For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Role permissions by components

Learn how to manage role permissions in Cortex XDR.

You can manage role permissions in Cortex XDR, which are listed by the various components according to the sidebar navigation in Cortex XDR. Dataset permissions are also included for custom roles. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access to, but only when you’ve given the user View/Edit permissions to the applicable component. Whenever you create a new role or edit an existing role, these role permissions are configurable for all Cortex XDR apps and services in the Components tab of the Create Role window on the Roles page. For more information, see Manage user roles.

Note

Cortex XDR provides predefined Palo Alto Networks roles, which have set role permissions. For more information, see Default PANW roles.

The following table explains for each Cortex XDR component and additional action permissions, which are listed according to the sidebar navigation headings, the pages that can be accessed with this role permission with the detailed edit permissions available on each page, and any additional information you should know about the role permissions for this component.

Dashboards & Reports
Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Dashboards

  • Dashboards & ReportsDashboardData Ingestion dashboard

    • Change mode

    • Edit

    • Mark as default

    • Save as report template

  • Dashboards & ReportsCustomizeDashboards Manager

    • New

    • Edit

    • Save as new

    • Set as default

    • Save as a report

    • Private/public

    • Disable

    • Delete

Dashboards & ReportsCustomizeWidget Library is displayed when the user role permissions is set to at least one of the following:

  • Dashboards: View/Edit

  • Reports: View

Ingestion Monitoring

Dashboards & ReportsDashboardData Ingestion Dashboard

  • No detailed View/Edit permissions

Reports

  • Dashboards & ReportsReports

    • Delete

  • Dashboards & ReportsCustomizeReports Templates

    • New

    • Delete

    • Edit

    • Generate Report

    • Save as new

CustomizeWidget Library is displayed when the user role permissions is set to at least one of the following:

  • Dashboards: View/Edit

  • Reports: View

Incident Response

Incident & Alerts

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Alerts & Incidents

  • Incident ResponseIncidents

    • All actions

  • Incident ResponseIncidentsAlerts TableAlerts

    • All actions

  • Incident ResponseIncident Configuration

    • All actions

Investigation

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Query Center

  • Incident ResponseInvestigationQuery Builder

    • Pivot to XQL Query Builder (editor).

  • Incident ResponseInvestigationQuery Center

    • Show results

    • Rename

    • Save query results

    • Schedule queries

    • Remove queries

  • Incident ResponseInvestigationScheduled Queries

    • Show executed queries

    • Edit

    • Remove

    • Rename

    • Disable

  • Detection & Threat IntelDetection Rules → BIOC → BIOC Rules

    • Add BIOC with View/Edit permissions for the Query Center.

  • Detection & Threat IntelDetection RulesCorrelationsCorrelation Rules

    • Add Correlation with View/Edit permissions for the Query Center.

  • SettingsConfigurationsData ManagementCompute Units Usage

    • View only as an informative page with View permissions for the Query Center.

Editing BIOC and Correlation Rules requires View/Edit permissions for both the Incident ResponseInvestigationQuery Center and Detections & Threat IntelDetectionsRules (see below)

Personal Query Library

Incident ResponseInvestigationQuery BuilderXQL Search to access your personal queries in the Query Library tab.

  • Save to library

  • Edit

  • Labels

  • Description

  • Private/public

Forensics

Incident ResponseInvestigationForensics, where all pages related to Forensics are accessible and all actions can be performed.

Host Insights

  • Incident ResponseInvestigationHost Inventory

    • Can open in asset view without being able to perform any actions.

  • AssetsVulnerability Assessment

    • Exclude

    • Add comment

  • Asset View from Quick LauncherIP View, and pivot (right-click) from a host with a Cortex XDR agent installed.

Response

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Action Center

Incident ResponseResponseAction Center

Isolate

  • Incident ResponseResponseAction CenterAll ActionsNew Action and from the Define an Action page, select Isolate.

  • EndpointsAll Endpoints, and pivot (right-click) from a host with a Cortex XDR agent installed, and select Security OperationsIsolate Endpoint.

  • Incident ResponseIncidentsExecutions tab

    • All actions

Terminate Process

Causality chain view is available from the Alerts table (Incident ResponseIncidentsAlerts Table), or from the Query Results after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:

  • Investigate Causality ChainOpen Card in new tab

  • Investigate Causality ChainOpen Card in same tab

Quarantine

Causality chain view is available from the Alerts table (Incident ResponseIncidentsAlerts Table), or from the Query Results after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:

  • Investigate Causality ChainOpen Card in new tab

  • Investigate Causality ChainOpen Card in same tab

File Retrieval

  • Incident ResponseResponseAction CenterAll ActionsNew Action and from the Define an Action page, select Files Retrieval.

  • EndpointsAll Endpoints, and pivot (right-click) from a host with a Cortex XDR agent installed, and select Security OperationsRetrieve Endpoint Files.

  • Incident ResponseIncidentsExecutions tab

    • Retrieve Support File

File Search

Incident ResponseIncidentsKey Assets & Artifacts tab, and search for a file.

Destroy Files

Incident ResponseResponseAction CenterAll ActionsNew Action and from the Define an Action page, select Destroy file.

  • All actions

Allow List/Block List

  • Incident ResponseResponseAction CenterAll ActionsNew Action and from the Define an Action page, select either:

    • Add to block list

    • Add to allow list

  • Incident ResponseResponseAction CenterCurrently Applied ActionsBlock List

    • Disable

    • Move to Allow List

    • Edit Comment

    • Delete

  • Incident ResponseResponseAction CenterCurrently Applied ActionsAllow List

    • Disable

    • Move to Block List

    • Edit Comment

    • Delete

Disable Response Actions

EndpointsAll Endpoints, and pivot (right-click) an endpoint that isn't an iOS endpoint, and select Endpoint ControlDisable Capabilities.

Remediation

Delete Quarantined Files

Incident ResponseResponseAction CenterCurrently Applied ActionsFile Quarantine

  • Delete

EDL

Incident ResponseResponseEDL

  • Add

  • Delete

Agent Scripts Library

Incident ResponseResponseAction CenterAgent Script Library

Run Standard Script

  • Incident ResponseResponseAction CenterAgent Script Library, and any script from the Scripts Library table, where the Outcome column is set to Standard, you can select:

    • Run

  • Incident ResponseResponseAction CenterAll Actions+New Action, and from the Choose page, select Run Endpoint Script.

    • The standard scripts are available in the Scripts list to select from.

Run High-Risk Script

Incident ResponseResponseAction CenterAgent Script Library, and any script from the Scripts Library table, where the Outcome column is set to High Risk, you can select:

  • Run

  • Incident ResponseResponseAction CenterAll Actions+New Action, and from the Choose page, select Run Endpoint Script.

    • The high-risk scripts are available in the Scripts list to select from.

Script Configurations

Incident ResponseResponseAction CenterAgent Script Library

  • New Script

  • Edit

  • Save as new

  • Delete

  • Download definitions file

Live Terminal

  • Incident ResponseResponseLive Terminal

  • Incident ResponseIncidentsExecutions tab

  • EndpointsAll Endpoints, pivot (right-click) from a host with a Cortex XDR agent installed, and select Security OperationsInitiate Live Terminal.

Automation Rules

Incident ResponseResponseAutomationAutomation Rules

  • All actions

Detections & Threat Intel

Detections

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Rules

  • Detection & Threat IntelDetection RulesIOCIOC Rules

    • Add IOC

    • Edit

    • Disable

    • Delete

    • Add to EDL

  • Detection & Threat IntelDetection RulesBIOCBIOC Rules

    • Add BIOC

    • Import Rules

    • Disable

    • Save as new

    • Open in Query Builder

  • Detection & Threat IntelDetection RulesCorrelationsCorrelation Rules

    • Add Correlation

    • Exclude Rule

    • Disable

    • Edit

    • Save as new

    • Delete

  • Detection & Threat IntelDetection RulesExceptions

    • New Exception

    • Import Exceptions

    • Edit

    • Delete

    • Export

Editing BIOC and Correlation Rules requires View/Edit permissions for both the Incident ResponseInvestigationQuery Center (see above) and Detections & Threat IntelDetectionsRules

Prevention Rules

  • Detection & Threat IntelThreat Intel ManagementIndicator Rules

    • Add Rule > Prevention Rule

    • Add Rule > Detection Rule

  • Detection RulesBIOC, select one or more BIOC rules, and right-click:

    • Add selection to restrictions profile (only agent-supported) rules

  • EndpointsPolicy ManagementPreventionProfiles, click Add Profile, and select whether to create a new profile or import a profile from a file. Select the applicable platform, and Restrictions as the profile type. When you continue configuring the restrictions profile, the following section is displayed:

    • Custom Prevention Rules

Request WildFire Verdict Change

From a WildFire report, you can click Report Verdict as Incorrect, and under Suggested Verdict, suggest a new verdict. Open a WildFire report from:

  • Incident ResponseIncidentsKey Assets & Artifacts tab, and under Artifacts, identify a file with a WildFire verdict and click Wildfire Analysis Report

  • Incident ResponseIncidentsAlerts TableAlerts, hover over the alert, and Investigate. You can open the WildFire report of any file included in the alert Causality Chain.

Assets
Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Network Configuration

  • AssetsNetwork ConfigurationIP Addresses Ranges

    • Edit

    • Delete

  • AssetsNetwork ConfigurationInternal Domain Suffixes

    • Edit

You can only edit and delete new IP address ranges added, and not the out-of-the-box IP addresses.

Compliance

  • AssetsCloud ComplianceCompliance Violation table

  • Dashboards & ReportsDashboardCompliance Violation

Asset Inventory

  • AssetsAsset Inventory

    • All actions

  • AssetsAsset Scores

    • All actions

  • AssetsCloud InventoryAll Cloud Assets

    • All actions

AssetsAsset Scores is displayed when the user role permissions is set to:

  • Incident ResponseIncident & AlertsAlerts & Incidents

Asset Roles Configuration

AssetsAsset Roles Configuration

  • All actions

Endpoints
Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Endpoint Administrations

SettingsExceptions Configuration

  • All actions

Endpoint Management

EndpointsAll Endpoints

Locate one or more endpoints, right-click and select:

  • Endpoint ControlPerform Heartbeat

  • Select one or more endpoints that you want to force the check-in of, and right-click + Alt to open the options menu in advanced mode, and select Endpoint ControlForce Check-in.

  • Select one or more agents that you want to restart, and right-click + Alt to open the options menu in advanced mode, and select Endpoint ControlRestart Agent.

  • Endpoint ControlChange Endpoint Alias

  • Endpoint ControlUpgrade Agent Version

  • Endpoint ControlSet Agent Proxy

  • Endpoint ControlUninstall Agent

  • Endpoint ControlDelete Endpoint

  • Endpoint ControlExclude endpoints from auto upgrade

  • Endpoint ControlInclude endpoints in auto upgrade

Retrieve Endpoint Data

  • EndpointsAll Endpoints

    • Locate one or more endpoints, right-click and select Endpoint ControlRetrieve Support File.

Endpoint Scan

EndpointsAll Endpoints

Locate one or more endpoints, right-click and select:

  • Security OperationsInitiate Malware Scan

  • Security OperationsAbort Malware Scan

Change Managing Server

EndpointsAll Endpoints

  • Select one or more agents that you want to move to the target server, and right-click + Alt to open the options menu in advanced mode, and select Endpoint ControlChange managing server.

Pause Protection

EndpointsAll Endpoints

  • Select the endpoints you want to pause protection on, right-click and select Endpoint ControlPause Endpoint Protection.

Endpoint Token Management

EndpointsAll Endpoints

On the top right corner of the screen, the Tokens and Passwords icon is displayed, which you can left-click and select:

  • Retrieve Token

  • Retrieve Support File Password

Endpoint Groups

EndpointsEndpoint Groups

  • Add Group

  • View endpoints

  • Edit

  • Delete

  • Save as new

  • Export group

Endpoint Prevention Policies

EndpointsPolicy ManagementPreventionPolicy Rules

  • View Policy Details

  • Edit

  • Save As New

  • Disable

  • Delete

Global Exceptions

EndpointsPolicy ManagementPreventionGlobal Exceptions

  • All actions

Endpoint Profiles

EndpointsPolicy ManagementExtensionsProfiles

  • Add Profile

  • Edit Profile

  • Save As New

  • Delete

Endpoint Extension Policies

EndpointsPolicy ManagementExtensions

  • Policy Rules:

    • View Policy Details

    • Edit

    • Save As New

    • Disable

    • Delete

  • Profiles

    • Add Profile

    • Edit Profile

    • Save As New

    • Delete

  • Device Permanent Exceptions

    • All actions

  • Device Temporary Exceptions

    • All actions

Endpoint Installations

EndpointsAgent Installations

  • Create

  • Edit

  • Delete

  • 64 bit installer

  • 32 bit installer

  • Hide this row

  • Show rows

Host Firewall

  • EndpointsHost FirewallRule Groups

    • New Group

    • Edit Group

    • Save As New

    • Disable Group

    • Delete Group

    • Export Group Rules

    • Import Group Rules

    • Show rows

    • Hide rows

  • EndpointsHost FirewallHost Firewall Events

    • Collect Detailed Host Firewall Logs

Users can still view Extensions profiles when the type is set to host firewall.

Device Control

Device Control Rules

EndpointsDevice Control Violations

  • Add device to permanent exceptions

  • Add device to temporary exceptions

  • Add device to a profile exception

Device Control Exceptions

EndpointsPolicy ManagementExtensions

  • Policy Rules

  • Profiles

  • Device Permanent Exceptions

  • Device Temporary Exceptions

Configurations

General Settings

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Auditing

  • SettingsManagement Audit Logs

    • No detailed View/Edit permissions

  • SettingsAgent Audit Logs

    • No detailed View/Edit permissions

  • SettingsXDR Collector Audit Logs

XDR Collector Audit Logs requires a Cortex XDR Pro per GB license.

Alert Notification

Notifications

General Configuration

SettingsConfigurationsGeneralServer Settings

  • Timezone:

    • Edit timezone

  • Timestamp Format

    • Edit timestamp format

  • Email Contacts

    • Add

  • Define the incidents target MTTR per incident severity

    • Set the days and hours

  • Impersonation Role

    • Edit impersonation role

Cortex XDR - Analytics

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

On-demand Analytics

SettingsConfigurationsCortex XDR - Analytics

  • Enable

  • Identity Analytics

Data Broker

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Broker Service

SettingsConfigurationsData BrokerBroker VMs

  • Add BrokerDownload any of the broker images

  • Add BrokerGenerate Token

  • All applet actions

Pathfinder Applet

SettingsConfigurationsData BrokerBroker VMs, and in the APPS column of the Broker VMs page, the Pathfinder applet is displayed.

  • All actions

Pathfinder Data Collection

SettingsConfigurationsData CollectionPathfinder Collection Center

  • All actions

To use the Pathfinder Collection Center page, you need to have View/Edit permission for the Broker Service and the Pathfinder Applet (see permissions above).

Data Collection

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Log Collections

  • SettingsConfigurationsXDR CollectorsConfiguration

    • All actions

  • SettingsConfigurationsXDR CollectorsAdministration

    • Change Collector Alias

    • Upgrade Collector Version

    • Set Collector Proxy

    • Uninstall Collector

    • Delete Collector

    • Retrieve Support Files

  • SettingsConfigurationsXDR CollectorsGroups

    • Add Group

    • Edit

    • Delete

    • Save as new

  • SettingsConfigurationsXDR CollectorsInstallers

    • Create

    • Delete

    • Hide

  • SettingsConfigurationsXDR CollectorsProfiles

    • Add Profile

    • Edit

    • Save As New

    • Delete

  • SettingsConfigurationsXDR CollectorsPolicies

    • Add Policy

    • Disable

    • Delete

    • Save As New

    • Edit

  • SettingsConfigurationsData CollectionCustom Collectors

    • All actions

  • SettingsConfigurationsData CollectionCollection Integrations

    • All actions

Ingestion of logs and data requires a Cortex XDR Pro per GB license

External Alerts Mapping

SettingsConfigurationsData CollectionExternal Alert Mapping

  • Save as new

  • Disable

Data Management

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Data Management

  • SettingsConfigurationsData ManagementDataset Management

    • All actions

  • SettingsConfigurationsData ManagementParsing Rules

    • All actions

  • SettingsConfigurationsData ManagementEvent Forwarding

    • All actions

To set permissions for Compute Unit Usage, use IntegrationsPublic API (see table below).

Integrations

Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Public API

  • SettingsConfigurationsData ManagementCompute Unit Usage

  • SettingsConfigurationsIntegrationsAPI Keys

    • New Key

    • Edit

    • Delete

    • Save as new

Threat Intelligence

SettingsConfigurationsIntegrationsThreat intelligence

  • Create

  • Delete

  • Edit

Long Running HTTP Integrations configuration

Settings → Configurations → IntegrationsLong Running HTTP Integrations configuration

Help
Components
Additional Action Permissions with View/Edit Permissions
Access Permissions to these Pages with Detailed View/Edit Permissions
Additional Information

Support

HelpSubmit a Support Caser

Last updated

Was this helpful?