Mandiant Incident Response Cloud IAM Access Guide 2022.1

Prev Next

Providing your Mandiant Incident Response Consultant with access to your Cloud IAM products

This section covers the following information:

  • About External User Accounts below

  • Adding an External User Account on the next page

About external user accounts

A user account defined in a different IAM organization can be invited to enroll in your IAM organization. After the external user enrolls, the account is visible in the Trellix - FireEye IAM Web UI. For example, you might add an external account to allow a Customer Support engineer to access your organization. You can disable this access later by removing the external user account from your IAM organization.

Permissions assigned in this organization

An external user's access privileges in your organization are specified when you create the account and invite the user to enroll. The user's permissions within your IAM organization cannot be viewed or modified in the user's primary organization or in any other organization in which the user is enrolled. To terminate an external user's access to your organization, you delete the account from your list of users.

Limitations on managing an external user account

The following limitations apply to managing external user accounts:

  • You cannot re-enroll an external user. This must be done from the user's primary organization.

  • You cannot reset the password for an external user. This must be done from the user's primary organization.

  • Deleting an external user account removes the account from the list of External Users in this IAM organization. The account remains intact in its primary organization.



Adding an external user account

To allow a user defined in a different IAM organization to access resources in your own IAM organization, you can add an external user account to your organization, assigning roles that grant the account selected access privileges in your organization. An external user account can be used to allow a partner or Customer Support engineer to access your appliances.

To give the external user account access to your IAM organization, you need to know the email address for that user account. To specify the access privileges granted to the external user, you assign the account one or more roles for each product the user is allowed to access in your organization. User accounts can be assigned roles for more than one product type, and they typically are. A user can be assigned multiple roles for accessing the FireEye Web UI or Helix Web UI. For access to FireEye appliances, a user is typically assigned a role for each product type in the IAM organization.

An external user account retains the access privileges granted in your organization until you edit the account's role assignments or remove the account from the list of external users in your organization.

To add an external user account, you start at the Users page. The main view of the Users page lists internal users and external users separately. After the external user account is added, it appears in the External Users panel.

The following table describes the fields in the Invite User view (used to create a new internal user account) and the Add User view (used to add a user account from another organization):

Field

Description

Email

Enter the user's email address. In FireEye IAM, the account user name is an email address.

  • If you are creating a new user account in this organization, enter the email address that will be used to enroll the account in this organization (the user's primary organization).

  • If you are adding a user account that is defined in an external organization, enter the email address that was used to enroll the account in that organization (the user's primary organization).

NOTE: When you view the lists of all user accounts, the Internal Users list and the External Users list can be sorted and filtered on the Email column.



Field

Description

Available Products

Products

A product type for which the user currently is not assigned roles.

Assign Roles

If you want to assign the user roles for a product in this list, click Grant in this column.

Assigned Products

Products Assigned

A product type for which roles are assigned to the user.

Roles

The roles that the user is currently assigned for this product type.

Options

                    Operations you can perform on this role:                    

  • Configure—Assign or remove individual roles for this product.

  • Remove—Remove all roles for this product from the user account.

Prerequisites

  • IAM Admin access to the FireEye IAM Web UI.

  • The email address by which the user is enrolled in the other IAM organization.        

    • You will enter the email address of one or more Mandiant Consultants.

  • The Products and Roles in which to grant access (as applicable to your environment):        

    • Threat Analytics Platform --> TAP Analyst

    • Cloud HX --> HX Admin

    • Email Threat Prevention --> ETP Org Read Only Admin

To add a user account from a different organization:

  1. Log in to the FireEye IAM Web UI.

  2. Select Organization Settings > Users.

The Users page lists all FireEye IAM user accounts known to your IAM organization.

The Internal Users panel lists user accounts that are defined in your organization.

The External Users panel lists user accounts that are defined in other organizations but which the organization administrator has added and assigned roles.


Screenshot of the Users page showing Internal Users and External Users panels with user lists, columns for Email, Name, Phone Number, Status, and action options.

  1. Click Add in the External Users panel.

  2. Enter the email address under which the user is enrolled in their primary IAM organization, and then click Next.

Screenshot of the Invite User dialog showing the What is the user's email address? field, product selection area, and a Next button on the right of the email input.

  1. In the Available Products list, locate the product type and click Grant.

Screenshot of the Add User page showing the Available Products list with Grant links and the Assigned Products panel with assigned product rows and role columns.



  1. In the Roles tab of the Assign Access for Product dialog box, select the checkbox for each product-specific role you want to assign the user.

    Dialog titled Assign Access for Product - Identity Access Management showing the Roles tab with a table of roles (IAM Admin checked), descriptions, number of permissions, and the Assign button highlighted in the lower-right

  2. Click Assign.

  3. To assign the external user roles for another product type, repeat steps 5 through 7.

  4. After all roles have been assigned, click Add. The user account appears in the External Users panel of the Users main view