Trellix EDR has three main roles: Trellix EDR Administrator, Trellix SOC Analyst L2, and Trellix SOC Analyst L1.
Note
The ePO tile is present on the IAM page for all ePO - SaaS users because ePO is configured as the foundational service for Trellix EDR. This configuration is independent of any assigned user roles.
As an Trellix EDR Administrator, you can:
Configure Trellix EDR settings.
Conduct investigations, triage, monitor threats, and perform searches in Device Search, Real Time Search, and Historical Search.
Take action on the endpoints.
Configure endpoint policies.
Create and edit custom collectors and reactions.
Create users and assign custom roles.
As an Trellix SOC Analyst L2, you can:
Conduct investigations, triage, monitor threats, and perform searches in Device Search, Real Time Search, and Historical Search.
Take action on the endpoints.
As an Trellix SOC Analyst L1, you can:
Conduct investigations, triage, monitor threats, and perform searches in Device Search, Real Time Search, and Historical Search.
Important
Users with Trellix EDR Search API access can use MVISION APIs to make changes. These users cannot access the Trellix EDR interface.
As an Trellix Account Administrator, when you select the following roles for Trellix EDR and assign it to the user, the user can:
The Configure endpoint policies role — Configure endpoint policies on the Policy Catalog page.
The Configure tenant's settings and data sources role — Configure Trellix EDR tenant's settings and data sources.
The Execute a targeted remediation action (single device) role:
Access the Device Actions option on the Monitoring dashboard when endpoints are selected.
Access Quarantine device and End Quarantine device options under Device Details → Take an action on the Investigating dashboard.
Access the Actions option on the Real-time Search dashboard when endpoints are selected.
If the Execute a targeted remediation action (single device) option is not selected:
The Action History dashboard is not visible
The Manage threat exclusions option from the Configuration page is not visible
The Investigating dashboard is not visible
The Take actions drop-down options Exclude from threats and Dismiss from the Monitoring dashboard are disabled and not visible
All remediation actions are disabled and do not appear on the respective dashboards.
The Triage, scope, and conduct investigation cases role — Create an investigation from the Take action option on the Monitoring dashboard.
If the Triage, scope, and conduct investigation cases option is not selected, the user can't see the Investigating dashboard on the Trellix EDR menu option.