How to Manage Access to Keytos Shield
Overview - How Does Access Management Work in Keytos Shield?
Keytos Shield uses Role Based Access Control (RBAC) to manage access to your subscription. With RBAC, you can assign specific roles to users, which determine the actions they can perform and the resources they can access within Keytos Shield. This ensures that users only have the permissions necessary for their job.
What RBAC Roles Are Available in Keytos Shield?
The following roles are available in Keytos Shield:
- Owner: Has full access to all resources and settings within Keytos Shield, including network security, identity security, and central subscription management.
- Log Reader: Can view and export audit logs within Keytos Shield but cannot make changes to resources or settings.
- Network Administrator: Can manage network security settings within Keytos Shield but cannot access identity security or central subscription management.
- Network Log Reader: Can view and export network security logs within Keytos Shield but cannot make changes to network security settings or view non-network logs.
- Identity Administrator: Can manage identity security settings within Keytos Shield but cannot access network security or central subscription management.
- Identity Log Reader: Can view and export identity security logs within Keytos Shield but cannot make changes to identity security settings or view non-identity logs.
How to Assign RBAC Roles to Entra ID Users, Groups, or Applications
If you want to assign RBAC roles to Entra ID users and groups, follow these steps:
- Sign in to the Keytos Shield portal with an account that has the Owner role.
- Navigate to the Settings page.
- Scroll down to the RBAC role you want to assign.
- Type in the name of the Entra ID user, group, or application you want to assign the role to.
- Click on the user, group, or application from the search results.
- Scroll up and click Save Changes to apply the role assignment.
Troubleshooting Shield Access Management Issues
I Can’t See the RBAC Role Assignment Options on the Settings Page
If you can’t see the RBAC role assignment options on the Settings page, it is likely because your account does not have the Owner role. Only users with the Owner role can assign RBAC roles in Keytos Shield. Ensure that you are signed in with an account that has the necessary permissions.
I’m Assigned Owner in Azure But Can’t See the RBAC Options in Keytos Shield
Azure RBAC does not automatically grant you access to Keytos Shield. Even if you are assigned the Owner role in Azure to your Shield subscription SaaS resource, you must still be explicitly assigned an RBAC role within Keytos Shield to manage access. Ensure that your account has been granted the appropriate role in Keytos Shield.
I Don’t Know Who My Owner Is Or They’ve Left the Organization
If you don’t know who your Keytos Shield owner is or if the owner has left the organization, reach out to Keytos support for assistance.