Use Broadcom JIT to automate CloudSOC Sysadmin Assignment
search cancel

Use Broadcom JIT to automate CloudSOC Sysadmin Assignment

book

Article ID: 398752

calendar_today

Updated On:

Products

CASB Securlet SAAS CASB Security Advanced CASB Security Premium CASB Security Standard CASB Advanced Threat Protection

Issue/Introduction

You want to automate the CloudSOC sysadmin role assignment. 

Resolution

In the Broadcom SaaS' Account Details page, you can configure Group Role Mapping to associate an identity provider group to a product role. If you do this for CASB's System Administrator Product role, the user logging in using Broadcom SSO will have the system admin role as shown below:

Please note that this JIT feature only assigns the role but does not remove the system admin role. However, if you list the group in SSO app allowed user/group list, then removing the user would prevent the user from log into CloudSOC. For example, for Azure SSO shown below, removing the user from the CloudSOCSysAdmin group will block the user from logging into CloudSOC. 

Additional Information

For additional information please refer to tech doc Identity Provider Page.