Enable Role Based Access for AI Access Security (NGFW Managed by Strata Cloud Manager)
Focus
Focus
AI Access Security

NGFW (Managed by Strata Cloud Manager)

Table of Contents


Enable Role Based Access for AI Access Security (NGFW Managed by Strata Cloud Manager)

Enable role-based access to AI Access Security for NGFW (Managed by Strata Cloud Manager).
  1. Use one of the various ways to access Identity & Access.
  2. (New admins only) Add Access to your tenant where AI Access Security is active.
    This step is required only if the user for which you’re granting AI Access Security access isn't already registered with the Palo Alto Networks Customer Support Portal (CSP).
  3. Assign role-based access for AI Access Security.
    You don't need to configure a tenant role for a user if access to only Enterprise DLP is required.
    1. Select User and for the Identity Address, enter the email address for which you granted access in the previous step.
    2. For Apps & Services, select AI Access Security.
    3. Select a predefined Common Services Role.
  4. Add Another to enable additional role-based access to subscriptions for the admin on Strata Cloud Manager.
    Click Add Another for each subscription you want to enable role-based access. Skip this step if you only want to enable role-based access to AI Access Security.
    1. Enable role-based access for AIOps for NGFW.
      This controls which parts of Strata Cloud Manager the admin has access to. For example, if the assigned role privilege does not allow the admin access to Web Security policy rules then the admin can't implement policy rules to control access to GenAI apps.
    2. Enable role-based access for Enterprise Data Loss Prevention (E-DLP).
      This defines the access privileges to configure Enterprise DLP data patterns and profiles that define what is considered sensitive data that must be blocked.
    3. Enable role-based access for SaaS Security Inline if the license is active.
      Review the role privileges if you're assigning a predefined role to the admin. Role-based access to SaaS Security Inline can give your admin the privileges to tag and configure the risk score for GenAI apps.
  5. Submit.