Restricting policy visibility
Overview
To restrict policy visibility by groups, you can create a content set and an RBAC role for your functional group. A content set named West and an RBAC role named West Policy Users is used for this example.
Create a content set for a functional group
- From the Main menu, go to Administration > Permissions > Content Sets and then click New Content Set.
- Enter West for the content set name and an optional description and then click Save.
For more information about content sets, see Tanium Console User Guide: Managing content sets.
Create a role to assign to a user or user group
- From the Main menu, go to Administration > Permissions > Roles and then click New Role.
- In the Role Details section, enter West Policy Users for the role name and an optional description.
- In the Permissions section, grant the following permissions and add required content sets.
- Expand Endpoint Configuration to grant the following permissions:
Permission Access Content Sets Endpoint Configuration READ Enforce Global Objects
West
WRITE West Endpoint Configuration API EXECUTE Endpoint Configuration Module USE Enforce Global Objects
West
- Expand Enforce to grant the following permissions:
Permission Access Content Sets Enforce SHOW Enforce Create ENFORCEMENT Enforce Global Objects
West
Enforce Edit Any ENFORCEMENT West Policy Type READ Enforce Global Objects
Enforce Linux
Enforce Mac
Enforce Service Objects
Enforce Windows
Reserved
- Expand Endpoint Configuration to grant the following permissions:
- Click Save.
- Assign the West Policy Users RBAC role to the user or user group of your choice.
- From the Main menu, go to Administration > Permissions > User or Administration > Permissions > User Groups and then click on the name of the user or user group.
- In the Roles section, click Manage Roles, select West Policy Users and then click Apply.
- Scroll to the end of the page and click Save.
For more information about RBAC roles, see Tanium Console User Guide: Managing roles.
Create a policy
- Sign in to the Tanium Console as the user with the West Policy Users RBAC role.
- From the Main menu, go to Modules > Enforce.
- Follow the steps in Creating policies to create a policy and select the West content set in the Content Set section.
Mac and macOS are trademarks of Apple Inc., and registered in the U.S. and other countries and regions.
Last updated: 5/30/2023 2:07 PM | Feedback