Identity Security permissions

Identity Security provides centralized visibility and governance over both human and non-human identities across cloud, SaaS, and on-premises environments. Users access these features by going to Modules → Identity Security.

Identity Security permissions controls the following permissions :

* Cloud Identity Security (Posture Management): Focuses on identity posture, detecting misconfigured IAM policies, over-privileged accounts, inactive identities, and excessive permissions.
* Identity Threat Detection and Response (ITDR): Focuses on real-time threat detection, identifying active attacks such as compromised credentials, privilege escalation, lateral movement, and suspicious authentication patterns.

 .

Cloud Identity Security requires Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.

ITDR requires a separate ITDR add-on.

| Permission | Description | Roles Example |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None | The user has zero visibility into the Identity Security. All related dashboard widgets are hidden. | |
| View | Read-only access to all Identity Security features (subject to addon/license availability). Users can observe, investigate, and analyze identity data, but cannot make any changes. | <ul><li>SOC Tier-1 Analyst: View identity posture issues and ITDR issues during triage.</li><li>SOC Tier-2 Analyst &#x26; Threat Hunter: Deep investigation access to identity issues and threats, but rule/policy changes should be escalated.</li></ul> |
| View/Edit | Complete control. Includes the ability to create, modify, and delete identity security configurations, detection rules, and conditional access policies. | <ul><li>SOC Tier-3 Analyst: May require access to manage conditional access policies and settings during advanced response</li><li>Security Engineer: Build and tune identity detection rules and access policies.</li></ul> |

Required and recommended permissions

To effectively secure identities and investigate complex identity-based threats, analysts and engineers require deep visibility into the underlying cloud configurations, automation responses, and compliance standards. Consider adding the following permissions:

| Permission | Permission Level | Reason |
| --------------------------------- | ----------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases & Issues | View | Required. Needed to see the cases and issues generated by Identity Detection Rules. |
| Action Center | View/Edit | Strongly Recommended. Required to track and execute active response actions against compromised identities (e.g., disabling accounts or forcing MFA). |
| Query Center & Query Library | View or View/Edit | Strongly Recommended. Required to run and save XQL investigations on complex identity data. |
| Asset Inventory & Asset Groups | View | Strongly Recommended. Provides essential broader context for the affected identities and how they map to organizational assets. |
| Cloud Security & Compute Policies | View | Strongly Recommended. Dictates the overarching cloud posture and CWP policies governing the identities. |
| Credentials | View | Strongly Recommended. Needed to view the integrations and connections linking Cortex XSIAM to cloud and identity providers (such as AWS, Okta, or Microsoft Entra ID). |
| Playbooks & Scripts | View | Strongly Recommended. Heavily utilized for automated identity remediation, such as auto-disabling compromised accounts or alerting identity owners. |
| Reports & Compliance | View | Recommended. General Reports, Compliance Reports, and Catalog & Assessment Profiles often include identity posture data and frameworks requiring identity security controls. |