In the Armor Management Portal (AMP), roles are similar to job titles that you must create and assign to your users. When you create a new role, you can populate that role with specific permissions. These permissions determine the type of access a user has in AMP.
...
Info |
---|
When you create a new user, you must assign that user a role. |
There are two ways to assign a user to a role:
- Assign a default role with permissions already enabled in AMP.
- To learn more, see Assign a default role.
- Create a new role, populate that role with your preferred permissions, and then assign that role to a user.
- To learn more, see Create and assign a new role.
Note |
---|
To review Frequently Asked Questions (FAQs) regarding roles and permissions in AMP, see Introduction to Roles and Permissions. |
...
Note | |
---|---|
In AMP, you can easily identify a default role by the orange Armor badge that displays next to the role name. You cannot edit the permissions within the default roles. | |
Expand | |
title | Permissions in the default Admin role
The default Admin role contains every permission available.
This role is automatically assigned to a new administrator account.
This role is automatically updated with new permissions after an AMP release.
Note |
---|
With the Admin role, you can also view the specific routes associated with each permission. |
- In the Armor Management Portal (AMP), in the left-side navigation, clickAccount.
- ClickRoles + Permissions.
- Locate and select the desired role.
- Click the expand arrow for the permission that you want to view.
...
...
Permissions in the default
...
billing role
At a high-level, the default Billing role contains mostly read-only permissions.
Note |
---|
This role is not automatically updated with new permissions after an AMP release. |
Review the following table to better understand the specific permissions associated with the default Billing role.
AMP Screen | Permission | Description |
---|---|---|
Security Dashboard (landing page) | Read Dashboard Statistics | This permission allows you to view the widgets (and corresponding data) that populate the security dashboard. These widgets display a high-level status of your virtual machines, agents, and open security incidents. |
Malware Protection | Read AVAM | This permission allows you to view antivirus and anti-malware (malware protection) details for each virtual machine. |
FIM | Read FIM | This permission allows you to view file integrity details for each virtual machine. |
Patching | Read OS Packages | This permission allows you to view details OS patching details for each virtual machine. |
Intrusion Detection | Read IDS | This permission allows you to view intrusion detection data. |
Log & Data Management | Read LogManagement | This permission allows you to view high-level information for log collection for each virtual machine, such as:
|
Log & Data Management | Read LogSearch | This permission allows you to view details for log collection, such as the specific log message, for each virtual machine. |
Firewall | Read Firewall | This permission allows you to view details for firewall rules for each virtual machine. |
Marketplace | Read Product Catalog | This permission allows you to view available add-on products. You must have this permission enabled in your account in order to view purchased services and also to order new services in AMP. |
Marketplace (and My Products) | View Subscriptions | This permission allows you to view subscription-based add-on products in the My Products screen of the User Details screen. |
Workloads | Read Workload(s) | This permission allows you to view high-level data for workloads, such as
|
Virtual Machines | Write Orders | This permission allows you to provision a new virtual machine. |
Virtual Machines | Read Virtual Machine Stats | This permission allows you to view usage data for a virtual data. This data is displayed in a line graph. |
Virtual Machines | Read Virtual Machine(s) | This permission allows you to view data for a virtual machine, such as
|
Virtual Machines | Read Location(s) | This permission allows you to view a list of available Armor data centers when you manage your virtual machines. |
Virtual Machines | Read Virtual Data Centers | This permission allows you to view the list of virtual environments in your account. |
Virtual Machines | Read Server Replication | This permission allows you to view high-level data for the server replication (disaster recovery) add-on product. Specifically, this permission allows you to view:
|
Virtual Machines | Read Tasks | This permission allows you to view pending tasks, such as a scheduled delete or downsize of a virtual machine. |
Virtual Machines | Read Storage | This permission allows you to view disk and storage information for a virtual machine. |
IP Addresses | Read Network IP | This permission allows you to view data for unassigned and assigned public and private IP addresses |
IP Addresses | Read Network NAT | This permission allows you to view DNAT assignments. |
L2L VPN | Read Network L2L | This permission allows you to view high-level data for your L2L network tunnels. |
SSL/VPN | Read SSL VPN Devices and Users | This permission allows you to view the status of your users' SSL VPN client. |
Compliance | Read Compliance | This permission allows you to view information for the vulnerability scanning add-on product information. Specifically, you will see the status of the add-on product. |
Tickets | Read Ticket(s) | This permission allows you to view support tickets listed in the ViewArchivedTickets section. |
Overview (Account screen) | Read Identity | This permission allows you to view the account-level information, such as
|
User Detail | Update Personal Identity | This permission allows you to update your personal account information, such as your:
|
User Detail | Read Notification(s) | This permission allows you to view the notification preferences for your users, such as a user's preference to receive an email regarding technical updates. |
Invoices | View Invoices | This permission allows you to view current and previous invoices. |
Payment Methods | Read Payment Information | This permission allows you to view current payment information, such as the primary payment method. |
Payment Methods | Write / Update Payment Information | This permission allows you to update the payment information, such as adding a new credit card or assigning a new primary payment method |
Not applicable | Read Entity Metadata | This permission allows you to view optional notes and tags that have been added to various AMP resources, such as a note added to a virtual machine. |
Not applicable | Write Entity Metadata | This permission allows you to add, update, and delete optional notes and tags to various AMP resource, such as adding a note to a virtual machine. |
Not applicable | Global Search | This permission allows you to use the global search function throughout AMP. |
...
...
Permissions in the default
...
technical role
At a high-level, the default Technical role contains read-only and write-only permissions, with a focus on security and infrastructure resources in AMP.
Note |
---|
This role is not automatically updated with new permissions after an AMP release. |
Review the following table to better understand the specific permissions associated with the default Technical role.
AMP Screen | Permission | Description |
---|---|---|
Security Dashboard (landing page) | Read Dashboard Statistics | This permission allows you to view the widgets (and corresponding data) that populate the security dashboard. These widgets display a high-level status of your virtual machines, agents, and open security incidents. |
Malware Protection | Read AVAM | This permission allows you to view antivirus and anti-malware (malware protection) details for each virtual machine. |
FIM | Read FIM | This permission allows you to view file integrity details for each virtual machine. |
Patching | Read OS Packages | This permission allows you to view details OS patching details for each virtual machine. |
Intrusion Detection | Read IDS | This permission allows you to view intrusion detection data. |
Log & Data Management | Read LogManagement | This permission allows you to view high-level information for log collection for each virtual machine, such as:
|
Log Management | Read LogSearch | This permission allows you to view details for log collection, such as the specific log message, for each virtual machine. |
Log Management | Write LogManagement | This permission allows you to update the log management service, specifically the permission to upgrade the log retention plan. |
Firewall | Read Firewall | This permission allows you to view details for firewall rules for each virtual machine. |
Firewall | Write Firewall | This permission allows you to add, update, or delete firewall rules. |
Marketplace | Read Product Catalog | This permission allows you to view available add-on products. You must have this permission enabled in your account in order to view purchased services and also to order new services in AMP. |
Marketplace (and My Products) | View Subscriptions | This permission allows you to view subscription-based add-on products in the My Products screen of the User Details screen. |
Marketplace (and My Products) | Write Subscriptions | This permission allows you to view the Armor Marketplace, as well as add and cancel subscription-based add-on products. Specifically, you can add the subscription in the Armor Marketplace, and then cancel the subscription in the My Products screen of the User Details screen. |
Workloads | Read Workload(s) | This permission allows you to view high-level data for workloads, such as
|
Workloads | Write Workload | This permission allows you to create, update, and remove workloads and tiers. |
Virtual Machines / VM Details | Write Orders | This permission allows you to provision a new virtual machine. |
Virtual Machines / VM Details | Read Virtual Machine Stats | This permission allows you to view usage data for a virtual data. This data is displayed in a line graph. |
Virtual Machines / VM Details | Read Virtual Machine(s) | This permission allows you to view data for a virtual machine, such as
|
Virtual Machines / VM Details | Scale Virtual Machine | This permission allows you upgrade or downgrade (resize) the size of a virtual machine. |
Virtual Machines / VM Details | Write Virtual Machine | This permission allows you to create, update, and remove virtual machines. |
Virtual Machines / VM Details | Read Location(s) | This permission allows you to view a list of available Armor data centers when you manage your virtual machines. |
Virtual Machines / VM Detail | Read Virtual Data Centers | This permission allows you to view the list of virtual environments in your account. |
Virtual Machines | Read Server Replication | This permission allows you to view high-level data for the server replication (disaster recovery) add-on product. Specifically, this permission allows you to view:
|
Virtual Machines | Write Server Replication | This permission allows you to order and cancel the server replication add-on product. |
Virtual Machines | Read Tasks | This permission allows you to view pending tasks, such as a scheduled delete or downsize of a virtual machine. |
Virtual Machines | Write Tasks | This permission allows you to schedule a delete or downsize of a virtual machine. |
Virtual Machines | Read Storage | This permission allows you to view disk and storage information for a virtual machine. |
IP Addresses | Read Network IP | This permission allows you to view data for unassigned and assigned public and private IP addresses |
IP Addresses | Write Network IP | This permission allows you to update an IP address, such as:
|
IP Addresses | Read Network NAT | This permission allows you to view DNAT assignments. |
IP Addresses | Write Network NAT | This permission allows you to add and remove DNAT assignments. |
L2L VPN | Read Network L2L | This permission allows you to view high-level data for your L2L network tunnels. |
L2L VPN | Write Network L2L | This permission allows you to add, update, and remove L2L tunnels. |
SSL/VPN | Read SSL VPN Devices and Users | This permission allows you to view the status of your users' SSL VPN client. |
SSL/VPN | Write SSL VPN Devices and User | This permission allows you to enable your users the ability to download and install the SSL VPN client. |
Compliance | Read Compliance | This permission allows you to view information for the vulnerability scanning add-on product information. Specifically, you will see the status of the add-on product. |
Compliance | Write Compliance | This permission allows you to upgrade, downgrade, or delete the vulnerability scanning add-on product. |
Tickets | Read Ticket(s) | This permission allows you to view support tickets listed in the ViewArchivedTickets section. |
Overview (Account screen) | Read Identity | This permission allows you to view the account-level information, such as
|
User Detail | Update Personal Identity | This permission allows you to update your personal account information, such as your:
|
User Detail | Read Notification(s) | This permission allows you to view the notification preferences for your users, such as a user's preference to receive an email regarding technical updates. |
Not applicable | Read Entity Metadata | This permission allows you to view optional notes and tags that have been added to various AMP resources, such as a note added to a virtual machine. |
Not applicable | Write Entity Metadata | This permission allows you to add, update, and delete optional notes and tags to various AMP resource, such as adding a note to a virtual machine. |
Not applicable | Global Search | This permission allows you to use the global search function throughout AMP. |
Step 2: Assign a default role
...