Identity Security permissions - Configure permissions for Cloud Identity Security and the ITDR add-on. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
Abstract

Configure permissions for Cloud Identity Security and the ITDR add-on.

Identity Security provides centralized visibility and governance over both human and non-human identities across cloud, SaaS, and on-premises environments. Users access these features by going to ModulesIdentity Security.

Identity Security permissions controls the following permissions :

  • Cloud Identity Security (Posture Management): Focuses on identity posture, detecting misconfigured IAM policies, over-privileged accounts, inactive identities, and excessive permissions. For more information, see Cloud Identity Security.

  • Identity Threat Detection and Response (ITDR): Focuses on real-time threat detection, identifying active attacks such as compromised credentials, privilege escalation, lateral movement, and suspicious authentication patterns.

    For more information, see Identity Threat Module (ITDR).

Notice

Cloud Identity Security requires Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.

ITDR requires a separate ITDR add-on.

Permission

Description

Roles Example

None

The user has zero visibility into the Identity Security. All related dashboard widgets are hidden.

View

Read-only access to all Identity Security features (subject to addon/license availability). Users can observe, investigate, and analyze identity data, but cannot make any changes.

  • SOC Tier-1 Analyst: View identity posture issues and ITDR issues during triage.

  • SOC Tier-2 Analyst & Threat Hunter: Deep investigation access to identity issues and threats, but rule/policy changes should be escalated.

View/Edit

Complete control. Includes the ability to create, modify, and delete identity security configurations, detection rules, and conditional access policies.

  • SOC Tier-3 Analyst: May require access to manage conditional access policies and settings during advanced response

  • Security Engineer: Build and tune identity detection rules and access policies.