Configuring data policies for access control

Prev Next

An IAM organization admin can create role-based access control (RBAC) data policies with constraints that limit what individual users can see in Helix Enterprise. For example:

  • The class constraint can limit access by non-admin users.

  • The product constraint can limit access to specific appliance types.

  • The Comm Broker and device ID constraints can limit access to specific devices and regions.

  • The customer ID constraint can limit access to certain child organizations in a federated setup.

Important

There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

Data policies apply to users, not to roles. A single user can have only one data policy assigned. Newly assigned or modified data policies are applied when the user logs in to Helix Enterprise.

Note

Data policies apply to alerts that are generated after alert-based data policies were introduced in August 2021. For example, a user with a data policy that allows access to Network Security alerts cannot see Network Security alerts that were generated before August 2021, but can see Network Security alerts that were generated after August 2021. Users with no alert-based data policy assigned can see all alerts that were generated both before and after August 2021.

You can designate one default policy for each organization. The default policy, which is displayed with a star prefixed to its name, is assigned to all users who do not have another data policy assigned.

  • If no default data policy is designated for an organization, users who do not have another data policy assigned will have no limitations.

  • If a data policy assigned to a user is deleted, the default data policy will automatically be assigned to the user.

  • The "Admin User Data Policy" is provided to override the default data policy on selected admin users. The rule defined for this data policy is class DOES NOT EQUAL null (class!=null), which grants the admin user who is assigned the policy full access.

The display of real-time data (for example, dashboard data) depends on the data policies assigned to the user who views the data. If a data policy prevents a user from seeing certain data on a dashboard, the dashboard is available but widgets with restricted data are empty. A message informing the user that a data policy prevented access is displayed once in each Helix Enterprise session.

Historical data included in a scheduled report depends on the data policies assigned to the user who created the report. If the data policy assigned to a user who created a report changes to be more restrictive or less restrictive, the next scheduled report will automatically show less or more data.

Important

Deleting a data policy permanently removes it from Helix Enterprise and from any users with the data policy.

Note

The visibility setting at the organization or item level also affects what users can see. See Setting public or private visibility.

Some Web UI pages show only those items that users are entitled to see based on their assigned data policies. For example:

  • Appliances, Appliance Groups, Appliance Settings—Only those appliances for which a user has access are displayed.

  • Alerts—Only those alerts for which a user has access are displayed.

  • Alert Details—If a user has access to an alert, but does not have access to certain events, those events will not be displayed.

  • Asset-Based Alert Correlation—Only the associated alerts and events for which a user has access are displayed.

  • Cases—Only those cases assigned to or created by the user are displayed.

  • Case Details—If a user is assigned to a case, but does not have access to certain alerts and events included in the case, those alerts and events will not be displayed.

  • Entities—Only the associated alerts and events for which a user has access are displayed.

  • Sensors—Only those sensors for which a user has access are displayed.

The Application Settings > Data Policies page allows an IAM organization admin to create data policies and assign them to users. It also allows the admin to export data policies from one Helix Enterprise organization and import them into another, and export user assignments for audit reporting. This is the page where the admin sets global visibility to private or public.

To access the Data Policies page:
  1. From the main menu, select your avatar and then select Application Settings.

  2. Click Data Policies.