Users & Roles

Accounts created in the Dome9 portal and in the Infinity Portal handle users and roles slightly differently. Dome9 users are created in the Dome9 portal. In the Infinity Portal, users are created for the entire portal and then imported to the CloudGuard CNAPPClosed Cloud-Native Application Protection Platform - a cloud-native security model that encompasses Cloud Security Posture Management (CSPM), Cloud Service Network Security (CSNS), and Cloud Workload Protection Platform (CWPP) in a single holistic platform. integrated into it.

Users

Users interact with CloudGuard with:

Infinity Portal

If you do not see the Users page in the Settings menu, the users on your CloudGuard account are fully managed by the Infinity Portal. For more information, see the Infinity Portal Administration Guide.

If you see the Users page in the Settings menu, then it is necessary to import users created in the Infinity Portal to CloudGuard. For more information, see Adding a New User in the Infinity Portal.

Dome9 Portal

The Users page under the Settings menu shows the users of the current CloudGuard account.

The user that creates the account is the Account Owner. This user manages CloudGuard Account-related issues, such as billing and subscription plan and has the privileges of a Super User. Only one Account Owner exists for each account. An Account Owner can assign a different user as the Account Owner. In this case, the previous Account Owner receives the role of Super User.

CloudGuard uniquely identifies a user with an email address. You cannot create more than one user for each email. If you need a user which is not bound to an email address, create a Service Account.

Caution - Make sure to delete unnecessary SSOClosed Single Sign-On (SSO) - A session/user authentication process that permits a user to enter one name and password in order to access multiple applications. users when they are deactivated or no longer need access to CloudGuard (see Deleting users for more information).

Service Accounts

You can create a Service Account to work with CloudGuard through the API. A service account interaction with CloudGuard using the web interface is not possible. You identify the service account with an API Key ID and API Key Secret. Unlike a regular user, this account is not bound to a specific email address. You can use the service account for administration, maintenance, and all other automation tasks, regardless of the person who does these tasks.

You can assign service accounts the same Roles as regular users. To create a service account, see Adding a New Service Account.

Roles

You can configure roles and assign them to users and service accounts. Then you assign permissions to a role. When you assign a role to a user, the permissions of the role are granted to the user, so it is not necessary to assign these permissions to the user explicitly.

In the Infinity Portal only, these e roles are synchronized with Specific Service Roles in your Infinity Portal account. You can assign the roles to users in the Infinity Portal. For more information, see Adding and Editing User Accounts.

You can configure any number of custom roles to include all the different types of users necessary for your CloudGuard account, each with the permissions applicable to it.

The preconfigured CloudGuard roles include:

You cannot change or delete the preconfigured roles. You cannot delete a role that contains members.

Switch User Roles

In the Dome9 portal, use the menu on the top bar next to your username to select a different role in your CloudGuard account. The role must be configured and assigned to you.

Direct Permissions

You can grant direct permissions to users or roles to perform various actions in CloudGuard. Some permissions can be set separately or as part of other permissions. Some other permissions can only be granted collectively, such as View permissions given by inheritance. For example, the permission for managing Policies also grants permission to view Rulesets and Notifications.

To set direct permissions, select where to apply them (Scope & Controls, Network Security, or Code Security) and then drill down to set the required level of granularity. At each level, you can grant permissions to View or Manage.

To see permissions that you have already set, toggle the Show Selected button.

Configurations

You can manage users, service accounts, and roles in the Users & Roles menu. In the users or roles table, click the menu in the first column to see and select available actions.