Security Management Platform Global Settings Current - User Guide

Working with Security Management Platform Global Settings Overview of Security Management Platform Global Settings Signing up for Security Management Platform Global Settings Managing organizations and regions Adding users and groups to an organization Managing your Microsoft Entra tenants and on-premises domains Security Management Platform Home page Configuring settings Documentation roadmap Technical Support

Organization

Once an organization has been created, you can select Settings | Organization in the left navigation to see the organization details, edit the organization name and the domains that are authorized to access it and delete organizations that are no longer needed.

For details, see Editing organization settings and Deleting organizations.

Access Control

Once you have created an organization, you can add additional users and determine what tasks each user can perform. To perform these activities, select Settings | Access Control in the left navigation bar.

Access control is a process by which users are granted access and certain privileges to systems, resources, or information. In Security Management Platform, you can grant authenticated users access to specific resources based on your company policies and the permission level assigned to the user.

The Access Control setting provides two options: Roles and Users

To see the task flow for access control procedures, see the task flow Assigning a role to a user.

API Keys

The Public API provides secure, programmatic access to organization data outside the Security Management Platform console. To access the API, you need a dedicated organization-specific Public API token. API tokens can be granted specific permissions and can be set to expire or be revoked when no longer needed.

For each request, the token is validated against your organization's token record, including expiration, revocation status, and assigned scopes. After validation, the token is exchanged for a short-lived access token, and the request is forwarded to the underlying service.

An interactive Playground for trying example queries against the Public API is in early design. See the Public API Playground prototype for a preview of the proposed experience.

Managing API keys and permissions

The ability to create, edit, regenerate, revoke, or delete API keys is controlled by the Can Manage API Keys permission. This permission allows users to manage API keys for the organization but does not grant access to API data or operations.

Access to the Public API is determined by the permissions assigned to each API key. An API key can only perform the actions and access the data allowed by its assigned permissions.

NOTE: The Can Manage API Keys permission controls who can manage API keys, while the permissions assigned to an API key determine what the key can access.

Follow these recommendations to help secure and manage API access within your organization:

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating