<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about permission profiles regarding Inspection settings in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241269#M40253</link>
    <description>&lt;P&gt;I created a Permission Profile where every option was either disabled or set to Read Only (if it could not be disabled) but with Install Policy allowed.&lt;/P&gt;
&lt;P&gt;When I login it still shows &lt;STRONG&gt;Inspection Settings&lt;/STRONG&gt; but they only opened in Read Only.&lt;/P&gt;
&lt;P&gt;When I modify the Permission Profile so that&amp;nbsp;&lt;STRONG&gt;Common Objects&lt;/STRONG&gt; is set to &lt;STRONG&gt;Write&lt;/STRONG&gt; (so that the administrator can modify Time Objects per your scenario) it also opens Inspection Settings for editing.&lt;/P&gt;
&lt;P&gt;I assume this means Inspection Settings are treated as general objects and are not associated to Access Control or Threat Prevention.&lt;/P&gt;</description>
    <pubDate>Sat, 15 Feb 2025 16:38:10 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2025-02-15T16:38:10Z</dc:date>
    <item>
      <title>Question about permission profiles regarding Inspection settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241041#M40215</link>
      <description>&lt;P&gt;Hey Folks!&lt;/P&gt;&lt;P&gt;a customer of mine wants to implement restrictions via permission profiles and while this is mostly working as expected so far, today we came upon something we do not understand yet:&lt;/P&gt;&lt;P&gt;We tried to create a profile for certain admins, so that they can only edit objects and install the policy...nothing more (so not even viewing any policies). They have a lot of time-objects with which they control access from 3rd parties and these have to be changed very frequently throughout the day. This is mostly working, but it seems there is one additional thing that can still be accessed and changed, no matter what settings in the profile we choose: The inspection settings.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Is this something that is always allowed, no matter the permissions?&lt;BR /&gt;We have unchecked all permissions and those that could not be unchecked (like "settings" in Threat Prevention, which I suspect is also for inspection settings), we set to "Read". Only the access Control Objects are enabled and set to "Write". Yet, it is still possible to change the settings there, which we do not want to allow.&lt;BR /&gt;I could not find anything regarding this, but surely we would not be the only ones to stumble upon this, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always, happy for any hints regarding this!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 14:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241041#M40215</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2025-02-12T14:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Question about permission profiles regarding Inspection settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241056#M40220</link>
      <description>&lt;P&gt;If you try to change anything and you press 'OK' does it go through or then you get an error regarding not enough rights?&lt;/P&gt;
&lt;P&gt;Sometimes it looks like you can change something but if you press OK it will not proceed and the only option is cancel.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 18:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241056#M40220</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-12T18:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Question about permission profiles regarding Inspection settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241170#M40245</link>
      <description>&lt;P&gt;If you can indicate EXACT settings you used, happy to try it in my lab, either R81.20 or R82. However, if you dont wish to post publicly, you are more than welcome to message me directly.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 00:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241170#M40245</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-14T00:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about permission profiles regarding Inspection settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241269#M40253</link>
      <description>&lt;P&gt;I created a Permission Profile where every option was either disabled or set to Read Only (if it could not be disabled) but with Install Policy allowed.&lt;/P&gt;
&lt;P&gt;When I login it still shows &lt;STRONG&gt;Inspection Settings&lt;/STRONG&gt; but they only opened in Read Only.&lt;/P&gt;
&lt;P&gt;When I modify the Permission Profile so that&amp;nbsp;&lt;STRONG&gt;Common Objects&lt;/STRONG&gt; is set to &lt;STRONG&gt;Write&lt;/STRONG&gt; (so that the administrator can modify Time Objects per your scenario) it also opens Inspection Settings for editing.&lt;/P&gt;
&lt;P&gt;I assume this means Inspection Settings are treated as general objects and are not associated to Access Control or Threat Prevention.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2025 16:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-permission-profiles-regarding-Inspection-settings/m-p/241269#M40253</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-02-15T16:38:10Z</dc:date>
    </item>
  </channel>
</rss>

