NTA user roles for multitenancy

The IBM® QRadar® Network Threat Analytics (NTA) app 2.0.0 and later supports multitenant environments in QRadar 7.6.0. and later.

In a multitenant deployment, you ensure that customers see only their data by creating domains that are based on their QRadar input sources. By creating security profiles and user roles, you can manage privileges for large groups of users within the domain. User roles ensure that users have access to only the information that they are authorized to see.

Note: NTA 2.0.0 and later does not support multiple domains under one security profile. A security profile can have only one domain that is assigned to it for NTA to work as expected.

For NTA to work with QRadar, the QRadar admin can create user roles that designate an NTA tenant admin and any non-admin users or NTA tenant. Each role has distinct responsibilities and associated activities.

User access control

The following three distinct user roles manage NTA multitenancy.

QRadar admin or MSSP admin

Responsibilities:

  • Setting up the first shared instance and other non-admin NTA instances
  • Configuring non-admin instances with appropriate tenant admin tokens and instance identifiers
  • Upgrading all apps or systems
  • Delete or uninstall Tenant instance

NTA tenant admin

Complete the following procedure to create a role for the tenant admin user.

  1. On the navigation menu, click Admin.
  2. In the System Configuration section, click User Management, and then click the User Roles icon.
  3. Create a new role for the tenant admin user. For example, TenantAdministrator.
  4. Select the checkboxes as indicated in the following screen capture to add the permissions to the role.
    Screenshot showing permissions for NTA Tenant Admin role
  5. Click Save.

Responsibilities:

  • Configuring NTA Settings (Application Settings)
  • Creating and managing baselines
  • Investigating network threats

Required Permissions:

  • Delegated administration
  • Log activity (view only)
  • Network activity (view only)
  • Offenses (view only)
  • NTA

NTA tenant user

Complete the following procedure to create a role for the NTA tenant user.

  1. On the navigation menu, click Admin.
  2. In the System Configuration section, click User Management, and then click the User Roles icon.
  3. Create a new role for a tenant user. For example, TenantUser.
  4. Select the checkboxes as indicated in the following screen capture to add the permissions to the role.
    Screenshot showing permissions for NTA Tenant User role
  5. Click Save.

Responsibilities:

  • View and analyze network data in NTA
  • Review findings and anomalies
  • Internal investigation of network threats

Required Permissions:

  • Log Activity (view only)
  • Network Activity (view only)
  • Offenses (view only)
  • NTA