Overview of Central Management System user interfaces

Prev Next

The Central Management System appliance has the following user interfaces:

    Two user interfaces that are external to the Central Management System appliance pertain to using the appliance in a Trellix Helix environment:

    • Trellix Helix Web UI―An interface that provides a single view of alerts from all the Helix appliances in your network. For more information, see the Helix User Guide

    • Trellix Cloud IAM Web UI―An interface to the Cloud IAM server. It is used primarily by your IAM organization administrator (a user account that Trellix provides for you along with your IAM organization). The administrator creates Trellix Cloud accounts for users and applies role-based and rule-based access controls. This is described in "Trellix Cloud IAM User Accounts" in the System Security Guide.

      Important

      There are two versions of IAM. If the URL you use to access the IAM UI ends with fireeye.com, this document pertains to you. If the URL you use to access the IAM UI ends with trellix.com, see the Trellix IAM Guide for information regarding IAM.

      The owners of these user accounts can also log in to the Trellix Cloud IAM Web UI. Their access privileges in the Trellix Cloud IAM Web UI are generally limited updating their account preferences and changing their passwords. This is described in "Your Trellix Cloud IAM User Account" in the System Security Guide.

    Access to the Trellix Cloud IAM Web UI is necessary for you to configure support for single sign‑on (SSO) authentication. When SSO authentication is enabled and Helix mode is enabled on Trellix appliances, users can sign in once to authenticate to their Trellix Cloud Account and then navigate among the components without having to log in locally to each appliance. This is described in "Single Sign-On Authentication" in the System Security Guide.

    Caution

    Do not change the password for the permanent api_analyst user account on the Central Management System server. Doing so could break the connection between the Central Management System server and Helix. If you need API connectivity between the Central Management System server and a third-party product, add another user account with the api_analyst role.