Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Request] RBAC update - third party response actions #6398

Closed
caitlinbetz opened this issue Jan 7, 2025 · 3 comments · Fixed by #6434
Closed

[Request] RBAC update - third party response actions #6398

caitlinbetz opened this issue Jan 7, 2025 · 3 comments · Fixed by #6434
Assignees
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Feature: Response actions also includes response console Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0

Comments

@caitlinbetz
Copy link

caitlinbetz commented Jan 7, 2025

Description

We have made a change to the RBAC requirements for using third party response actions, requiring users to add a second privilege to use these capabilities.

Existing docs pages:
https://www.elastic.co/guide/en/security/current/third-party-actions.html
https://www.elastic.co/guide/en/security/current/response-actions-config.html

A user will need BOTH of following Kibana privileges to use third party response actions:

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

ESS: 8.18

Serverless release

Monday January 27 2025

Feature differences

No differences

API docs impact

@paul-tavares could you provide?

Prerequisites, privileges, feature flags

No response

@natasha-moore-elastic natasha-moore-elastic self-assigned this Jan 8, 2025
@natasha-moore-elastic natasha-moore-elastic added Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management Feature: Response actions also includes response console Docset: Serverless Issues for Serverless Security Docset: ESS Issues that apply to docs in the Stack release v8.18.0 Priority: Medium Issues that have relevance, but aren't urgent Effort: Medium Issues that take moderate but not substantial time to complete labels Jan 8, 2025
@natasha-moore-elastic
Copy link
Contributor

Hey @caitlinbetz @paul-tavares, is there a test environment you could share for this feature?

Thanks!

@paul-tavares
Copy link
Contributor

@natasha-moore-elastic ,

See my comment on this issue: #6303 (comment)

@lcawl
Copy link
Contributor

lcawl commented Jan 17, 2025

Management > Actions and Connectors > EDR sub-privilege
New privilege that we would like to document

I'm not sure where you want to mention this in the Security Guide, but I've created elastic/kibana#207136 to mention it in the Kibana Guide.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Docset: ESS Issues that apply to docs in the Stack release Docset: Serverless Issues for Serverless Security Effort: Medium Issues that take moderate but not substantial time to complete Feature: Response actions also includes response console Priority: Medium Issues that have relevance, but aren't urgent Team: EDR Workflows Formerly Defend Workflows, Onboarding and Lifecycle Management v8.18.0
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants