Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Request] RBAC update - third party response actions #6398

Open
caitlinbetz opened this issue Jan 7, 2025 · 0 comments
Open

[Request] RBAC update - third party response actions #6398

caitlinbetz opened this issue Jan 7, 2025 · 0 comments
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Feature: Response actions also includes response console Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0

Comments

@caitlinbetz
Copy link

caitlinbetz commented Jan 7, 2025

Description

We have made a change to the RBAC requirements for using third party response actions, requiring users to add a second privilege to use these capabilities.

Existing docs pages:
https://www.elastic.co/guide/en/security/current/third-party-actions.html
https://www.elastic.co/guide/en/security/current/response-actions-config.html

A user will need BOTH of following Kibana privileges to use third party response actions:

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

ESS: 8.18

Serverless release

Monday January 27

Feature differences

No differences

API docs impact

@paul-tavares could you provide?

Prerequisites, privileges, feature flags

No response

@natasha-moore-elastic natasha-moore-elastic self-assigned this Jan 8, 2025
@natasha-moore-elastic natasha-moore-elastic added Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management Feature: Response actions also includes response console Docset: Serverless Issues for Serverless Security Docset: ESS Issues that apply to docs in the Stack release v8.18.0 Priority: Medium Issues that have relevance, but aren't urgent Effort: Medium Issues that take moderate but not substantial time to complete labels Jan 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Feature: Response actions also includes response console Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0
Projects
None yet
Development

No branches or pull requests

2 participants