Adding an external user account

Prev Next

To allow a user defined in a different IAM organization to access resources in your own IAM organization, you can add an external user account to your organization, assigning roles that grant the account selected access privileges in your organization. An external user account can be used to allow a partner or Trellix support engineer to access your Trellix appliances.

Note

By default, Trellix Customer Support can access your IAM organization through the external user groups that are automatically added to your organization when it is created: Trellix Support ‑ Level 1 and Trellix Support ‑ Levels 2 & 3. Unlike an external user account, an external user group accesses the resources in your organization with privileges controlled by its owning organization. See About user groups.

To give the external user account access to your IAM organization, you need to know the name of the user's primary organization (the organization where the account is defined and enrolled) and the email address for that user account. To specify the access privileges granted to the external user, you assign the account one or more roles for each product the user is allowed to access in your organization. User accounts can be assigned roles for more than one product type, and they typically are. A user can be assigned multiple roles for accessing the Trellix Web UI or Helix Web UI. For access to Trellix appliances, a user is typically assigned a role for each product type in the IAM organization.

An external user account retains the access privileges granted in your organization until you edit the account's role assignments or remove the account from the list of external users in your organization.

To add an external user account, start at the Users page. The main view of the Users page lists internal users and external users separately. After the external user account is added, it appears in the External Users panel.

Prerequisites
  • IAM Admin access to the Trellix IAM Web UI.

  • The email address by which the user is enrolled in the other IAM organization.

  • The name of the external user's primary organization.

To add a user account from a different organization:

  1. Log in to the IAM Web UI.

  2. Select Organization Settings > Users.

    The Users page lists all IAM user accounts known to your organization.

    The Internal Users panel lists user accounts that are defined in your organization. The External Users panel lists user accounts that are defined in other organizations but which the organization administrator has added and assigned roles.

  3. Click Add in the External Users panel.

  4. Enter the email address under which the user is enrolled in their primary IAM organization, and then click Next.

    CloudIAM_Users_AddExternal_1_EmailOrganization.png
  5. Select the name of the external user's primary organization and click Next.

  6. In the Available Products list, locate the product type and click Grant.

    CloudIAM_Users_AddExternal_2_Products.png
  7. In the Roles tab of the Assign Access for Product dialog box, select the check box for each product-specific role you want to assign the user.

    CloudIAM_Users_AddExternal_3_Roles.png
  8. Click Assign.

  9. To assign the external user roles for another product type, repeat steps 7 through 9.

  10. After all roles have been assigned, click Add. The user account appears in the External Users panel of the Users main view.