Skip to content
3 changes: 3 additions & 0 deletions deploy-manage/_snippets/feature-privilege-access-levels.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
* **All**: Users have full access to the feature, which includes performing all available actions and managing configuration.
* **Read**: Users can view the feature, but can't perform any actions or manage configuration.
* **None**: Users can't access or view the feature.
2 changes: 1 addition & 1 deletion solutions/security/ai/ai-assistant-knowledge-base.md
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ We strongly recommend you [enable autoscaling](/deploy-manage/autoscaling.md#clu

## Role-based access control (RBAC) for Knowledge Base [knowledge-base-rbac]

The `Elastic AI Assistant: All` role privilege allows you to use AI Assistant and access its settings. It has two sub-privileges, `Field Selection and Anonymization`, which allows you to customize which alert fields are sent to AI Assistant and Attack Discovery, and `Knowledge Base`, which allows you to edit and create new Knowledge Base entries.
The `Elastic AI Assistant: All` role privilege allows you to use AI Assistant and access its settings. To grant its sub-feature privileges individually, turn on **Customize sub-feature privileges**. For the full list, refer to [Elastic AI Assistant sub-feature privileges](/solutions/security/get-started/security-kibana-privileges.md#elastic-ai-assistant-sub-feature-privileges).

:::{image} /solutions/images/security-knowledge-base-rbac.png
:alt: Knowledge base's RBAC settings
Expand Down
2 changes: 1 addition & 1 deletion solutions/security/ai/ai-assistant.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ The Elastic AI Assistant is designed to enhance your analysis with smart dialogu
::::{admonition} Requirements
* {applies_to}`stack: ga` An [Enterprise subscription](https://www.elastic.co/pricing).
* {applies_to}`serverless: ga` An {{sec-serverless}} project with the [EASE or Security Analytics Complete feature tier](/deploy-manage/deploy/elastic-cloud/project-settings.md).
* To use AI Assistant, the **Elastic AI Assistant: All** Security [privilege](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md), the **Actions and Connectors: Read** management [privilege](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md) and the **Monitor** Elasticsearch [Cluster privilege](elasticsearch://reference/elasticsearch/security-privileges.md#privileges-list-cluster).
* To use AI Assistant, the **Elastic AI Assistant: All** Security [privilege](/solutions/security/get-started/security-kibana-privileges.md), the **Actions and Connectors: Read** management [privilege](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md) and the **Monitor** Elasticsearch [Cluster privilege](elasticsearch://reference/elasticsearch/security-privileges.md#privileges-list-cluster).
* To set up AI Assistant, the **Actions and Connectors : All** [privilege](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md).
* An [LLM connector](/explore-analyze/ai-features/llm-guides/llm-connectors.md), which AI Assistant uses to generate responses.
* A [machine learning node](/explore-analyze/machine-learning/setting-up-machine-learning.md).
Expand Down
24 changes: 5 additions & 19 deletions solutions/security/ai/attack-discovery/grant-access.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,25 +23,11 @@ Your role needs these [{{kib}} privileges](/deploy-manage/users-roles/cluster-or
| Available in | Privileges |
|---|---|
| {applies_to}`stack: ga 9.4+` {applies_to}`serverless: ga` | `All` for **Attack discovery**, and at least `Read` for **Rules and Exceptions** and **Alerts** |
| {applies_to}`stack: ga 9.1-9.3` | `All` for **Security > Attack discovery**, and at least `Read` for **Security > Rules, Alerts, and Exceptions** |
| {applies_to}`stack: ga =9.3` | `All` for **Security > Attack discovery**, and at least `Read` for **Security > Rules, Alerts, and Exceptions** |
| {applies_to}`stack: ga 9.1-9.2` | `All` for **Security > Attack discovery**, and at least `Read` for **Security** |
| {applies_to}`stack: ga =9.0` | `All` for **Security > Attack discovery** |


### Schedules sub-feature privilege [ad-schedules-privilege]

```{applies_to}
stack: ga 9.1+
serverless:
security: ga
```

**Attack discovery** includes a **Schedules** sub-feature privilege:

| UI label | What it controls |
|---|---|
| **Schedules → Allow changes** | Create, edit, enable, disable, or delete Attack discovery schedules |

Selecting `All` for **Attack discovery** includes **Allow changes**. To run Attack Discovery without managing schedules, turn on **Customize sub-feature privileges** and clear **Allow changes**.
For details on Attack discovery sub-feature privileges, refer to [Attack discovery sub-feature privileges](/solutions/security/get-started/security-kibana-privileges.md#attack-discovery-sub-feature-privileges).

## Index privileges [ad-index-privileges]

Expand Down Expand Up @@ -85,7 +71,7 @@ When you turn on [`securitySolution:enableAttackDiscoveryWorkflows`](kibana://re
|---|---|
| Monitor runs in **Generations** and open workflow execution details | `read` for **Analytics → Workflows** |
| Generate discoveries (manual or scheduled) | `read` and `execute` for **Analytics → Workflows** |
| Create, edit, or enable schedules | `read` and `execute` for **Analytics → Workflows**, plus [**Schedules** → **Allow changes**](#ad-schedules-privilege) |
| Deactivate or delete schedules | [**Schedules** → **Allow changes**](#ad-schedules-privilege) only |
| Create, edit, or enable schedules | `read` and `execute` for **Analytics → Workflows**, plus [**Schedules** → **Allow changes**](/solutions/security/get-started/security-kibana-privileges.md#attack-discovery-sub-feature-privileges) |
| Deactivate or delete schedules | [**Schedules** → **Allow changes**](/solutions/security/get-started/security-kibana-privileges.md#attack-discovery-sub-feature-privileges) only |

Granting `All` for **Analytics → Workflows** includes `read` and `execute`. For finer-grained access, use Workflows [sub-feature privileges](/explore-analyze/workflows/get-started/setup.md#workflows-role-access).
2 changes: 1 addition & 1 deletion solutions/security/ai/ease/ease-value-report.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ stack: preview 9.3

* To access the **Value report** page, your subscription must include AI-powered features. For {{sec-serverless}}, this means you need either the Elastic AI SOC Engine (EASE) or Security Analytics Complete [feature tier](https://www.elastic.co/pricing/serverless-security).

* To access the **Value report** page, you need the **SOC Management** Security sub-feature [{{kib}} privilege](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges.md).
* To access the **Value report** page, you need the **SOC Management** Security sub-feature [{{kib}} privilege](/solutions/security/get-started/security-kibana-privileges.md#security-sub-feature-privileges).

![value report RBAC setting](/solutions/images/security-value-report-rbac.png "=50%")

Expand Down
2 changes: 1 addition & 1 deletion solutions/security/configure-elastic-defend.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ In practice, you add the {{elastic-defend}} integration from the **Integrations*
|---|---|
| Deploy {{elastic-defend}} for the first time | [Requirements](/solutions/security/configure-elastic-defend/elastic-defend-requirements.md) → [Install {{elastic-defend}}](/solutions/security/configure-elastic-defend/install-elastic-defend.md) |
| Configure protection and event collection settings | [Configure an integration policy](/solutions/security/configure-elastic-defend/configure-an-integration-policy-for-elastic-defend.md) |
| Control which users can access {{elastic-defend}} features | [Feature privileges](/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges.md) |
| Control which users can access {{elastic-defend}} features | [Sub-feature privileges](/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges.md) |
| Set up endpoints in restricted networks | [Configure offline endpoints and air-gapped environments](/solutions/security/configure-elastic-defend/configure-offline-endpoints-air-gapped-environments.md) |
| Send endpoint data to a remote {{es}} output | [Use {{elastic-defend}} with a remote {{es}} output](/solutions/security/configure-elastic-defend/use-elastic-defend-with-remote-output-and-ccs.md) |
| Remove {{agent}} from a host | [Uninstall {{agent}}](/solutions/security/configure-elastic-defend/uninstall-elastic-agent.md) |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,59 +9,78 @@ applies_to:
products:
- id: security
- id: cloud-serverless
description: Lists Elastic Defend sub-feature privileges in Elastic Security and what each privilege allows.
---

# {{elastic-defend}} feature privileges
# {{elastic-defend}} sub-feature privileges

Access to {{elastic-defend}} features is controlled by sub-feature privileges that sit under the [**Security** privilege](/solutions/security/get-started/security-kibana-privileges.md), and you grant each one separately. This lets you apply the principle of least privilege, giving a role access to the endpoint management pages and response actions it needs.

You can create user roles and define privileges to manage feature access in {{elastic-sec}}. This allows you to use the principle of least privilege while managing access to {{elastic-defend}}'s features.
To grant these privileges, create or edit a role and add {{kib}} privileges to open the **Assign role to spaces** flyout. Expand the **Security** group of features, select **All** for the **Security** privilege, then turn on **Customize sub-feature privileges**. For instructions on creating and editing roles, refer to [](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md) for {{stack}}, or to [Custom roles](/deploy-manage/users-roles/serverless-custom-roles.md) for {{serverless-short}}.

To configure roles and privileges, find **Roles** in the navigation menu or by using the [global search field](/explore-analyze/find-and-organize/find-apps-and-objects.md). For more details on using this UI, refer to [](/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management.md) for {{stack}}, or to [Custom roles](/deploy-manage/users-roles/cloud-organization/user-roles.md) for {{serverless-short}}.
::::{important}
Selecting **All** for **Security** doesn't grant any sub-feature privileges. You must turn on **Customize sub-feature privileges** and grant each one individually.
::::

::::{note}
{applies_to}`stack: ga 9.1` {{elastic-defend}}'s feature privileges can be assigned on a per-space basis. For more information, refer to [Spaces and Elastic Defend FAQ](/solutions/security/get-started/spaces-defend-faq.md).
{applies_to}`stack: ga 9.1` {{elastic-defend}}'s sub-feature privileges can be assigned on a per-space basis. For more information, refer to [Spaces and Elastic Defend FAQ](/solutions/security/get-started/spaces-defend-faq.md).
::::

To grant access, select **All** for the **Security** feature in the **Assign role to space** configuration UI, then turn on the **Customize sub-feature privileges** switch.
## Access levels

::::{important}
Selecting **All** for the overall **Security** feature does NOT enable any sub-features. You must also enable the **Customize sub-feature privileges** switch, and then enable each sub-feature privilege individually.
::::
For each of the following sub-feature privileges, select the type of access you want to allow:

:::{include} /deploy-manage/_snippets/feature-privilege-access-levels.md
:::

For each of the following sub-feature privileges, select the type of access you want to allow:
:::{note}
Some sub-features don't have a **Read** privilege.
:::

## Endpoint management

* **All**: Users have full access to the feature, which includes performing all available actions and managing configuration.
* **Read**: Users can view the feature, but can’t perform any actions or manage configuration (some features don’t have this privilege).
* **None**: Users can’t access or view the feature.
These privileges control access to different parts of endpoint management.

| | |
:::{table}
:widths: description

| Privilege | What it allows |
| --- | --- |
| **Endpoint List** | Access the [Endpoints](/solutions/security/manage-elastic-defend/endpoints.md) page, which lists all hosts running {{elastic-defend}}, and associated integration details. |
| **Automatic Troubleshooting** |Access [Automatic Troubleshooting](/solutions/security/manage-elastic-defend/automatic-troubleshooting.md) to check if your hosts have third-party AV software installed.<br><br>**Note:** In {{stack}} 9.0.0, this privilege is called **Endpoint Insights**. |
| **Global Artifact Management** {applies_to}`stack: ga 9.1` | Manage global assignment of endpoint artifacts (e.g., trusted applications, event filters) across all spaces and policies. This privilege controls global assignment rights only; privileges for each artifact type are required for full artifact management. |
| **Global Artifact Management** {applies_to}`stack: ga 9.1` | Manage global assignment of endpoint artifacts (such as trusted applications and event filters) across all spaces and policies. This privilege controls global assignment rights only; privileges for each artifact type are required for full artifact management. |
| **Trusted Applications** | Access the [Trusted applications](/solutions/security/manage-elastic-defend/trusted-applications.md) page to remediate conflicts with other software, such as antivirus or endpoint security applications. |
| **Trusted Devices** {applies_to}`stack: ga 9.2` {applies_to}`serverless: ga`| Access the [Trusted devices](/solutions/security/manage-elastic-defend/trusted-devices.md) page to specify which trusted devices can connect to hosts with [Device Control](/solutions/security/configure-elastic-defend/configure-an-integration-policy-for-elastic-defend.md#device-control) enabled.
| **Trusted Devices** {applies_to}`stack: ga 9.2` {applies_to}`serverless: ga` | Access the [Trusted devices](/solutions/security/manage-elastic-defend/trusted-devices.md) page to specify which trusted devices can connect to hosts with [Device Control](/solutions/security/configure-elastic-defend/configure-an-integration-policy-for-elastic-defend.md#device-control) enabled. |
| **Host Isolation Exceptions** | Access the [Host isolation exceptions](/solutions/security/manage-elastic-defend/host-isolation-exceptions.md) page to add specific IP addresses that isolated hosts can still communicate with. |
| **Blocklist** | Access the [Blocklist](/solutions/security/manage-elastic-defend/blocklist.md) page to prevent specified applications from running on hosts, extending the list of processes that {{elastic-defend}} considers malicious. |
| **Event Filters** | Access the [Event Filters](/solutions/security/manage-elastic-defend/event-filters.md) page to filter out endpoint events that you don’t want stored in {{es}}. |
| **Endpoint Exceptions** {applies_to}`stack: ga 9.2` {applies_to}`serverless: ga`| Add and use [endpoint exceptions](/solutions/security/manage-elastic-defend/elastic-endpoint-exceptions.md).<br><br>**Note:** In {{stack}} 9.1.0 and earlier, this privilege is included within the **Security** privilege. |
| **{{elastic-defend}} Policy Management** | Access the [Policies](/solutions/security/manage-elastic-defend/policies.md) page and {{elastic-defend}} integration policies to configure protections, event collection, and advanced policy features. |
| **{{elastic-defend}} Scripts Management** {applies_to}`stack: ga 9.4+` {applies_to}`serverless: ga` | Access the [script library](/solutions/security/endpoint-response-actions/script-library.md) to upload and manage scripts for {{elastic-defend}} `runscript` response actions. |
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints, and view command output and status in the [response console](/solutions/security/endpoint-response-actions.md). Grant this privilege whenever you grant any response-action privilege (such as **Host Isolation**, **Process Operations**, and so on). If this privilege is **None**, running a response action in the console will create the action request, but the user won't be able to monitor its completion or view its results. |
| **Host Isolation** | Allow users to [isolate and release hosts](/solutions/security/endpoint-response-actions/isolate-host.md). |
:::

## Response actions

These privileges control access to different response actions and their history.

:::{table}
:widths: description

| Privilege | What it allows |
| --- | --- |
| **Response Actions History** | Access the [response actions history](/solutions/security/endpoint-response-actions/response-actions-history.md) for endpoints, and view command output and status in the [response console](/solutions/security/endpoint-response-actions.md). Grant this privilege whenever you grant a response-action privilege (such as **Host Isolation**, **Process Operations**, and so on). If this privilege is **None**, running a response action still creates the action request, but the user can't monitor its completion or view its results. |
| **Host Isolation** | [Isolate and release hosts](/solutions/security/endpoint-response-actions/isolate-host.md). |
| **Process Operations** | Perform host process-related [response actions](/solutions/security/endpoint-response-actions.md), including `processes`, `kill-process`, and `suspend-process`. |
| **File Operations** | Perform file-related [response actions](/solutions/security/endpoint-response-actions.md) in the response console. |
| **Execute Operations** | Perform shell commands and script-related [response actions](/solutions/security/endpoint-response-actions.md) in the response console.<br><br>The commands are run on the host using the same user account running the {{elastic-defend}} integration, which normally has full control over the system. Only grant this feature privilege to {{elastic-sec}} users who require this level of access. |
| **Scan Operations** | Perform folder scan [response actions](/solutions/security/endpoint-response-actions.md) in the response console. |

% The paragraph starting with "The commands are run ..." was in a warning admonition. Since admonitions inside tables aren't supported yet, converted this into plain text.
:::

## Upgrade considerations [_upgrade_considerations]
```yaml {applies_to}
stack:
```

After upgrading from {{elastic-sec}} 8.6 or earlier, existing user roles will be assigned **None** by default for any new endpoint management feature privileges, and youll need to explicitly assign them. However, many features previously required the built-in `superuser` role, and users who previously had this role will still have it after upgrading.
After upgrading from {{elastic-sec}} 8.6 or earlier, existing user roles will be assigned **None** by default for any new endpoint management sub-feature privileges, and you'll need to explicitly assign them. However, many features previously required the built-in `superuser` role, and users who previously had this role will still have it after upgrading.

You’ll probably want to replace the broadly permissive `superuser` role with more focused feature-based privileges to ensure that users have access to only the specific features that they need. Refer to [{{kib}} role management](/deploy-manage/users-roles/cluster-or-deployment-auth/defining-roles.md) for more details on assigning roles and privileges.
Loading
Loading