About User accounts

Prev Next

A user account represents a person or service who authenticates against the Trellix IAM server to access on-premises and cloud-based resources in your IAM organization. IAM users typically log in at the Web UI of a resource or the Trellix IAM service. IAM users can also programmatically access the API of the Trellix IAM service.

User account creation

Initially the only user account in a new IAM organization is the IAM organization administrator, which is the default user account created for the organization by Trellix. The organization administrator is responsible for provisioning other Trellix IAM user accounts in the organization.

Note

The default organization administrator can create IAM Admin users and delegate to them the task of creating the other user accounts.

To provision a user account, an administrator specifies a user name that is an email address, assigns user access permissions, and then emails the end user an invitation to enroll the account in the IAM organization. During the enrollment process, an end user creates their own password and enters user preferences.

Permissions granted by directly assigned roles

When you create a user account, you grant access permissions by assigning roles directly to the account. If no role is assigned, the user cannot log in to cloud-based Trellix Helix, nor to any on-premises and cloud-based Trellix appliances.

Permissions granted by membership in a user group

After a user account is created, you can modify its permissions by assigning the user to a user group. A user group can have permissions attached through directly assigned roles. A user group also inherits the roles directly assigned to its members. For more information, see IAM user groups.

The potential impact of deleting a user account