Prisma Cloud : RQL Query Types supported for Custom Role (RBAC) users

Prisma Cloud : RQL Query Types supported for Custom Role (RBAC) users

4144
Created On 02/26/24 02:41 AM - Last Modified 03/08/24 01:22 AM


Question


  • What are the RQL Query Types supported for Custom Role (RBAC) users?


Environment


  • Prisma Cloud


Answer


  • All Out of the Box Default roles come with permissions for all available Query Types
  • There are a total of 8 Supported Query Types for all Tenants:
    1. Asset
    2. Asset Configuration (Config)
    3. Application Asset (AppSec)
    4. Vulnerability
    5. Permission (IAM)
    6. Network Configuration (CNA)
    7. Network
    8. Audit Event
  • Additionally, there is another query type called AppDNA, which is currently in Limited GA status.
Custom Role Supported Query Types:
  • Custom roles, defined by users through Granular RBAC features, will only support the following Query Types:
    1. Asset
    2. Asset Configuration (Config)
    3. Permission (IAM)
    4. Network Configuration (CNA)
    5. Network
    6. Audit Event
  • Configure the necessary permissions for the above Query types
    1. For Permission (IAM) queries - IAM module should be enabled and Investigate->Config->READ permission should be available under the User role
    2. For Network Config (CNA) queries - Investigate->Config->READ and Investigate->Network->READ permission should be available under the User role

Custom Role Unsupported Query Types:

  • Following Query Types are not supported for custom roles and are out of scope for Granular RBAC:
    1. Application Asset (AppSec)
    2. Vulnerability
    3. AppDNA


Additional Information


Here is an example:

  • Out-of-the-box roles, such as System Admin, possess visibility into all query types accessible under the Investigate Menu as below:


image.png
 
  • Only the supported query types for Custom Roles are listed under Settings > Access Control > Permission Group > Add Permission Group
image.png
  • Users assigned with Custom Role will only have access to the Supported Query Types under the Investigate menu:
image.png

Note:
 
Custom Prisma Cloud Roles

Permissions listed on the Assign Permissions page are not comprehensive and do not map one-to-one with all available feature permissions for an out of the box role. For instance, if you create a custom permission by cloning a System Administrator role, the feature permissions listed on the Assign Permissions page may not include all permissions available in the out of the box System Administrator role, as these feature permissions are not currently enabled for custom roles. Feature permissions displayed on the Assign Permissions page lists all available permissions that can be assigned for any given custom role. Reference the Prisma Cloud Administrator Permissions page for a comprehensive list of default permissions by role.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008XISCA2&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language