
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select the user or role that you want to delete.
Click Delete, then click Confirm.
Results
The user role is removed from the Users or Roles list.
Duplicate a role
You can create a copy of an existing role and customize as needed.
Before you begin
Make sure that you have administrator permissions to use Trellix ePO - SaaS.
Task
Log on to Trellix ePO - SaaS as an administrator.
Select Menu → Configuration → Users & Roles.
On the Users & Roles page, select the role that you want to copy:
Trellix Threat Intelligence Administrator — with administrator permissions to manage reputations.
Trellix Threat Intelligence Viewer — with view only permissions to view reputations.
Click Duplicate.
Results
A copy of the existing role is created. You can edit the role name, assign or unassign permissions, and save the role.
Trellix Threat Intelligence Exchange - SaaS Installation Guide 7
4 | Getting started with Trellix Threat Intelligence Exchange - SaaS
Deploy client ATP using Trellix ePO - SaaS
For details about deploying client Adaptive Threat Protection using Trellix ePO - SaaS, see Trellix Endpoint Security (ENS) Installation Guide.
Deploy DXL local broker using Trellix ePO - SaaS
DXL local broker keeps file and reputation cache and reduces endpoints effort to reach the TIE services for reputation.
Note
DXL local broker is an optional component.
DXL local broker is mandatory for TIE services integration with on-premises infrastructure Intelligent Sandbox for sandboxing analysis of file samples.
For details about deployment and configure DXL local broker, and connect DXL client with DXL local broker, see Trellix Data Exchange Layer Installation Guide.
Note