Create a security managed action ↗
After you have created and assigned a configuration for each of your child tenant’s security actions, you can define the specific managed action on behalf of the child tenant.
- Navigate to each of the following Cortex XSIAM pages and follow the detailed steps:
- Settings → Issue Exception and Exclusion → All Issue Exception & Exclusion Rule page.
- Case & Issues → Case Configuration → Starred Issues → Starred Issues page.
- Inventory → Endpoints → Policy Management → Prevention → Profiles → Prevention Profiles page.
- Investigation & Response → Response → Action Center → Applied Actions → Block List/Allow List → Allow List/Block List page.
-
In the corresponding Configuration panel, select the action configuration you created and allocated to your child tenant.
The corresponding security action Table displays the actions managing the child tenant.
-
Depending on the security action, select:
- Add an exclusion to create an issue exclusion.
- Add a starring configuration to create a starred issue inclusion.
- Add a new profile to create a new endpoint profile.
Profiles you create are automatically cloned to your child tenants.