You can add users to help manage and monitor your Nebula console. You must be an Administrator or Super Admin to add new users.
User roles are as follows:
- Super Admin: Unrestricted access to the Nebula platform.
- Administrator: Full read and edit access to any groups they belong to. Administrators cannot adjust syslog logging or change single sign-on settings.
-
Read Only: Read access to any groups they belong to. They can generate reports and receive notifications, but cannot make any other system changes.
Note: Read Only users can access sensitive policy data, including Tamper Protection password, with ThreatDown API's. This can be used to modify the endpoint agent on the machine.
- Available = ✓
- Unavailable = ✕
| Super Admin | Administrator* | Read-Only | |
|---|---|---|---|
| Create Super Admins | ✓ | ✕ | ✕ |
| Create Administrators | ✓ | ✓ | ✕ |
| Create Read-Only Users | ✓ | ✓ | ✕ |
| Create and edit Groups | ✓ | ✓ | ✕ |
| Edit Users | ✓ | ✕ | ✕ |
| Deploy Endpoints | ✓ | ✓ | ✕ |
| Manage Endpoints | ✓ | ✓ | ✕ |
| Create and edit Policies | ✓ | ✓ | ✕ |
| Create and edit Exclusions | ✓ | ✕ | ✕ |
| Create false positive request | ✓ | ✓ | ✕ |
| Apply OS Patches | ✓ | ✓ | ✕ |
| Update 3rd-party software | ✓ | ✓ | ✕ |
| Create ignore rules for OS patches and software updates | ✓ | ✓ | ✕ |
| Create and edit Scheduled scans | ✓ | ✓ | ✕ |
| View Managed Services cases | ✓ | ✕ | ✕ |
| Create Application Block rule | ✓ | ✓ | ✕ |
| Create DNS Rule | ✓ | ✓ | ✕ |
| Bulk Export Drive Encryption Recovery Keys | ✓ | ✕ | ✕ |
| View Drive Encryption Recovery Keys | ✓ | ✓ | ✕ |
| Suspicious Activity Remediation | ✓ | ✓ | ✕ |
| Ransomware Rollback | ✓ | ✓ | ✕ |
| Close Suspicious Activity Incidents | ✓ | ✓ | ✕ |
| View Suspicious Activity | ✓ | ✓ | ✓ |
| Flight Recorder Search | ✓ | ✓ | ✓ |
| Upload files to Sandbox Analysis | ✓ | ✓ | ✕ |
| Investigate with Active Response Shell | ✓** | ✕ | ✕ |
| Respond to Identity Threat Detection & Response activity | ✓ | ✓ | ✕ |
| Configure AI Detection & Response rules | ✓ | ✓ | ✕ |
| Configure Single Sign-On | ✓ | ✕ | ✕ |
| Configure Syslogging | ✓ | ✕ | ✕ |
| Generate Reports | ✓ | ✓ | ✓ |
| Create Notifications | ✓ | ✓ | ✓ |
| Receive Notifications | ✓ | ✓ | ✓ |
| Create Support ticket | ✓ | ✓ | ✕ |
*=Applies only to assigned Groups
**=Active Response Shell permission must be enabled for each Super Admin.
Add a new user
To add another user, follow the steps below. We recommend having multiple admins in case you get locked out of your account due to two-factor authentication.
- On the left navigation pane, go to Configure > Users.
- In the top-right of the screen, click New user.
- Enter the email address for the new user, choose a role, and select groups for them to belong to.
- Click Invite.
The user email must be unique to Nebula and not currently in use. Creating task-specific emails or '+' plus addressing can be a unique email for Nebula. A maximum of 50 characters are allowed.
For more information, see:
When invited, the user receives an email that prompts them to create a login for their account. After creating their account, they may sign in and use the Nebula platform.
The original link stops working if the invited user does not create an account within 14 days. You can resend the invite to the user if needed. Return to this screen, check the email checkbox, and click Resend Invite.
Delete a user
- On the left navigation pane, go to Configure > Users.
- Select Users. A list of users displays.
- Select a user.
- In the top right, click Delete.
- To delete the user, click Delete on the confirmation window.
Note: The initial administrator account is the NAO, which is a unique account. This account cannot be deleted. If you need to change the NAO, contact Sales.