Invite Users to Cloud NGFW for AWS
Table of Contents
Expand all | Collapse all
-
- About Cloud NGFW for AWS
- Getting Started from the AWS Marketplace
- Register Your Cloud NGFW Tenant with a Palo Alto Networks Support Account
- Cloud NGFW for AWS Pricing
- Cloud NGFW Credit Distribution and Management
- Cloud NGFW for AWS Free Trial
- Cloud NGFW for AWS Limits and Quotas
- Subscribe to Cloud NGFW for AWS
- Locate Your Cloud NGFW for AWS Serial Number
- Cross-Account Role CFT Permissions for Cloud NGFW
- Invite Users to Cloud NGFW for AWS
- Manage Cloud NGFW for AWS Users
- Deploy Cloud NGFW for AWS with the AWS Firewall Manager
- Enable Programmatic Access
- Terraform Support for Cloud NGFW AWS
- Provision Cloud NGFW Resources to your AWS CFT
- Configure Automated Account Onboarding
- Usage Explorer
- Create a Support Case
- Cloud NGFW for AWS Certifications
- Cloud NGFW for AWS Privacy and Data Protection
-
-
- Prepare for Panorama Integration
- Link the Cloud NGFW to Palo Alto Networks Management
- Unlink the Cloud NGFW from Palo Alto Networks Management
- Associate a Linked Panorama to the Cloud NGFW Resource
- Use Panorama for Cloud NGFW Policy Management
- View Cloud NGFW Logs and Activity in Panorama
- View Cloud NGFW Logs in Strata Logging Service
- Tag Based Policies
- Configure Zone-based Policy Rules
- Enterprise Data Loss Prevention (E-DLP) Integration with Cloud NGFW for AWS
-
- Strata Cloud Manager Policy Management
Invite Users to Cloud NGFW for AWS
Learn about the various user roles and how to invite users to a Cloud NGFW for AWS
tenant.
As a Tenant Admin, you can invite additional
users to help manage your Cloud NGFW deployment. You can then place
these new users into the roles necessary for their level of access.
When you invite a user to the Cloud NGFW tenant, by specifying the
user’s email address and assigning one or more Cloud NGFW roles,
the Cloud NGFW tenant sends the user an email that includes a registration
link and temporary password. After logging in for the first time,
the new user will be prompted to create a new password. Until the
invited user has accepted the invitation and logged in to the tenant,
the invitation is considering pending.
Cloud NGFW Role | Permissions |
---|---|
Admin
|
|
Tenant Admin |
|
Tenant Reader
|
|
Local Firewall Admin |
Local
firewall administrators can only create NGFWs and associate rulestacks
within a specified AWS account. |
Local Rulestack Admin |
Each
Local Rulestack Admin has an account ID associated with it. This
allows local rulestacks created by that admin with NGFWs in the
same account. |
The email address domain of users invited
by the tenant admin must match the email address domain of the tenant
admin’s login credentials.
- Log in to the Cloud NGFW tenant.Select SettingsUsers and RolesInvite User.Enter the FirstName, LastName, and Email address of the invitee.Select the new user’s role or roles from the Roles drop-down. You can now invite an existing user to a Cloud NGFW tenant.Click Create.After logging in you will be prompted to Select a Tenant and click Continue. If you are a new user, you will receive an activation email through which you can register to SSO and log in to the tenant. Existing users can login to the tenant directly using your SSO.
Considerations for Multi-Account Use Cases
If an AWS client account is already added to a tenant from the CNGFW console, then during the subscription process the user has a choice to login with exiting tenant or create a new one. The table below illustrates these use cases:Use caseStepsIf you are already registered to SSOYou will not receive an activation emailIf you are an existing user who is not registered to SSOYou will receive an activation email to complete registration to SSO. However, you can still choose to sign in like earlier, until you complete the registration.Use a single email id to register to different tenants using Login with an Existing Tenant option.After logging in you will be prompted to Select a Tenant and click Continue. If you are a new user, you will receive an activation email through which you can register to SSO and log in to the tenant. Existing users can login to the tenant directly using your SSO.