Fallback roles for Trellix Appliances

Prev Next

Note

The IAM roles for Trellix appliances include six roles that grant access privileges needed to perform a specific job function

. The roles correspond in name to IAM roles for appliances:

  • Trellix Admin

  • Trellix Analyst

  • Trellix Auditor

  • Trellix Monitor

  • Trellix Operator

  • Trellix Reject

Note

These job-specific roles are product-agnostic rather than product-specific. Each role grants job-specific access privileges for all supported Trellix appliance types: ❌ The uri "file:/paligo/tmp/fireeye/641b8ec39664a/SSEC_2021_1_0/Content/Topics/CloudIAM/CloudIAM__thisCloudIAMRelease_ApplianceList_AND_nopara.flsnp" does not resolve to a parsable document. appliances. The roles act as "fallback roles" because a Trellix appliance will apply a fallback role only for users that are not assigned any appliance-specfic roles.

As an example, the Trellix Auditor role grants permissions typically needed by Auditors on appliances.

Fallback entitlements for HX Series appliance roles

The following roles are specific to HX Series appliances only, and IAM does not provide fallback roles for these roles:

  • HX Series appliance Analyst SR

  • HX Series appliance API Admin

  • HX Series appliance API Analyst

  • HX Series appliance FE Services

  • HX Series appliance Investigator

If a user account is not assigned any HX Series appliance roles, then HX Series appliance local role capabilities are used for these roles.

Viewing the roles

To view the list of fallback roles for Trellix appliances, filter the list of roles on the Name column.

Requirements
To view the list of IAM roles for Trellix appliances:
  1. Select Organization Settings > Roles.

  2. Filter the list on the Name column, specifying the match the string

    FireEye Appliance
    in mixed-case letters as shown. (The filter is case-sensitive.)

    The list refreshes and shows only the six fallback roles for Trellix appliances, plus the Trellix Appliance Org Admin role.

    CloudIAM_Roles_FireEye_7_Fallback_1-6.png

    Each global fallback role maps to a single entitlement that represents a collection of individual access privileges for a specific role for any appliance type.

List of entitlements