12-07-2022 07:29 PM
Currently my XDR Tenant only have 1 admin (let's called : "myadmin") account that can view Access Management menu under (Gear)>Configuration, the rest of the account cannot. I tried to change my account's role to Admin Account it's same role as "myadmin" but my account cannot view Access Management, do i miss some role specification to have that access management for my account?
Note : and is it possible to have an account that can only manage the user without have role to view or edit Endpoint/Dashboard menu?
12-09-2022 08:36 AM
Cortex XDR authentication and authorization is a bit complicated...
1. Customer Support Portal (CSP) is used for authentication. Which means you need to have user in CSP to be allowed to login to XDR.
2. Cortex XDR Gateway is responsible for the authorization. Here admin roles are assigned to the users
Permission Management • Cortex XDR Prevent Administrator Guide • Reader • Palo Alto Networks documen...
When you say you changed your role to Account Admin for your user, where did you do that? Did you do it at the Gateway - https://cortex-gateway.paloaltonetworks.com/
What is the assigned role for your user at the gateway?
Try to ask the Account Admin to assign you with Instance Admin role, sign-out and sign-in back again. Instance Admin should have permission to see access management.
12-09-2022 09:11 AM
Yes i have added the user in CSP member, it reflected on the cortex gateway, now im able to see the access management using instance admin role, but when i tried to clone it and change the Endpoint section to "None" then relogin the access management disappeared, i tried to set Endpoint section to as it is, same result..my guess maybe its because cloned roles (not the original), i need some clarification here if it's true..
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!