The following definitions explain some of the fundamental concepts and terminology of IAM solutions.
Roles
Trellix IAM uses roles to control what users can see and do on the products (the services and applications) in an IAM organization. A role specifies permissions for accessing a product type (Trellix appliances or Helix). To allow a user to have certain access permissions on a certain product type, an administrator assigns a role to the user account.
A set of system-defined roles, called global roles grant capabilities that correspond to the set of roles used to control access to Trellix appliances and services through their local user accounts. Global roles are also provided for accessing supported Trellix appliances, for accessing Helix, and also for accessing the Trellix IAM Web UI.
If other combinations of permissions are required for accessing the Trellix IAM Web UI or Helix, you can create your own custom roles that are internal to your own IAM organization.
Entitlements
Trellix IAM uses entitlements to map roles to user access permissions. Entitlements are system-defined entities that map a product type to one or many specific access permissions.
The Trellix IAM Web UI and Helix (previously known as the Threat Analytics Platform, or TAP) have entitlements that each represents an individual, fine-grained user access privilege. Thus the global roles for these products map to multiple entitlements. For details, see IAM global roles for the IAM Web UI and IAM global roles for Helix.
Each role for a Trellix appliance maps to a single entitlement that represents multiple access privileges. For details, see IAM global roles for appliances.
User accounts
The Trellix IAM organization administrator creates user accounts to allow network security staff to access the Trellix IAM Web UI, Helix Enterprise, and supported Trellix appliances. A user account contains information such as email address, group memberships, and entitlements that grant access to a single product type or multiple product types. For more information, see IAM user accounts.
Before a user can log in to a new account, the account must be enrolled in the IAM organization at a self-service enrollment Web site. For details, see Your IAM user account.
User groups
To grant the same access privileges a set of user accounts, an IAM Admin can create a user group. A user group grants its members the combined access privileges specified by multiple sources:
Roles that are assigned directly to the user group.
Roles assigned to each user account that is assigned to the user group
For details, see IAM user groups.