Vous devez vous connecter en utilisant votre rôle de super administrateur pour gérer le contrôle d'accès des utilisateurs. Lorsque vous créez un compte utilisateur, vous pouvez attribuer un ou plusieurs rôles à l'utilisateur ou vous pouvez également modifier les paramètres de l'utilisateur après l'avoir créé.
Types of user roles and their access controls
Tableau 9. Types de rôles d'utilisateur et leurs contrôles d'accès
User Role
Définition des rôles
Access Control Ares
Super Administrator
Access to all the features
Tableau de bord > Exécutif
Tableau de bord > Sécurité
Tableau de bord > IT Ops
Inventory
Inventaire > Enregistrer la recherche
Inventory > Apply tag
Inventory > Suggest reclassification
Inventory > Report generation
Investigate
Politique
Politique > Créer une politique
Politique > Bloqué périphérique
Gérer > scans
Gérer > actifs
Gérer > Utilisateurs
Gérer > Sites et régions
Manage > Tags and groups
Manage > Integration
Manage >Configuration
Reporting > Saved searches
Reporting > Reports
Reporting > Demandes de reclassement
Network Administrator
Access to network features of the product
Tableau de bord > Exécutif
Inventory
Inventaire > Enregistrer la recherche
Inventory > Apply tag
Inventory > Suggest reclassification
Inventory > Report generation
Investigate
Politique
Politique > Créer une politique
Politique > Bloqué périphérique
Gérer > scans
Gérer > actifs
Gérer > Sites et régions
Manage > Tags and groups
Manage > Integration
Manage >Configuration
Reporting > Saved searches
Reporting > Reports
Security Administrator
Access to security features of the product
Tableau de bord > Exécutif
Tableau de bord > Sécurité
Inventory
Inventaire > Enregistrer la recherche
Inventory > Apply tag
Inventory > Suggest reclassification
Inventory > Report generation
Investigate
Politique
Politique > Créer une politique
Politique > Bloqué périphérique
Gérer > scans
Gérer > actifs
Gérer > Sites et régions
Manage > Tags and groups
Manage > Integration
Manage >Configuration
Reporting > Saved searches
Reporting > Reports
IT Administrator
Access to IT features of the product
Tableau de bord > Exécutif
Tableau de bord > IT Ops
Inventory
Inventaire > Enregistrer la recherche
Inventory > Apply tag
Inventory > Suggest reclassification
Inventory > Report generation
Investigate
Politique
Politique > Bloqué périphérique
Gérer > scans
Gérer > actifs
Gérer > Sites et régions
Manage > Tags and groups
Manage > Integration
Manage >Configuration
Reporting > Saved searches
Reporting > Reports
Super Reader
Access to only read in the defined scope
Tableau de bord > Exécutif
Tableau de bord > Sécurité
Tableau de bord > IT Ops
Inventory
Inventaire > Enregistrer la recherche
Inventory > Report generation
Investigate
Politique
Politique > Bloqué périphérique
Reporting > Saved searches
Reporting > Reports
Scope Based Access Control for Users
When creating a user, in addition to the role, you can also assign the scope for the user. The scope is based on sites and regions in Device Intelligence tenants and you can assign one or more sites and regions when creating the user. The Super Administrator and Super Reader roles does not have any scope based restrictions. Only Super Administrator users can provide scope based access control.
Single Sign-On (SSO) Users
For single sign-on (SSO) users who use external identity providers (IdP) such as Okta, Active Directory, etc for authentication, authorization will depend on role mappings. By default, all SSO users will be mapped to the Super Reader role and have access to all the sites. Super Administrator can modify the default role and scope based access control for SSO Users.
Contrôle d’accès en Device Intelligence - Netskope Documentation technique