Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

User Roles for Data Security

Introduction

Data Security uses the same Eyeglass Role-Based Access Control (RBAC) system as the rest of the Eyeglass platform. This page covers the specific roles and permissions relevant to Ransomware Defender and Data Auditing. For the full RBAC setup procedure — creating roles, assigning permissions, mapping AD groups or users to roles, and logging in with a role account — see the User Role Guide, which documents the complete Eyeglass-wide workflow.

Data Security Roles and Permissions

Role/PermissionPurpose
RANSOMWARE_DEFENDERView and configure Ransomware Defender.
RANSOMWARE_READONLYRead-only view of Ransomware Defender.
EASY_AUDITOR_VIEWView existing reports, queries, and wiretaps.
EASY_AUDITOR_MODIFYAdd and update reports, queries, schedules, and wiretaps.
EyeglassAdmin (OneFS role)Requires ISI_PRIV_IFS_BACKUP (and ISI_PRIV_IFS_RESTORE on OneFS 8.2+) on the PowerScale side, for REST API audit ingestion. See Storage Platform Agent Configuration — Enable REST API audit ingestion.

A built-in role and user account separate the management of Ransomware Defender settings from event monitoring: the Ransomware Defender role manages and monitors the product, while RANSOMWARE_READONLY limits a user to viewing events without the ability to change configuration.

Easy Auditor has its own built-in account for separation of duties — see Easy Auditor Planning and Design.

Assigning Data Security Roles

Follow the Create RolesAssign PermissionsAssign Roles to Users/Groups workflow in the User Role Guide, selecting the Data Security permissions above when assigning permissions to a role. Licensing for each writable PowerScale or ECS cluster (agent license and agent maintenance, which govern which clusters Ransomware Defender actively protects) is covered separately in Pre-Requisites — Licensing and is not controlled by RBAC role assignment.

Prerequisites

Role assignment depends on the same Active Directory and system-zone authentication prerequisites as the rest of Eyeglass RBAC — an AD authentication provider in the PowerScale system zone, SMB/SMB2 enabled between the Eyeglass VM and the cluster, and system zone authentication as the supported proxy login method. See User Role Guide — Requirements for the complete list.

See also