Capture Client Getting Started Guide For Unified Management

Roles and Privileges

SonicWallCapture Client provides each of the administrative users with different privileges, depending on the roles assigned to them.

To view the roles of a user navigate to SonicWall Unified Management > Admin Settings > Users Access Management > User Groups page.

For details on the User Groups, refer to Users Access Management.

Capture Client has three types of users

  • Admin - An Admin can access and edit all the sections to get any changes reflected in the management console, and assign others with different types of privileges.

  • Operator - An Operator can perform device operations and can read and write the Assets and the Reports sections.

  • Read-only - A Viewer can only read any sections in the console.

The following table describes the accessibility and rights of the CMC users:

CMC Sections Admin Operator Viewer
Administrators page Read and Write Read-only Read-only
Tenant Settings Read and Write Read-only Read-only
Notifications Read and Write Read-only Read-only
Policies Read and Write Read-only Read-only
Assets Read and Write Read and Write Read-only
Reports Read and Write Read and Write Read-only
Threats(SentinelOne console) Read and Write Read-only Read-only

Above mentioned roles can be assigned to an user for different CMC scope. Here are various Scope Admins on Capture Client Management console:

  • Account Admin - An Account Admin CMC user has access to a CMC account scope that is mapped to an SentinelOne Account scope.

    Account Admin can be created/modified only from backend by Support team.

  • Multi-tenant Admin - A Multi-tenant Admin CMC user has access to multiple CMC tenants, which are also mapped to multiple SentinelOne sites but no access to Account scope.

  • Single-tenant Admin - A Single-tenant Admin CMC user has access to a single CMC tenant scope, which is mapped to a single SentinelOne Site scope.

The following table describes the workflow for the various scopes Admins on SentinelOne console for CMC users:

Scopes Workflow
CMC Account Admin An Account Admin is redirected to the SentinelOne console in the same site as UMCMC active scope before the redirection. But they can’t change the scope from SentinelOne console to another Tenant/Account from SentinelOne console. They need to change to Account Scope in UMCMC if they want to access SentinelOne console in Account Scope.
CMC Multi-Tenant Admin A multi-tenant Admin is redirected to the SentinelOne console, but not to any specific SentinelOne site. All SentinelOne sites in this user’s scope of access are listed in the site navigation menu and asked to select a site.
CMC Tenant Admin A single-tenant Admin is redirected to the single SentinelOne site in same as UMCMC scope.