<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSP Groups and Roles Assignment question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/571973#M115124</link>
    <description>&lt;P&gt;We have two account numbers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason, AIOps wouldn't activate in the "old" account number where all my firewalls are.&lt;/P&gt;
&lt;P&gt;Cortex XDR is on the other "newer" account number. The SE suggested we move everything from the old to the new account number.&lt;/P&gt;
&lt;P&gt;Problem is, we have different teams and need to limite some asset access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, according to this&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaTCAS" target="_blank"&gt;Support Portal User Role Matrix - Knowledge Base - Palo Alto Networks&lt;/A&gt;&amp;nbsp;we came up with this:&lt;/P&gt;
&lt;P&gt;- There should be two "general" super users/Domain Admins role for the sake of redundancy.&lt;/P&gt;
&lt;P&gt;- Groups are needed as some assets are managed by different teams. There will be a CSP Group per each team.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;Each group should have their own assets assigned.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Each group should have "group super users" and "group standard users" role. This should allow them to manage their own group and access the support portal for their respective assets only and for Cortex XDR.&lt;/P&gt;
&lt;P&gt;- There may be users within the groups with Group Limited or Group BPA roles. These users won't be able to get into Support Portal.&lt;/P&gt;
&lt;P&gt;- Some group users need to be able to get into Cortex XDR. Group roles won't allow it so there is a "Cloud Product" role which does allow it. That means, some users will have two roles: Cloud Product + Group Role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this achievable? We have been testing and came up with some issues with Support Portal. Already opened a case with PANW (02845505) about this as I found a post here recommending to open it as PANW will fix it in their backend.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtafur_0-1704511524725.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56290iDF51DC636F977499/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mtafur_0-1704511524725.png" alt="mtafur_0-1704511524725.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any input you may have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Jan 2024 03:26:52 GMT</pubDate>
    <dc:creator>mtafur</dc:creator>
    <dc:date>2024-01-06T03:26:52Z</dc:date>
    <item>
      <title>CSP Groups and Roles Assignment question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/571973#M115124</link>
      <description>&lt;P&gt;We have two account numbers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For some reason, AIOps wouldn't activate in the "old" account number where all my firewalls are.&lt;/P&gt;
&lt;P&gt;Cortex XDR is on the other "newer" account number. The SE suggested we move everything from the old to the new account number.&lt;/P&gt;
&lt;P&gt;Problem is, we have different teams and need to limite some asset access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, according to this&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaTCAS" target="_blank"&gt;Support Portal User Role Matrix - Knowledge Base - Palo Alto Networks&lt;/A&gt;&amp;nbsp;we came up with this:&lt;/P&gt;
&lt;P&gt;- There should be two "general" super users/Domain Admins role for the sake of redundancy.&lt;/P&gt;
&lt;P&gt;- Groups are needed as some assets are managed by different teams. There will be a CSP Group per each team.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;SPAN&gt;Each group should have their own assets assigned.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;- Each group should have "group super users" and "group standard users" role. This should allow them to manage their own group and access the support portal for their respective assets only and for Cortex XDR.&lt;/P&gt;
&lt;P&gt;- There may be users within the groups with Group Limited or Group BPA roles. These users won't be able to get into Support Portal.&lt;/P&gt;
&lt;P&gt;- Some group users need to be able to get into Cortex XDR. Group roles won't allow it so there is a "Cloud Product" role which does allow it. That means, some users will have two roles: Cloud Product + Group Role.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this achievable? We have been testing and came up with some issues with Support Portal. Already opened a case with PANW (02845505) about this as I found a post here recommending to open it as PANW will fix it in their backend.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtafur_0-1704511524725.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/56290iDF51DC636F977499/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mtafur_0-1704511524725.png" alt="mtafur_0-1704511524725.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for any input you may have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 03:26:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/571973#M115124</guid>
      <dc:creator>mtafur</dc:creator>
      <dc:date>2024-01-06T03:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSP Groups and Roles Assignment question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/571990#M115125</link>
      <description>&lt;P&gt;Interestingly, I cannot access with the test account that has Cloud Product + Group Super User to the KB. Same issue. Changed the account to Super user and problem persists.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully PANW can fix this issue.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 03:32:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/571990#M115125</guid>
      <dc:creator>mtafur</dc:creator>
      <dc:date>2024-01-06T03:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: CSP Groups and Roles Assignment question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/572599#M115214</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="color:var(--ck-color-mention-text);"&gt;&lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70131"&gt;@mtafur&lt;/a&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep us updated on how your case goes. Please let me know if you don't hear anything back on this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 18:13:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/572599#M115214</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2024-01-10T18:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: CSP Groups and Roles Assignment question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/572635#M115216</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220841"&gt;@JayGolf&lt;/a&gt;&amp;nbsp;. Case still going. They tried to fix their backend but no joy. It is currently in "Researching" status.&lt;/P&gt;
&lt;P&gt;I engaged with my SE as this was his suggestion. I'm a bit worried as this is impacting my timeline for AIOps deployment.&lt;/P&gt;
&lt;P&gt;Hopefully they'll fix this week. Whatsmore, I have issues with onboarding devices to AIOps...that's another ticket!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 00:27:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/csp-groups-and-roles-assignment-question/m-p/572635#M115216</guid>
      <dc:creator>mtafur</dc:creator>
      <dc:date>2024-01-11T00:27:18Z</dc:date>
    </item>
  </channel>
</rss>

