Role permissions by components
Learn how to manage role permissions in Cortex XDR.
You can manage role permissions in Cortex XDR, which are listed by the various components according to the sidebar navigation in Cortex XDR. Dataset permissions are also included for custom roles. Some components include additional action permissions, such as pivot (right-click) options, to which you can also assign access to, but only when you’ve given the user View/Edit permissions to the applicable component. Whenever you create a new role or edit an existing role, these role permissions are configurable for all Cortex XDR apps and services in the Components tab of the Create Role window on the Roles page. For more information, see Manage user roles.
Note
Cortex XDR provides predefined Palo Alto Networks roles, which have set role permissions. For more information, see Default PANW roles.
The following table explains for each Cortex XDR component and additional action permissions, which are listed according to the sidebar navigation headings, the pages that can be accessed with this role permission with the detailed edit permissions available on each page, and any additional information you should know about the role permissions for this component.
Dashboards & Reports
Dashboards
—
Dashboards & Reports → Dashboard → Data Ingestion dashboard
Change mode
Edit
Mark as default
Save as report template
Dashboards & Reports → Customize → Dashboards Manager
New
Edit
Save as new
Set as default
Save as a report
Private/public
Disable
Delete
Dashboards & Reports → Customize → Widget Library is displayed when the user role permissions is set to at least one of the following:
Dashboards: View/Edit
Reports: View
Ingestion Monitoring
—
Dashboards & Reports → Dashboard → Data Ingestion Dashboard
No detailed View/Edit permissions
Reports
—
Dashboards & Reports → Reports
Delete
Dashboards & Reports → Customize → Reports Templates
New
Delete
Edit
Generate Report
Save as new
Customize → Widget Library is displayed when the user role permissions is set to at least one of the following:
Dashboards: View/Edit
Reports: View
Incident Response
Incident & Alerts
Alerts & Incidents
—
Incident Response → Incidents
All actions
Incident Response → Incidents → Alerts Table → Alerts
All actions
Incident Response → Incident Configuration
All actions
Investigation
Query Center
—
Incident Response → Investigation → Query Builder
Pivot to XQL Query Builder (editor).
Incident Response → Investigation → Query Center
Show results
Rename
Save query results
Schedule queries
Remove queries
Incident Response → Investigation → Scheduled Queries
Show executed queries
Edit
Remove
Rename
Disable
Detection & Threat Intel → Detection Rules → BIOC → BIOC Rules
Add BIOC with View/Edit permissions for the Query Center.
Detection & Threat Intel → Detection Rules → Correlations → Correlation Rules
Add Correlation with View/Edit permissions for the Query Center.
Settings → Configurations → Data Management → Compute Units Usage
View only as an informative page with View permissions for the Query Center.
Editing BIOC and Correlation Rules requires View/Edit permissions for both the Incident Response → Investigation → Query Center and Detections & Threat Intel → Detections → Rules (see below)
Personal Query Library
—
Incident Response → Investigation → Query Builder → XQL Search to access your personal queries in the Query Library tab.
Save to library
Edit
Labels
Description
Private/public
Forensics
—
Incident Response → Investigation → Forensics, where all pages related to Forensics are accessible and all actions can be performed.
Host Insights
—
Incident Response → Investigation → Host Inventory
Can open in asset view without being able to perform any actions.
Assets → Vulnerability Assessment
Exclude
Add comment
Asset View from Quick Launcher → IP View, and pivot (right-click) from a host with a Cortex XDR agent installed.
Response
Action Center
✓
Incident Response → Response → Action Center
Isolate
✓
Incident Response → Response → Action Center → All Actions → New Action and from the Define an Action page, select Isolate.
Endpoints → All Endpoints, and pivot (right-click) from a host with a Cortex XDR agent installed, and select Security Operations → Isolate Endpoint.
Incident Response → Incidents → Executions tab
All actions
Terminate Process
✓
Causality chain view is available from the Alerts table (Incident Response → Incidents → Alerts Table), or from the Query Results after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:
Investigate Causality Chain → Open Card in new tab
Investigate Causality Chain → Open Card in same tab
Quarantine
✓
Causality chain view is available from the Alerts table (Incident Response → Incidents → Alerts Table), or from the Query Results after running a query on the related data. From both of these places, you can pivot (right-click) to the causality chain view from any row in the table and select:
Investigate Causality Chain → Open Card in new tab
Investigate Causality Chain → Open Card in same tab
File Retrieval
✓
Incident Response → Response → Action Center → All Actions → New Action and from the Define an Action page, select Files Retrieval.
Endpoints → All Endpoints, and pivot (right-click) from a host with a Cortex XDR agent installed, and select Security Operations → Retrieve Endpoint Files.
Incident Response → Incidents → Executions tab
Retrieve Support File
File Search
✓
Incident Response → Incidents → Key Assets & Artifacts tab, and search for a file.
Destroy Files
✓
Incident Response → Response → Action Center → All Actions → New Action and from the Define an Action page, select Destroy file.
All actions
Allow List/Block List
✓
Incident Response → Response → Action Center → All Actions → New Action and from the Define an Action page, select either:
Add to block list
Add to allow list
Incident Response → Response → Action Center → Currently Applied Actions → Block List
Disable
Move to Allow List
Edit Comment
Delete
Incident Response → Response → Action Center → Currently Applied Actions → Allow List
Disable
Move to Block List
Edit Comment
Delete
Disable Response Actions
✓
Endpoints → All Endpoints, and pivot (right-click) an endpoint that isn't an iOS endpoint, and select Endpoint Control → Disable Capabilities.
Remediation
✓
Delete Quarantined Files
Incident Response → Response → Action Center → Currently Applied Actions → File Quarantine
Delete
EDL
—
Incident Response → Response → EDL
Add
Delete
Agent Scripts Library
✓
Incident Response → Response → Action Center → Agent Script Library
Run Standard Script
✓
Incident Response → Response → Action Center → Agent Script Library, and any script from the Scripts Library table, where the Outcome column is set to Standard, you can select:
Run
Incident Response → Response → Action Center → All Actions+New Action, and from the Choose page, select Run Endpoint Script.
The standard scripts are available in the Scripts list to select from.
Run High-Risk Script
✓
Incident Response → Response → Action Center → Agent Script Library, and any script from the Scripts Library table, where the Outcome column is set to High Risk, you can select:
Run
Incident Response → Response → Action Center → All Actions+New Action, and from the Choose page, select Run Endpoint Script.
The high-risk scripts are available in the Scripts list to select from.
Script Configurations
✓
Incident Response → Response → Action Center → Agent Script Library
New Script
Edit
Save as new
Delete
Download definitions file
Live Terminal
—
Incident Response → Response → Live Terminal
Incident Response → Incidents → Executions tab
Endpoints → All Endpoints, pivot (right-click) from a host with a Cortex XDR agent installed, and select Security Operations → Initiate Live Terminal.
Automation Rules
—
Incident Response → Response → Automation → Automation Rules
All actions
Detections & Threat Intel
Detections
Rules
✓
Detection & Threat Intel → Detection Rules → IOC → IOC Rules
Add IOC
Edit
Disable
Delete
Add to EDL
Detection & Threat Intel → Detection Rules → BIOC → BIOC Rules
Add BIOC
Import Rules
Disable
Save as new
Open in Query Builder
Detection & Threat Intel → Detection Rules → Correlations → Correlation Rules
Add Correlation
Exclude Rule
Disable
Edit
Save as new
Delete
Detection & Threat Intel → Detection Rules → Exceptions
New Exception
Import Exceptions
Edit
Delete
Export
Editing BIOC and Correlation Rules requires View/Edit permissions for both the Incident Response → Investigation → Query Center (see above) and Detections & Threat Intel → Detections → Rules
Prevention Rules
✓
Detection & Threat Intel → Threat Intel Management → Indicator Rules
Add Rule > Prevention Rule
Add Rule > Detection Rule
Detection Rules → BIOC, select one or more BIOC rules, and right-click:
Add selection to restrictions profile (only agent-supported) rules
Endpoints → Policy Management → Prevention → Profiles, click Add Profile, and select whether to create a new profile or import a profile from a file. Select the applicable platform, and Restrictions as the profile type. When you continue configuring the restrictions profile, the following section is displayed:
Custom Prevention Rules
Request WildFire Verdict Change
✓
From a WildFire report, you can click Report Verdict as Incorrect, and under Suggested Verdict, suggest a new verdict. Open a WildFire report from:
Incident Response → Incidents → Key Assets & Artifacts tab, and under Artifacts, identify a file with a WildFire verdict and click Wildfire Analysis Report
Incident Response → Incidents → Alerts Table → Alerts, hover over the alert, and Investigate. You can open the WildFire report of any file included in the alert Causality Chain.
Assets
Network Configuration
—
Assets → Network Configuration → IP Addresses Ranges
Edit
Delete
Assets → Network Configuration → Internal Domain Suffixes
Edit
You can only edit and delete new IP address ranges added, and not the out-of-the-box IP addresses.
Compliance
—
Assets → Cloud Compliance → Compliance Violation table
Dashboards & Reports → Dashboard → Compliance Violation
Asset Inventory
—
Assets → Asset Inventory
All actions
Assets → Asset Scores
All actions
Assets → Cloud Inventory → All Cloud Assets
All actions
Assets → Asset Scores is displayed when the user role permissions is set to:
Incident Response → Incident & Alerts → Alerts & Incidents
Asset Roles Configuration
—
Assets → Asset Roles Configuration
All actions
Endpoints
Endpoint Administrations
✓
Settings → Exceptions Configuration
All actions
Endpoint Management
✓
Endpoints → All Endpoints
Locate one or more endpoints, right-click and select:
Endpoint Control → Perform Heartbeat
Select one or more endpoints that you want to force the check-in of, and right-click + Alt to open the options menu in advanced mode, and select Endpoint Control → Force Check-in.
Select one or more agents that you want to restart, and right-click + Alt to open the options menu in advanced mode, and select Endpoint Control → Restart Agent.
Endpoint Control → Change Endpoint Alias
Endpoint Control → Upgrade Agent Version
Endpoint Control → Set Agent Proxy
Endpoint Control → Uninstall Agent
Endpoint Control → Delete Endpoint
Endpoint Control → Exclude endpoints from auto upgrade
Endpoint Control → Include endpoints in auto upgrade
Retrieve Endpoint Data
✓
Endpoints → All Endpoints
Locate one or more endpoints, right-click and select Endpoint Control → Retrieve Support File.
Endpoint Scan
✓
Endpoints → All Endpoints
Locate one or more endpoints, right-click and select:
Security Operations → Initiate Malware Scan
Security Operations → Abort Malware Scan
Change Managing Server
✓
Endpoints → All Endpoints
Select one or more agents that you want to move to the target server, and right-click + Alt to open the options menu in advanced mode, and select Endpoint Control → Change managing server.
Pause Protection
✓
Endpoints → All Endpoints
Select the endpoints you want to pause protection on, right-click and select Endpoint Control → Pause Endpoint Protection.
Endpoint Token Management
✓
Endpoints → All Endpoints
On the top right corner of the screen, the Tokens and Passwords icon is displayed, which you can left-click and select:
Retrieve Token
Retrieve Support File Password
Endpoint Groups
—
Endpoints → Endpoint Groups
Add Group
View endpoints
Edit
Delete
Save as new
Export group
Endpoint Prevention Policies
—
Endpoints → Policy Management → Prevention → Policy Rules
View Policy Details
Edit
Save As New
Disable
Delete
Global Exceptions
—
Endpoints → Policy Management → Prevention → Global Exceptions
All actions
Endpoint Profiles
—
Endpoints → Policy Management → Extensions → Profiles
Add Profile
Edit Profile
Save As New
Delete
Endpoint Extension Policies
—
Endpoints → Policy Management → Extensions
Policy Rules:
View Policy Details
Edit
Save As New
Disable
Delete
Profiles
Add Profile
Edit Profile
Save As New
Delete
Device Permanent Exceptions
All actions
Device Temporary Exceptions
All actions
Endpoint Installations
—
Endpoints → Agent Installations
Create
Edit
Delete
64 bit installer
32 bit installer
Hide this row
Show rows
Host Firewall
—
Endpoints → Host Firewall → Rule Groups
New Group
Edit Group
Save As New
Disable Group
Delete Group
Export Group Rules
Import Group Rules
Show rows
Hide rows
Endpoints → Host Firewall → Host Firewall Events
Collect Detailed Host Firewall Logs
Users can still view Extensions profiles when the type is set to host firewall.
Device Control
✓
Device Control Rules
✓
Endpoints → Device Control Violations
Add device to permanent exceptions
Add device to temporary exceptions
Add device to a profile exception
Device Control Exceptions
✓
Endpoints → Policy Management → Extensions
Policy Rules
Profiles
Device Permanent Exceptions
Device Temporary Exceptions
Configurations
General Settings
Auditing
—
Settings → Management Audit Logs
No detailed View/Edit permissions
Settings → Agent Audit Logs
No detailed View/Edit permissions
Settings → XDR Collector Audit Logs
XDR Collector Audit Logs requires a Cortex XDR Pro per GB license.
Alert Notification
—
Notifications
General Configuration
—
Settings → Configurations → General → Server Settings
Timezone:
Edit timezone
Timestamp Format
Edit timestamp format
Email Contacts
Add
Define the incidents target MTTR per incident severity
Set the days and hours
Impersonation Role
Edit impersonation role
Cortex XDR - Analytics
On-demand Analytics
—
Settings → Configurations → Cortex XDR - Analytics
Enable
Identity Analytics
Data Broker
Broker Service
✓
Settings → Configurations → Data Broker → Broker VMs
Add Broker → Download any of the broker images
Add Broker → Generate Token
All applet actions
Pathfinder Applet
✓
Settings → Configurations → Data Broker → Broker VMs, and in the APPS column of the Broker VMs page, the Pathfinder applet is displayed.
All actions
Pathfinder Data Collection
—
Settings → Configurations → Data Collection → Pathfinder Collection Center
All actions
To use the Pathfinder Collection Center page, you need to have View/Edit permission for the Broker Service and the Pathfinder Applet (see permissions above).
Data Collection
Log Collections
—
Settings → Configurations → XDR Collectors → Configuration
All actions
Settings → Configurations → XDR Collectors → Administration
Change Collector Alias
Upgrade Collector Version
Set Collector Proxy
Uninstall Collector
Delete Collector
Retrieve Support Files
Settings → Configurations → XDR Collectors → Groups
Add Group
Edit
Delete
Save as new
Settings → Configurations → XDR Collectors → Installers
Create
Delete
Hide
Settings → Configurations → XDR Collectors → Profiles
Add Profile
Edit
Save As New
Delete
Settings → Configurations → XDR Collectors → Policies
Add Policy
Disable
Delete
Save As New
Edit
Settings → Configurations → Data Collection → Custom Collectors
All actions
Settings → Configurations → Data Collection → Collection Integrations
All actions
Ingestion of logs and data requires a Cortex XDR Pro per GB license
External Alerts Mapping
—
Settings → Configurations → Data Collection → External Alert Mapping
Save as new
Disable
Data Management
Data Management
—
Settings → Configurations → Data Management → Dataset Management
All actions
Settings → Configurations → Data Management → Parsing Rules
All actions
Settings → Configurations → Data Management → Event Forwarding
All actions
To set permissions for Compute Unit Usage, use Integrations → Public API (see table below).
Integrations
Public API
—
Settings → Configurations → Data Management → Compute Unit Usage
Settings → Configurations → Integrations → API Keys
New Key
Edit
Delete
Save as new
Threat Intelligence
—
Settings → Configurations → Integrations → Threat intelligence
Create
Delete
Edit
Long Running HTTP Integrations configuration
—
Settings → Configurations → Integrations → Long Running HTTP Integrations configuration
Last updated
Was this helpful?
