User accounts and system accounts

Prev Next

You can view the list of local accounts on an appliance Web UI or the CLI. For each account, the list shows the account name, role, account status, and account login data. The list is divided into two types of accounts: user accounts and system accounts.

This section describes user account roles and system account roles.

User account roles

User account roles give system administrators finer control over what users can do and see on the appliance. Each user account is associated with a single role, which is a collection of capabilities that allow the user to perform certain operations. A default user account is provided for each of the following user roles, depending on your appliance type.

admin

This role enables a user to perform all appliance product functions and have full access to all Web UI views, all CLI commands, and the API. The primary function of this role is to configure and control the system.

analyst

This role enables a system analyst to focus on detecting malware and taking appropriate action, including setting up alerts and reports.

For more information about analyst roles on Endpoint Security (HX) appliances, see Analyst user account roles specific to Endpoint Security (HX) appliances.

api_admin

This role is a Web service API role, and it grants API access to Endpoint Security (HX) appliance features only. Users assigned the api_admin role can perform all of the functions of an api_analyst, but in addition they can maintain API custom policy channels and can contain hosts.

api_analyst

This role is a Web service API role, and it grants only API access to the appliance features.

api_monitor

This role is a Web service API role, and it grants only API access to existing reports on the appliance. Unlike the api_analyst, an api_monitor cannot generate reports or perform other actions.

auditor

This role enables a user to view System Logs and Audit Logs only. The only other roles that grant access to these logs are the Admin and Monitor roles.

fe_services

This role is a TrellixManaged Defense account used to maintain the connection to the Managed Defense backend. Users assigned this role have API and CLI access to Endpoint Security (HX) appliance features and can run CLI commands, but they cannot log into the Web UI.

monitor

This role grants read-only access to the appliance setting screens, the Health Check page, and the Appliance Update page. A monitor cannot request data or take actions on the system. Monitors do not have access to appliance product features or the API and can only run CLI show commands. On some systems, they also have access to some malware analysis functions.

operator

This role grants a subset of the capabilities associated with the admin role. Operators have read-only access to Web UI dashboards, can run CLI show commands only, and have no access to the API. Operators can adjust some, but not all, appliance settings and can perform log management and appliance updates.

On the Endpoint Security (HX) appliance, Operators can also perform agent upgrades.

reject

A user with a reject user account is automatically locked out and is denied access of any kind to the appliance.

Analyst user account roles Specific to Endpoint Security (HX) appliances

On the Endpoint Security (HX) appliance, these roles represent three tiers of analysts, focusing on the detection of malware and responding appropriately.

analyst

On an Endpoint Security (HX) appliance, this role enables users to perform most Endpoint Security (HX) appliance functions, except approving containment requests and stopping containment. They have no access to agent or appliance settings. They have read-only access to the maintenance of host sets, and they cannot maintain data acquisition scripts. They have no access to the API and can only run CLI show commands.

analyst_sr

On an Endpoint Security (HX) appliance, this role grants users the same capabilities as the analyst role, but they can perform most other Endpoint Security (HX) appliance functions, except approving containment requests and stopping containment. They have no access to agent or appliance settings. They have read-only access to the maintenance of host sets, but can fully maintain data acquisition scripts. They have no access to the API and can only run CLI show commands.

investigator

On an Endpoint Security (HX) appliance, this role enables users to perform the same functions as the analyst and analyst_sr roles, but they can also approve containment requests and stop containment of host endpoints. Investigators have no access to the API and can only run CLI show commands.

System account roles

System accounts are “reserved accounts” that permit remote login for the purpose of specific Trellix system-internal communication. Local password login to these accounts is disabled by default. The user cannot log in to the appliance locally using a password, but can log in using an SSH authorized key.

Note

You cannot create or modify system accounts. The appliance Web UI and CLI display system account status information so that you can verify that these accounts are not used to log in to the appliance. System accounts can be locked out so they cannot be used to log in to the appliance.

On appliances other than the Central Management System appliance, a default system account corresponds to each of the following system-defined roles:

ccd_node

This role enables remote login to Intelligent Virtual Execution - Server compute nodes in an on-premises MVX cluster. Use of this role is limited to internal communication between standard compute nodes and compute nodes that have been designated as broker nodes. This type of communication uses the cluster communication process (CCD) and the TLS/SSH protocol.

ccd_sensor

This role enables remote login to a Intelligent Virtual Execution - Server compute node in an on-premises MVX cluster. Use of this role is limited to internal communication between standard compute nodes and Network Security sensors. This type of communication uses the cluster communication process (CCD) and the GCL protocol that is based on TLS/SSH.

cmcrendv

This role enables remote login to initiate a persistent connection from an appliance to a Central Management System appliance. Use of this role is limited to communication from a rendezvous client and the GCL protocol that is based on SSH.

hasync

This role enables remote login used to initiate a persistent connection between two Network Security nodes in an HA deployment. Use of this role is limited to the HA appliance reboot monitoring daemon (hamon) on the Network Security appliance and the GCL protocol that is based on SSH.