User access reference information

The following is a list of common fields on the Users page:

Field Description
Show User Subset Displays all users except for hidden users.
User Type Indicates whether a user was defined in Cortex XSIAM using the Customer Support Portal, SSO (single sign-on) using your organization’s IdP, or both Customer Support Portal/SSO.
Direct XDR Role Name of the role specifically assigned to a user. When a user does not have any Cortex XSIAM access permissions assigned specifically to them, the field displays No-Role.
Groups <p>Lists the groups to which a user belongs. Any group that was imported from Active Directory displays AD beside the group name.</p><p>If a user group has scoping permissions, the users in the group are granted permissions according to the user group settings, even if the user does not have configured scope settings.</p>
Group Roles Lists the group roles based on the groups to which a user belongs. Hovering over the group role displays the group associated with this role.
Scope Lists a summary of the granular scoping configured for the user.
Groups Scope Lists a summary of the granular scoping configured in the user groups that the user belongs to