Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 4.4.0

User Roles for Data Security

Introduction

Data Security uses the same Eyeglass Role-Based Access Control (RBAC) system as the rest of the Eyeglass platform, managed from the User Roles menu in the Eyeglass UI. This page covers the specific roles and permissions relevant to Ransomware Defender and Easy Auditor.

Data Security Roles and Permissions

Role/PermissionPurpose
RANSOMWARE_DEFENDERView and configure Ransomware Defender.
RANSOMWARE_READONLYRead-only view of Ransomware Defender.
EASY_AUDITOR_VIEWView existing reports, queries, and wiretaps.
EASY_AUDITOR_MODIFYAdd and update reports, queries, schedules, and wiretaps.

A built-in role and user account separate the management of Ransomware Defender settings from event monitoring: the Ransomware Defender role manages and monitors the product, while RANSOMWARE_READONLY limits a user to viewing events without the ability to change configuration.

Easy Auditor has its own built-in account for separation of duties.

Assigning Data Security Roles

Follow the Create RolesAssign PermissionsAssign Roles to Users/Groups workflow in the Eyeglass UI, selecting the Data Security permissions above when assigning permissions to a role:

  1. Create Roles: Open the User Roles menu and select Create New Role. Define the role's name.
  2. Assign Permissions: Select the created role and assign the appropriate Data Security permissions (for example, RANSOMWARE_DEFENDER or EASY_AUDITOR_MODIFY).
  3. Assign Roles to Users/Groups: In the Roles tab, select the role, then go to the Users or Groups tab and select the plus sign (+) to add a user or AD group to the role. Enter the username or group name, specify whether the account is a remote or local user, and confirm.
  4. Verify Permissions: Log in as a test user to confirm they have the correct access.

AD groups can also be mapped directly to a role: select the role, then use the + button in the Groups section to add the AD group by name.

Prerequisites

Role assignment requires an Active Directory (AD) authentication provider, per the general installation requirements.

See Also