Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kryten
Collaborator

Question about permission profiles regarding Inspection settings

Hey Folks!

a customer of mine wants to implement restrictions via permission profiles and while this is mostly working as expected so far, today we came upon something we do not understand yet:

We tried to create a profile for certain admins, so that they can only edit objects and install the policy...nothing more (so not even viewing any policies). They have a lot of time-objects with which they control access from 3rd parties and these have to be changed very frequently throughout the day. This is mostly working, but it seems there is one additional thing that can still be accessed and changed, no matter what settings in the profile we choose: The inspection settings.

Is this something that is always allowed, no matter the permissions?
We have unchecked all permissions and those that could not be unchecked (like "settings" in Threat Prevention, which I suspect is also for inspection settings), we set to "Read". Only the access Control Objects are enabled and set to "Write". Yet, it is still possible to change the settings there, which we do not want to allow.
I could not find anything regarding this, but surely we would not be the only ones to stumble upon this, right?

 

As always, happy for any hints regarding this!

 

 

0 Kudos
3 Replies
Lesley
Mentor Mentor
Mentor

If you try to change anything and you press 'OK' does it go through or then you get an error regarding not enough rights?

Sometimes it looks like you can change something but if you press OK it will not proceed and the only option is cancel. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

If you can indicate EXACT settings you used, happy to try it in my lab, either R81.20 or R82. However, if you dont wish to post publicly, you are more than welcome to message me directly.

Cheers,

Andy

0 Kudos
Tal_Paz-Fridman
Employee
Employee

I created a Permission Profile where every option was either disabled or set to Read Only (if it could not be disabled) but with Install Policy allowed.

When I login it still shows Inspection Settings but they only opened in Read Only.

When I modify the Permission Profile so that Common Objects is set to Write (so that the administrator can modify Time Objects per your scenario) it also opens Inspection Settings for editing.

I assume this means Inspection Settings are treated as general objects and are not associated to Access Control or Threat Prevention.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events