> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md).

# Manage user access

{% hint style="warning" %}

### Prerequisite

Managing users, roles, scopes, user groups, authentication settings in Cortex XDR Access Management requires **View/Edit** RBAC permissions for **Access Management** (under **Configurations**). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see *Predefined user roles* in [Set up users and roles](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md).
{% endhint %}

Review the following topics:

* [Set up users and roles](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md)
* [User group management](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md#UUID-c6567cfd-f3f7-da7e-e266-557f3946ec41)
* [Assign user roles and groups](/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md#UUID-61ea0230-3be4-e77f-9899-950d47d74fd8)
* [Manage user roles and access management](/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md)
* [Manage user scope](/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md#UUID-c4e04c0a-5701-9f78-1fd3-ae2c976e7908)

Manage access permissions for Cortex XDR users.

<details>

<summary>Edit user permissions</summary>

Update a user's role and scope, add a user to a user group, and view permissions based on the role, scope, and user groups assigned to the user.

You can configure granular scoping for Scope-Based Access Control (SBAC) by granting access only to the relevant data that the user requires for their designated role. Administrators apply scopes to limit the data and content that users can be granted access to in Cortex XDR, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, and Endpoints, which can be applied as relevant to the enforcement area or entity. For more information, see [Manage user scope](/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md#UUID-c4e04c0a-5701-9f78-1fd3-ae2c976e7908).

{% hint style="info" %}

### Note

* You can only reduce the permissions of an Account Admin user via Cortex Gateway.
* Non-administrator users with **Access Management** permissions are restricted from granting, modifying, or removing the **Instance Administrator** role for any user, user group, or API key. Additionally, the **Edit** and **Remove** buttons are hidden for users who already hold an effective **Instance Administrator** role.
  {% endhint %}

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Edit User Permissions**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>To apply the same settings to multiple users, select them, and then right-click and select <strong>Edit User Permissions</strong>.</p></div>
3. In the **Role** tab, under **Role**, select the default or custom role.
4. (Optional) Under **User Groups**, add the user to a group.
5. (Optional) Under **Show Accumulated Permissions**:

   1. Do one of the following:
      * Select all to view the combined permissions for every role and user group assigned to the user.
      * Select a specific role assigned to the user to view the available permissions for that role.
   2. Under **Components**, expand each list to view the permissions to the various Cortex XDR components.
   3. Under **Datasets**, there are two possibilities for viewing a user's dataset access permissions:
      * When dataset access management is enabled and the user has access to certain Cortex Query Language (XQL) datasets, the datasets are listed.
      * When dataset access management is disabled and users have access to all XQL datasets, the text **No dataset has been selected** is displayed.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>User permissions for components and datasets are based on the access permissions set in the user role. For more information on editing these user role permissions, see <a href="/pages/WBrLWoc8jdNvDqXguED6#UUID-99c7fd76-2fe4-6df8-b439-a0668b13e0d0">Manage user roles</a>.</p></div>
6. (Optional) You can configure granular scoping:

   1. Click the **Scope** tab.
   2. Under **Scope Definition**, expand the scoping areas that you want to grant the user role access to in the tenant by clicking the chevron icon (**>**) beside the scoping area title, and make any changes required. The following table explains the options available to configure:

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Important</h3><p>Before configuring, ensure that you review <strong>Understand scoping</strong> in the <a href="/pages/WBrLWoc8jdNvDqXguED6#UUID-c4e04c0a-5701-9f78-1fd3-ae2c976e7908">Manage user scope</a> section.</p></div>

      | Scoping Area     | Granular Scoping Configurations                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
      | ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
      | Assets           | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No assets</strong>: No asset is accessible.</li><li><strong>All assets</strong>: Defines access to all assets.</li><li><strong>Select asset groups</strong>: Defines access to the specific assets associated with the Asset Groups selected, and to view all their related cases, issues, and findings for these specific assets and Asset Groups. Under <strong>Select asset groups</strong>, define the specific asset groups that you want to grant access. Only Asset Groups relevant for scoping are listed, which are asset groups that are using only the asset attributes listed in <a href="/pages/WBrLWoc8jdNvDqXguED6#UUID-c4e04c0a-5701-9f78-1fd3-ae2c976e7908">Manage user scope</a> (under <strong>Understand scoping</strong> → <strong>Scoping Areas</strong> → <strong>Assets</strong>).</li></ul><p>The scoping of assets also affects the scoping of cases, issues, and findings.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Visibility of Security domain Issues that refer to assets with agents is controlled by the <strong>Endpoints</strong> scoping configuration.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
      | Cases and Issues | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No cases and issues</strong>: Defines access to no cases and issues.</li><li><strong>All cases and issues</strong>: Defines access to all cases and issues. Users can view cases or issues referencing assets within their scope. Use the <strong>Assets</strong> section to define which assets are in scope.</li><li><p><strong>Select domains</strong>: Defines access to the domains selected to view their related cases and issues. Under <strong>Select domains</strong>, define the specific domains that you want to grant access.</p><p>Users can only view cases or issues referencing assets and endpoints within their scope. Use the <strong>Assets</strong> section to define which assets are in scope.</p></li></ul><p>When selecting <strong>All cases and issues</strong> or <strong>Select domains</strong>, you can separately configure access to issues and cases that lack an asset reference or where the referenced asset is not in <strong>All Assets</strong> and <strong>All Endpoints</strong> inventories. To provide access, select the <strong>Allow access to cases and issues that are not referencing known assets or endpoints</strong> checkbox. Once selected, you can specifically control which users have access to issues and cases that lack <strong>Affected Assets</strong> (as seen in the issue’s panel) and <strong>Assets</strong> (as seen in the case's panel), or where the listed assets are not part of the Asset or Endpoint inventories. When the assets listed are not part of the inventories, the asset string is typically non-clickable. In some cases, such as for identity-related issues, assets may open a dedicated <strong>User Risk View</strong>, which differs from the standard inventories panels. In the <strong>Issues</strong> and <strong>Cases</strong> tables, such items can be identified by empty values in the following columns: Asset IDs, Target Agent Identifier, and Source Agent Identifier.</p> |
      | Endpoints        | <p>Set the <strong>Scope</strong> by selecting one of the following:</p><ul><li><strong>No endpoints</strong>: Defines access to no endpoints with no ability to view their related agent management and enterprise policies.</li><li><strong>All endpoints</strong>: Defines access to all endpoints with the ability to view their related agent management and enterprise policies. This configuration can impact the visibility of related <strong>Security</strong> domain <strong>Cases and Issues</strong>, but will not affect asset visibility.</li><li><strong>Select specific (at least one required)</strong>: Defines specific access to all endpoint groups by selecting <strong>Endpoint Groups</strong> or all endpoint tags by selecting <strong>Endpoint Tags</strong> to view their related agent management and enterprise policies. This configuration can impact the visibility of related <strong>Security</strong> domain <strong>Cases and Issues</strong>, but will not affect asset visibility.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Important</h3><p>By default, <strong>Enable Scope Based Access Control</strong> is disabled in Settings → Configurations → General → <strong>Server Settings</strong>, and granular scoping is not enforced. Before enabling SBAC, we recommend that an administrator or a user with <strong>Access Management</strong> permissions first ensures that the users, user groups, and API Keys defined in Cortex XDR are granted the required access by assigning the relevant scopes. For more information, see <a href="/pages/WBrLWoc8jdNvDqXguED6#UUID-c4e04c0a-5701-9f78-1fd3-ae2c976e7908">Manage user scope</a>.</p></div>
7. Click Save.

</details>

<details>

<summary>Import multiple users</summary>

Use a CSV file to import users who belong to a Customer Support Portal account, and assign them roles that are defined in Cortex XDR. You can use the CSV template provided in Cortex XDR, or prepare a CSV file from scratch.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Click **Import Multiple User Roles**.
3. Do one of the following:
   * To use the CSV template, click **Download example file**, and replace the example values with your values.
   * Prepare a CSV file from scratch. Make sure the file includes these columns:
     * User email: Email address of the user belonging to a Customer Support Portal account, for example, <john.smith1@exampleCompany.com>.
     * Role name: Name of the role that you want to assign to this user, for example, Privileged Responder. The role must already exist in Cortex XDR.
     * Is an account role: A boolean value that defines whether the user is designated with an Account Admin role in Cortex Gateway. Set the value to TRUE; otherwise, the value is set to FALSE (default).
4. Locate the file and drag it to the dialog box.
5. Click **Import**.

</details>

<details>

<summary>View user permissions</summary>

View all of the permissions currently assigned to a user.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Edit User Permissions**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>To apply the same settings to multiple users, select them, and then right-click and select <strong>Edit User Permissions</strong>.</p></div>
3. In the **Role** tab, under **Show Accumulated Permissions**, do one of the following:
   * Select all to view the combined permissions for every role and user group assigned to the user.
   * Select a specific role assigned to the user to view the available permissions for that role.
4. Under **Components**, expand each list to view the permissions to the various Cortex XDR components.
5. Under **Datasets**, there are two possibilities for viewing a user's dataset access permissions:
   * When dataset access management is enabled and the user has access to certain Cortex Query Language (XQL) datasets, the datasets are listed.
   * When dataset access management is disabled and users have access to all XQL datasets, the text **No dataset has been selected** is displayed.
6. To view the granular scoping configurations granted to the user role, click the **Scope** tab, and under **Scope Definition**, expand the scoping areas to view the settings by clicking the chevron icon (**>**) beside the scoping area title. The scoping areas include Assets, Cases and Issues, and Endpoints.

</details>

<details>

<summary>Hide user</summary>

There might be instances where you want to hide a user from the list of users, for example, a user that has a Customer Support Portal Super User role but isn't active on your Cortex XDR tenant. After you hide a user, they will no longer be displayed in the list of users when **Show User Subset** is selected on the **Users** page. Non-administrator users with **Access Management** permissions can hide any user, including those assigned the **Instance Administrator** role.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Hide User**.

</details>

<details>

<summary>Add user to a user group</summary>

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Edit User Permissions**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>To apply the same settings to multiple users, select them, and then right-click and select <strong>Edit User Permissions</strong>.</p></div>
3. Under **User Groups**, add the user to a group.
4. Click **Save**.

</details>

<details>

<summary>Deactivate user</summary>

You cannot deactivate a user who has an Account Admin role.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Deactivate User**.
3. Click **Deactivate**.

</details>

<details>

<summary>Remove role assigned to user</summary>

You cannot remove a user who has an Account Admin role.

1. Select **Settings** → **Configurations** → **Access Management** → **Users**.
2. Right-click the relevant user, and select **Remove User Role**.
3. Click **Remove**.

</details>

**User access reference information**

The following is a list of common fields on the **Users** page:

| Field            | Description                                                                                                                                                                                                                                                                                                                                          |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Show User Subset | Displays all users except for hidden users.                                                                                                                                                                                                                                                                                                          |
| User Type        | Indicates whether a user was defined in Cortex XDR using the Customer Support Portal, SSO (single sign-on) using your organization’s IdP, or both Customer Support Portal/SSO.                                                                                                                                                                       |
| Direct XDR Role  | Name of the role specifically assigned to a user. When a user does not have any Cortex XDR access permissions assigned specifically to them, the field displays **No-Role**.                                                                                                                                                                         |
| Groups           | <p>Lists the groups to which a user belongs. Any group that was imported from Active Directory displays <strong>AD</strong> beside the group name.</p><p>If a user group has scoping permissions, the users in the group are granted permissions according to the user group settings, even if the user does not have configured scope settings.</p> |
| Group Roles      | Lists the group roles based on the groups to which a user belongs. Hovering over the group role displays the group associated with this role.                                                                                                                                                                                                        |
| Scope            | Lists a summary of the granular scoping configured for the user.                                                                                                                                                                                                                                                                                     |
| Groups Scope     | Lists a summary of the granular scoping configured in the user groups that the user belongs to                                                                                                                                                                                                                                                       |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
