Assigning Permission Sets - McAfee HISCDE-AB-IA - Host Intrusion Prevention Product Manual

Product guide for use with epolicy orchestrator 4.5
Table of Contents

Advertisement

Managing Your Protection
System management
Intrusion Prevention policy pages and the Host Intrusion Prevention event and client rules pages
under Reporting.
For this Host IPS feature...
IPS
Firewall
General
The global administrator also needs to give ePolicy Orchestrator permissions to handle other
areas that work with Host Intrusion Prevention, including queries and dashboards. For example,
to analyze and manage firewall client rules found on the Host IPS pages under Reporting, a
user needs view permissions for Event Log, view permissions for Systems, view permissions
for System Tree access, and view and change permission for the Host Intrusion Prevention
Firewall feature.
Table 3: Permissions required for working with various features
For these Host IPS features
Host IPS dashboards
Host IPS queries
Host IPS client events and client rules
Host IPS server tasks
Host IPS packages in repository
Host IPS automatic responses
For more information on permission sets, see the ePolicy Orchestrator documentation.

Assigning permission sets

Use this task to assign permissions to Host Intrusion Prevention features on the ePO server.
Before you begin
Determine the Host Intrusion Prevention features to which you want to give access and the
additional permission sets that must be assigned to access all aspects of that Host Intrusion
Prevention feature. For example, to view Firewall Client rules, the user must have permission
to the Firewall feature in the Host Intrusion Prevention permission set, as well as to Event log,
Systems, and System Tree access permission sets.
Task
For option definitions, click ? in the interface.
1
Click Menu | User Management | Permission Sets.
2
Next to Host Intrusion Prevention, click Edit.
3
Select the desired permission for each feature:
• None
• View settings only
• View and change settings
4
Click Save.
24
McAfee Host Intrusion Prevention 8.0 Product Guide for ePolicy Orchestrator 4.5
These permissions are available...
None, view settings only, or view and change settings.
None, view settings only, or view and change settings.
None, view settings only, or view and change settings.
These permission sets are required
Dashboards, Queries
Queries
Systems, System Tree access, Threat Event Log
Server Tasks
Software
Automatic Responses, Event Notifications, Client Events

Advertisement

Table of Contents
loading

This manual is also suitable for:

Host intrusion prevention 8.0

Table of Contents