Manage user access ↗
Prerequisite
- Managing users, roles, scopes, user groups, authentication settings in Cortex XSIAM Access Management requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see Predefined user roles in Set up users and roles.
- To make users visible in the Users list within the Cortex tenant, an administrator must first assign them the Cortex User role on the Edit User screen in the Manage User Console of the Customer Support Portal (CSP). This role assignment in the CSP controls both the user's visibility in the tenant and their ability to authenticate via the CSP. For more information, see Cortex Gateway Administrator Guide.
Role and permission management
While the CSP controls initial visibility and access, you must update the specific permissions associated with each role within the tenant itself or via the Roles tab in the Cortex Gateway.
The following applies to user access and retention:
- SSO-only access: To allow a user to appear in the tenant while restricting them to SSO login only, assign them the Cortex User role in the CSP, but do not assign them a direct role or a default role in the Cortex Gateway or the tenant.
- Access revocation: If no role is assigned to a user (either directly or through a user group) in the Cortex Gateway or the tenant, the user cannot access the tenant. The user is subsequently revoked in the Cortex Gateway, and their information is no longer saved.
Manage users in the Cortex XSIAM tenant
Once users are visible in the tenant, perform the following tasks in Cortex XSIAM to edit permissions, import multiple users, view permissions, or manage user status.
Edit user permissions
Update a user's role and scope, add a user to a user group, and view permissions based on the role, scope, and user groups assigned to the user.
You can configure granular scoping for Scope-Based Access Control (SBAC) by granting access only to the relevant data that the user requires for their designated role. Administrators apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information, see Manage user scope.
Note
- You can only reduce the permissions of an Account Admin user via Cortex Gateway.
- Non-administrator users with Access Management permissions are restricted from granting, modifying, or removing the Instance Administrator role for any user, user group, or API key. Additionally, the Edit and Remove buttons are hidden for users who already hold an effective Instance Administrator role.
- Select Settings → Configurations → Access Management → Users.
-
Right-click the relevant user, and select Edit User Permissions.
Tip
To apply the same settings to multiple users, select them, and then right-click and select Edit User Permissions.
- In the Role tab, under Role, select the default or custom role.
- (Optional) Under User Groups, add the user to a group.
-
(Optional) Under Show Accumulated Permissions:
- Do one of the following:
- Select all to view the combined permissions for every role and user group assigned to the user.
- Select a specific role assigned to the user to view the available permissions for that role.
- Under Components, expand each list to view the permissions to the various Cortex XSIAM components.
- Under Datasets, there are two possibilities for viewing a user's dataset access permissions:
- When dataset access management is enabled and the user has access to certain Cortex Query Language (XQL) datasets, the datasets are listed.
- When dataset access management is disabled and users have access to all XQL datasets, the text No dataset has been selected is displayed.
Note
User permissions for components and datasets are based on the access permissions set in the user role. For more information on editing these user role permissions, see Manage user roles.
- Do one of the following:
-
(Optional) You can configure granular scoping:
- Click the Scope tab.
-
Under Scope Definition, expand the scoping areas that you want to grant the user role access to in the tenant by clicking the chevron icon (>) beside the scoping area title, and make any changes required. The following table explains the options available to configure:
Important
Before configuring, ensure that you review Understand scoping in the Manage user scope section.
Scoping Area Granular Scoping Configurations Assets <p>Set the Scope by selecting one of the following:</p><ul><li>No assets: No asset is accessible.</li><li>All assets: Defines access to all assets.</li><li>Select asset groups: Defines access to the specific assets associated with the Asset Groups selected, and to view all their related cases, issues, and findings for these specific assets and Asset Groups. Under Select asset groups, define the specific asset groups that you want to grant access. Only Asset Groups relevant for scoping are listed, which are asset groups that are using only the asset attributes listed in Manage user scope (under Understand scoping → Scoping Areas → Assets).</li></ul><p>The scoping of assets also affects the scoping of cases, issues, and findings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Note</p><p>Visibility of Security domain Issues that refer to assets with agents is controlled by the Endpoints scoping configuration.</p></div> Cases and Issues <p>Set the Scope by selecting one of the following:</p><ul><li>No cases and issues: Defines access to no cases and issues.</li><li>All cases and issues: Defines access to all cases and issues. Users can view cases or issues referencing assets within their scope. Use the Assets section to define which assets are in scope.</li><li><p>Select domains: Defines access to the domains selected to view their related cases and issues. Under Select domains, define the specific domains that you want to grant access.</p><p>Users can only view cases or issues referencing assets and endpoints within their scope. Use the Assets section to define which assets are in scope.</p></li></ul><p>When selecting All cases and issues or Select domains, you can separately configure access to issues and cases that lack an asset reference or where the referenced asset is not in All Assets and All Endpoints inventories. To provide access, select the Allow access to cases and issues that are not referencing known assets or endpoints checkbox. Once selected, you can specifically control which users have access to issues and cases that lack Affected Assets (as seen in the issue’s panel) and Assets (as seen in the case's panel), or where the listed assets are not part of the Asset or Endpoint inventories. When the assets listed are not part of the inventories, the asset string is typically non-clickable. In some cases, such as for identity-related issues, assets may open a dedicated User Risk View, which differs from the standard inventories panels. In the Issues and Cases tables, such items can be identified by empty values in the following columns: Asset IDs, Target Agent Identifier, and Source Agent Identifier.</p> Endpoints <p>Set the Scope by selecting one of the following:</p><ul><li>No endpoints: Defines access to no endpoints with no ability to view their related agent management and enterprise policies.</li><li>All endpoints: Defines access to all endpoints with the ability to view their related agent management and enterprise policies. This configuration can impact the visibility of related Security domain Cases and Issues, but will not affect asset visibility.</li><li>Select specific (at least one required): Defines specific access to all endpoint groups by selecting Endpoint Groups or all endpoint tags by selecting Endpoint Tags to view their related agent management and enterprise policies. This configuration can impact the visibility of related Security domain Cases and Issues, but will not affect asset visibility.</li></ul> Datasets Rows <p>Configure a filterto define the specific subset of rows a user is allowed to access in each raw dataset. A raw dataset is every dataset where Palo Alto Networks data is ingested out-of-the-box or third-party data is ingested using a configured dedicated collector, also called a data source. This filter configuration does not impact the visibility of cases and issues.</p><p>Follow these steps to configure afilter:</p><p>1. For datasets where nofilteris defined, determine how to set the When no filter is defined option as either:</p><ul><li>No rows are accessible (default): Without a configuredfilter, no rows are accessible. Users can query the datasets in Cortex Query Language (XQL) as they have access, but the results will be empty.</li><li>All rows are accessible: Without a configuredfilter, all rows are accessible. Users can query the datasets in Cortex Query Language (XQL) as they have access, and view all results.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Note</p><p>When defining a filter for row-level scoping on raw datasets, queries based on the Cortex Data Model (XDM) are not supported. XDM queries return specific rows only when All rows are accessible is selected and no filter is defined in the Datasets Rows scoping area. Otherwise, no rows are returned.</p></div><p>2. Define any filters for the applicable datasets listed in the table:</p><p>1. Scroll down the list of datasets to the dataset you want to apply afilteron, and click the Edit Scope icon.</p><p>2. In the Define what rows are accessible window, continue to write the query for thefilterin the query box (where the syntax is a limited subset of XQL) to limit the data rows for the selected dataset according to the access permissions you want the user to have. The beginning of the query is already defined before the query box, and there is no need to include this in your query.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Important</p><p>For optimal performance, we recommend using a single field in thefilterdefinition and simple comparison operators.</p></div><p>FIXME_ACCORDION_PLACEHOLDER</p><p>3. (Optional) Set the Time frame for the query. The default is Last 1 day.</p><p>4. (Optional) You can preview the query results displayed based on your defined query by clicking Preview. You can edit your query until you're satisfied with the output. By default, the query results are limited to 1000 records.</p><p>5. When you are finished, click Done.</p><p>The Scope field for the dataset that you added the filter on is updated with the query.</p><p>Example 13. **null
</p><p>3. Scroll down the list of datasets to the dataset you want to apply afilteron, and click the Edit Scope icon.</p><p>4. In the Define what rows are accessible window, continue to write the query for thefilterin the query box (where the syntax is a limited subset of XQL) to limit the data rows for the selected dataset according to the access permissions you want the user to have. The beginning of the query is already defined before the query box, and there is no need to include this in your query.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Important For optimal performance, we recommend using a single field in thefilterdefinition and simple comparison operators.</p></div><p>FIXME_ACCORDION_PLACEHOLDER</p><p>5. (Optional) Set the Time frame for the query. The default is Last 1 day.</p><p>6. (Optional) You can preview the query results displayed based on your defined query by clicking Preview. You can edit your query until you're satisfied with the output. By default, the query results are limited to 1000 records.</p><p>7. When you are finished, click Done.The Scope field for the dataset that you added the filter on is updated with the query.Example 13. **null
</p>
Important
By default, Enable Scope Based Access Control is disabled in Settings → Configurations → General → Server Settings, and granular scoping is not enforced. Before enabling SBAC, we recommend that an administrator or a user with Access Management permissions first ensure that the users, user groups, and API Keys defined in Cortex XSIAM are granted the required access by assigning the relevant scopes. For more information, see Manage user scope.
- Click Save.
Import multiple users
Use a CSV file to import users who belong to a Customer Support Portal account, and assign them roles that are defined in Cortex XSIAM. You can use the CSV template provided in Cortex XSIAM, or prepare a CSV file from scratch.
- Select Settings → Configurations → Access Management → Users.
- Click Import Multiple User Roles.
- Do one of the following:
- To use the CSV template, click Download example file, and replace the example values with your values.
- Prepare a CSV file from scratch. Make sure the file includes these columns:
- User email: Email address of the user belonging to a Customer Support Portal account, for example, john.smith1@exampleCompany.com.
- Role name: Name of the role that you want to assign to this user, for example, Privileged Responder. The role must already exist in Cortex XSIAM.
- Is an account role: A boolean value that defines whether the user is designated with an Account Admin role in Cortex Gateway. Set the value to TRUE; otherwise, the value is set to FALSE (default).
- Locate the file and drag it to the dialog box.
- Click Import.
View user permissions
View all of the permissions currently assigned to a user.
- Select Settings → Configurations → Access Management → Users.
-
Right-click the relevant user, and select Edit User Permissions.
Tip
To apply the same settings to multiple users, select them, and then right-click and select Edit User Permissions.
- In the Role tab, under Show Accumulated Permissions, do one of the following:
- Select all to view the combined permissions for every role and user group assigned to the user.
- Select a specific role assigned to the user to view the available permissions for that role.
- Under Components, expand each list to view the permissions to the various Cortex XSIAM components.
- Under Datasets, there are two possibilities for viewing a user's dataset access permissions:
- When dataset access management is enabled and the user has access to certain Cortex Query Language (XQL) datasets, the datasets are listed.
- When dataset access management is disabled and users have access to all XQL datasets, the text No dataset has been selected is displayed.
- To view the granular scoping configurations granted to the user role, click the Scope tab, and under Scope Definition, expand the scoping areas to view the settings by clicking the chevron icon (>) beside the scoping area title. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows.
Hide user
There might be instances where you want to hide a user from the list of users, for example, a user that has a Customer Support Portal Super User role but isn't active on your Cortex XSIAM tenant. After you hide a user, they will no longer be displayed in the list of users when Show User Subset is selected on the Users page. Non-administrator users with Access Management permissions can hide any user, including those assigned the Instance Administrator role.
- Select Settings → Configurations → Access Management → Users.
- Right-click the relevant user, and select Hide User.
Add user to a user group
- Select Settings → Configurations → Access Management → Users.
-
Right-click the relevant user, and select Edit User Permissions.
Tip
To apply the same settings to multiple users, select them, and then right-click and select Edit User Permissions.
- Under User Groups, add the user to a group.
- Click Save.
Deactivate user
You cannot deactivate a user who has an Account Admin role.
- Select Settings → Configurations → Access Management → Users.
- Right-click the relevant user, and select Deactivate User.
- Click Deactivate.
Remove role assigned to user
You cannot remove a user who has an Account Admin role.
- Select Settings → Configurations → Access Management → Users.
- Right-click the relevant user, and select Remove User Role.
- Click Remove.