Security in a Trellix IAM organization

Prev Next

Trellix IAM provides multiple levels of security.

Allowed email domains

As an option, you can configure the system so that user accounts can be created for specific email domains only.

Single-factor authentication

A Trellix IAM account is always secured using the account user name specified by the administrator, combined with the password created by the user during self-enrollment in the organization.

Two-factor authentication

If the IAM organization is additionally secured by a two-factor authentication (2FA) policy, a user establishes identity by providing the user name and password followed by up to three one‑time passcodes. By default, all three two-factor authentication options are Not Enabled, meaning that the IAM organization does not use 2FA.

Trellix IAM supports Google 2-Step Verification. With a smartphone enrolled as a Google two-factor authentication device, the user obtains a one-time-use password from the Google Authenticator mobile app, an SMS text message, a voice call, or some combination of the three. If the Google Authenticator mobile app is installed on the user's phone, passwords can be generated even when no Internet connection or mobile service is available. In case the authentication device is not available, the user can use a one-time-use password from a set of backup codes that was generated and stored ahead of time.

User password policy

The default password policy enforces password construction requirements, account lockout after a certain number of failed login attempts, and expiration policies. An administrator can select individual requirements and change the values associated with the options.

Note

IAM automatically sends a reminder email 15 days before a user account password is due to expire. If necessary, the system sends a second reminder one day before the password expiration date.

Web UI session timeout

Web UI sessions with IAM automatically expire after a certain period of time. An administrator can also customize this setting.

Role-based access controls

To allow a user to access OIDC clients, the organization administrator assigns the user account a role for each product type that the user needs to access. System-defined global roles are created automatically when Trellix creates an IAM organization.

Global roles grant product-specific user access permissions that are geared toward a job function pertaining to that product.

Global roles are provided for each supported Trellix appliance type.

If your Trellix IAM Web UI role or Helix role has workflows that require a collection of entitlements not covered by a global role, an administrator can create a custom role.