NTA user roles for multitenancy
The IBM® QRadar® Network Threat Analytics (NTA) app 2.0.0 and later supports multitenant environments in QRadar 7.6.0. and later.
In a multitenant deployment, you ensure that customers see only their data by creating domains that are based on their QRadar input sources. By creating security profiles and user roles, you can manage privileges for large groups of users within the domain. User roles ensure that users have access to only the information that they are authorized to see.
For NTA to work with QRadar, the QRadar admin can create user roles that designate an NTA tenant admin and any non-admin users or NTA tenant. Each role has distinct responsibilities and associated activities.
User access control
The following three distinct user roles manage NTA multitenancy.
QRadar admin or MSSP admin
Responsibilities:
- Setting up the first shared instance and other non-admin NTA instances
- Configuring non-admin instances with appropriate tenant admin tokens and instance identifiers
- Upgrading all apps or systems
- Delete or uninstall Tenant instance
NTA tenant admin
Complete the following procedure to create a role for the tenant admin user.
- On the navigation menu, click Admin.
- In the System Configuration section, click User Management, and then click the User Roles icon.
- Create a new role for the tenant admin user. For example, TenantAdministrator.
- Select the checkboxes as indicated in the following screen capture to add the permissions to the
role.
- Click Save.
Responsibilities:
- Configuring NTA Settings (Application Settings)
- Creating and managing baselines
- Investigating network threats
Required Permissions:
- Delegated administration
- Log activity (view only)
- Network activity (view only)
- Offenses (view only)
- NTA
NTA tenant user
Complete the following procedure to create a role for the NTA tenant user.
- On the navigation menu, click Admin.
- In the System Configuration section, click User Management, and then click the User Roles icon.
- Create a new role for a tenant user. For example, TenantUser.
- Select the checkboxes as indicated in the following screen capture to add the permissions to the
role.
- Click Save.
Responsibilities:
- View and analyze network data in NTA
- Review findings and anomalies
- Internal investigation of network threats
Required Permissions:
- Log Activity (view only)
- Network Activity (view only)
- Offenses (view only)
- NTA