Access Control

Navigate to Main menu > Admin > Access Control, the Members, Roles, Scopes, Groups and Spaces tabs enable you to manage access across the Ivanti Neurons Platform.

The Spaces tab and the associated options are only available for Unified Product Experience tenants. For more information, see Unified Product Experience.

The Groups tab and the associated options are available when syncing groups using SCIM provisioning protocol. For more information on setting up SCIM provisioning for IDPs, see SCIM Provisioning.

Members

When a company signs up for the Ivanti Neurons Platform, the first person who logs in becomes a member and is assigned the role of Administrator. Other people can be invited to become Neurons Platform members and use the features the Neurons Platform has to offer.

There is no connection between the list of users who are members of the Neurons Platform and the user data such as Function, Feature, and Directory that is imported using an Active Directory connector.

Roles

Configure the permissions of your members by assigning them one or more Roles.

The Neurons Platform comes with several pre-configured roles that cannot be changed. If these roles do not meet your needs, you can also create custom roles.

Space aware roles - The permissions are specific to each space, so you can assign roles to a specific space only. Examples are Device Management, App Management in a space. To learn more, refer to the Roles Management section in the Ivanti Neurons for MDM Administrator guide.

General roles - The permissions are, by nature, applicable to all roles. Examples are tenant-level settings such as MDM Certificates, App Catalog Settings.

Scopes

Use scopes to define which devices members can see and manage. Administrators can create a scope containing a static list of devices or they can create a scope that works dynamically based on filters.

Members can have multiple scopes assigned to them. Scope creation and assignment requires the Access Control > Modify Scopes permission.

Scopes currently apply to only the following areas of Ivanti Neurons platform:

  • Devices
  • People
  • Smart Advisors
  • Dashboard components that get data from Devices or People
  • Bots (Custom Action)
    The use of Custom Actions can now be restricted using Neurons Scopes, providing enhanced security by controlling which device groups or people a bot is allowed to execute actions against, based on the scope access of the user who triggered the bot. For more information on Scope for Run now, see Run now.
  • App Control
    Scopes enable administrators to set limitations on what users and devices can see or access in App Control.
  • Patch Management
    In certain scenarios, the number of devices found in a scope may be higher than the number of devices available in Patch Management once this device scope is assigned. The icon shows the information in the column is not as per specified scope. A banner also indicates this on the top of the page.
  • Patch Management Reports
    Patch Management reports are generated based on the device scopes assigned.
    Learn more about Patch Management Reports.
  • Edge Intelligence (Device Scope supported)
    In certain scenarios, the number of devices found in a scope may be higher than the number of devices available in Edge Intelligence once this device scope is assigned.
    Scenarios are:
    1. When configuring a scope, the used filter criteria can result in identical devices. For an example: multiple devices with the same computer name.

    2. Not all devices have the Edge Intelligence engine or capability installed.

    3. Device being offline for longer than 30 days, which Edge Intelligence will clean up.

Groups

Groups allows you assign roles through SCIM from your Identity Provider (IdP). You can control assigned roles through group membership at the IdP. With this setup, Neurons admins don’t need to assign the same default roles to every new member. Instead, new members receive access based on the roles of the groups they belong to.

The Groups tab displays groups that are synced using SCIM provisioning protocol from your IdP. For more information on configuring SCIM, see SCIM Provisioning.

To assign roles, follow these steps:

  1. Navigate to Admin > Access Control.
  2. Go to the Groups tab.
    This displays the list of existing and newly added groups.

    The Member column shows the number of users who have logged in from a group with roles and the number of directly invited members in that group.
    The Population column indicates the number of users in that group, irrespective of whether the group has been assigned a role.

    Ensure you note the following information to interpret the count under the Member column:

    • A group has a non-zero member count only if the group is assigned a role and the users in that group have logged in.

    • When a directly invited member (including an unaccepted invite) is a user of a group with roles, they are included in the member count.

  3. On the Groups tab, you can do the following:
    • To assign role-based access control (RBAC): Select the required group, then click Assign Role to Group option, select roles that you want to assign, and click Save.
    • To authenticate member login via Ivanti Neurons: Enable the check-box under the Can Authenticate column for a group, and click Save Authentication Settings.
    • To deny access to all members in a group: Disable the check-box under the Can Authenticate column for the group.

Once the changes are saved, the users can log in based on:

  • Users from groups with the Can Authenticate option enabled can authenticate via Ivanti Neurons and log in.

  • If the group has roles assigned, the Can Authenticate option will be enabled automatically. Users in groups with roles can log in and access Ivanti Neurons with those roles.

  • If a group has the Can Authenticate option enabled but no roles assigned, users in that group can log in, but their access to Ivanti Neurons content is restricted.

  • If the group has the Can Authenticate option disabled, users from that group will not have access to Ivanti Neurons.

  • After users log in with assigned roles, the Members page will list users from groups with roles.

Spaces

The Spaces tab and the associated options are only available for Unified Product Experience tenants. For more information, see Unified Product Experience.

Spaces allow you to categorize mobile devices based on their characteristics or the user they belong to, making it easier to facilitate delegation management. Spaces can be created to reflect an organizational hierarchy or geography. Ivanti Neurons for MDM supports single-level delegation with a central management entity referred to as a Default Space, and a number of subordinate management entities referred to as Delegated Spaces.

To learn more about Spaces, see the Ivanti Neurons for MDM Administrator guide.