This topic directly addresses PCNSE objectives related to securing administrative access to Panorama using Role-Based Access Control (RBAC).
Panorama provides powerful centralized management, making it critical to control who can access it and what actions they can perform. Role-Based Access Control (RBAC) on Panorama enables administrators to enforce the principle of least privilege, ensuring users only have the permissions necessary to perform their job functions.
RBAC separates administrative privileges into two key components:
By combining Admin Roles and Access Domains, you can create highly granular permission sets for different administrative users or groups.
Panorama > Admin Roles
Panorama > Access Domains
Panorama > Administrators
While predefined roles exist, custom roles offer tailored permissions.
Panorama > Admin Roles
.
Start with minimal privileges and add permissions as needed, following the least privilege principle.
Access Domains restrict the devices and configuration objects an administrator can manage.
Panorama > Access Domains
.
Carefully plan your Access Domains. An administrator assigned to a specific domain will ONLY see and be able to manage the items explicitly included in that domain.
Combine Roles and Domains when creating administrator accounts.
Panorama > Administrators
.
Panorama > Setup > Management > Authentication Settings
.
Panorama > Administrators
,
Panorama > Admin Roles
,
Panorama > Access Domains
.
These links point to the relevant sections within the official Palo Alto Networks documentation for Panorama version 11.0.