The following table summarizes the IAM initial configuration tasks to be performed by the default IAM organization administrator:
Task | Description |
|---|---|
Configure the IAM Organization | |
Add a description | Verify the information pre-configured by Trellix, and add a description:
See IAM organization. |
Configure global security policies | (Optional) Customize default security policies:
See IAM organization. |
Configure User Access Controls | |
View global roles | View the global (system-defined) IAM roles and their entitlements. System-defined roles provided by Trellix IAM correspond to the capabilities granted by the roles implemented on Trellix Central Management System, Email Security — Server, Network Security, and Endpoint Security (HX) appliances and on cloud-based Helix. Global roles are designed to support the functions that your information security team already performs using those products. |
Add custom roles | (Optional) If you need different groupings of entitlements for IAM Web UI roles or Helix roles, create IAM custom roles. See IAM roles. |
Provision Users | |
Create user accounts | Create an IAM account for every user that needs access to OIDC clients.
See IAM user accounts. NOTE: New users enroll by following emailed links to the enrollment page for your IAM organization and creating their own passwords. After enrolling, users can update their account information, preferences, and password by logging in to the Trellix IAM Web UI with their Trellix IAM credentials. |
Create user groups | (Optional) To manage multiple users at once, create an IAM user group and assign roles to the user group. If you add to the user group a user account that has other roles that were assigned directly, those roles are added to the user group implicitly. See IAM User groups. |