Oracle Cloud Infrastructure (OCI) provider permissions ↗
When you set up Cortex XSIAM to collect data from your cloud environments, the onboarding wizard will ensure that the correct permissions are granted for Cortex XSIAM. The following tables list the permissions required for each of the options available in the onboarding wizards.
The following reference tables are organized by capability and then the list of the CSP permissions being requested.
Discovery engine
"Discovery Engine" read only access. Grants read-only access to OCI tenancy and resources.
ADS
| Permission | Module | Scope | Purpose |
|---|---|---|---|
| Admit group CortexOutpostGroup of tenancy CortexOutpost to use volumes in tenancy | ADS | In tenancy | Allow creation of backups from volumes |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to use key-delegate in tenancy | ADS | In tenancy | Re-encrypt backups during copy/restore operations |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to associate keys in tenancy with volumes in tenancy CortexOutpost | ADS | Volumes in tenancy | Associate encryption keys with volumes during backup/restore |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to use tag-namespaces in tenancy | ADS | In tenancy | Enable tagging for permission scoping, resource tracking, and cost visibility |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where request.operation != 'DeleteBootVolumeBackup' | ADS | Excludes delete | Allow full management of boot volume backups except deletion |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to manage boot-volume-backups in tenancy where target.resource.tag.cortex_m-o-lcaas_id.panw_capability = 'cortex-scan-platform' | ADS | Only boot-volume-backups tagged with panw_capability = cortex-scan-platform | Restrict deletion to Cortex scan-related resources only |
| Admit group CortexOutpostGroup of tenancy CortexOutpost to read all-resources in tenancy | ADS | In tenancy | Read-only access to all resources |
Registry scan
Dynamic group permissions
| Permission | Scope | Purpose |
|---|---|---|
| Allow dynamic-group registry-scan to manage buckets in tenancy | Tag-scoped (project_id) | Manage Object Storage buckets for scan artifacts/results |
| Allow dynamic-group registry-scan to manage objects in tenancy | Tag-scoped (project_id) | Upload/download image layers, manifests, and reports |
| Allow dynamic-group registry-scan to read secret-bundles in tenancy | Tag-scoped (project_id) | Retrieve registry credentials from OCI Vault |
| Endorse dynamic-group registry-scan to read repos in any-tenancy | Cross-tenancy | Allow cross-tenancy image pulls for scans |
Inherited base permissions for registry scanning
| Permission | Scope | Purpose |
|---|---|---|
| Allow any-user to manage buckets in tenancy | Tag-scoped (project_id) | Create/manage buckets for scan data |
| Allow any-user to manage objects in tenancy | Tag-scoped (project_id) | Read/write objects (artifacts, logs, results) |
| Allow any-user to use keys in tenancy | Tag-scoped (project_id) | Decrypt secrets for registry access |
| Allow any-user to manage secret-versions in tenancy | Tag-scoped (project_id) | Rotate credentials and manage secret versions |
| Allow any-user to manage secrets in tenancy | Tag-scoped (project_id) | Create/update secrets for scanners |
| Allow any-user to manage secret-family in tenancy | Tag-scoped (project_id) | Broader secret-management rights |
| Allow any-user to manage vaults in tenancy | Tag-scoped (project_id) | Create/administer Vaults for key and secret storage |
| Allow any-user to inspect tag-family in tenancy | Global | Discover tag namespaces/definitions |
| Allow any-user to use tag-family (namespace=cortex_cloud, managed_by=PANW) | Restricted | Restrict tag usage to Palo Alto-managed groups |
| Endorse any-group to use tag-namespaces in any-tenancy | Cross-tenancy | Allow tag namespace usage across tenancies |