Permissions to view Attack Path related Dashboard

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Permissions to view Attack Path related Dashboard

Hello everyone,

 

My team has been assisting a customer with integrating Prisma cloud with their Azure infrastructure. Among the configuration was the creation of various dashboards, including one that is related to attack paths. Currently the only widget on this dashboard is the Runtime Burndown and Inventory which is described here Create and Manage Dashboards. The issue here is, that a number of users cannot even view this dashboard as they receive a "Permission Denied" screen. The Permission Group of the role associated with them has view permission for every setting and update permission for Reports on both Alerts and Compliance. The odd part is, that they can view all other dashboards normally. The dashboard has been shared with all users to make sure this is not a share issue.

Sadly, in the official articles, there is no definite explanation on the permissions that are associated with each of the widgets, in order to troubleshoot, at least I have not found any info.

Any information would be appreciated.

3 REPLIES 3

L3 Networker

Hello! 

The issue is that default dashboards are only available for sysadmins. 

As a workaround they can create a custom dashboard but only limited widgets will be available. This is by design. 

 

Documentation for reference: 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XhZhCAK

 

Please let me know if you have any further questions. 

Hello,

 

I checked the article you sent, and this is an important piece of information. However, this particular dashboard was not created by Palo Alto, but by an engineer from the customer's side as noted in the created by field that appears when pressing the three dots right next to the dashboard's name. That is actually quite puzzling, since as mentioned before, all view permissions have been granted to the roles the particular users that reported it are using.

I guess, since the widget mentions the category of "Code to Cloud" this would most likely be related to compute permissions. 

CPanagiotopoulos_1-1757573591728.png

Thank you again in advance.

Hello!

Yes you are correct. Have you given compute related permissions to the user and role in question? 

If not I encourage you to open a customer support case where we could further assist you. 

  • 168 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!