Assign roles to users

Prev Next

You can limit or extend user access to Trellix Insights by assigning or unassigning roles. All roles have specific permission sets. You cannot assign or unassign roles for your own account.

Make sure that you have administrator permission to use ePO - SaaS.

  1. Log on to ePO - SaaS as an administrator.

  2. Select MenuConfigurationUsers & Roles.

  3. On the Users and Roles page, select a user from the Users panel.

    The user details, assigned roles, and unassigned roles for the selected user appears on the right pane.

  4. Select the needed roles from the Unassigned Roles list.

    The Roles panel lists these default roles.

    Roles

    Permissions

    Trellix EDR Administrator

    Provide administrative access to Trellix EDR and allow users to:

    • Configure endpoint policies (ePO - SaaS only).

    • Configure tenant's settings and data sources.

    • Execute a targeted remediation action (single device).

    ePO - SaaS Administrator

    Provide administrative access to ePO - SaaS and allow the user to:

    • View Automatic Responses and view results in the Server Task Log.

    • View Server Tasks and task results in Server Task Log.

    • View client tasks and policies in Trellix Endpoint Security (ENS) Adaptive Threat Protection, Trellix Endpoint Security (ENS) Common, McAfee Host Intrusion Prevention, Endpoint Security Threat Prevention, and Trellix Endpoint Security (ENS) Web Control.

    • View client tasks and policies in Trellix Agent.

    • View client tasks and policies in Trellix Data Exchange Layer.

    • View client tasks and policies in Trellix Endpoint.

    • View Firewall catalog and client rules.

    • View Policy Assignment Rules.

    • View client tasks and policies in Trellix Endpoint Security (ENS) Threat Prevention .

    • View queries in Trellix Endpoint Security (ENS) Threat Prevention, Trellix Endpoint Security (ENS) Common, Trellix Endpoint Security (ENS) Firewall, Endpoint Security Threat Prevention, and Trellix Endpoint Security (ENS) Web Control.

    • View Audit Logs, Client Events, Dashboards, Exploit Prevention Events, Queries and Reports created by users, and Threat Events.

    • View System Tree and Systems.

    Note

    For invited users with Trellix Insights role, the ePO - SaaS Administrator role is not needed to access Trellix Insights.

    MVISION Insights Admin Access

    Provides administrative access to Trellix Insights.

    Note

    This permission is needed to complete the onboarding process.

    MVISION Insights General Access

    Provides general access to Trellix Insights.

    MVISION ePO Security Analyst

    Allow user to:

    • Execute a targeted remediation action (single device).

    • Triage, scope, and conduct investigation cases.

    Receive Notifications

    Allow user to receive notifications from Trellix Insights.

    Administrators and invited users receive notifications if this role is assigned.

    Notifications alert users of possible campaign attacks on their organization and provide a link to navigate to the campaign details page. The notifications are color coded to indicate the severity of the campaigns.

    By default, notifications are retained for 30 days.

  5. Click Save Changes.

The selected roles now appear in the Assigned Roles list.