Skip to main content
Question

SecOps IAM based access controls

  • May 11, 2026
  • 2 replies
  • 48 views

u6004331239
Forum|alt.badge.img+3

Hi, for some reason, I cannot give GCP users access to our SecOps instance even when the instance should be configured in a way that authentications and authorizations should just work with IAM. I have added the needed roles for the users. I had to give accesses with the Group Mapping feature, by adding the users there with their email-usernames. They can access but they do not have the chronicle.propertySchemaDefinitions.get permission even if I give them Tier1-Tier3 roles. Therefore, they cannot really work with the cases. How I can give them the permission or how I can fix the IAM access feature? How to debug it? I’m not gonna give them admins to SecOps..

2 replies

dnehoda
Staff
Forum|alt.badge.img+17
  • Staff
  • May 11, 2026

The chronicle viewer role should be fine for this.  

What permissions do those groups have under advanced, permissions?  

 

 


u6004331239
Forum|alt.badge.img+3

For some reason it did not work. In Permissions (API keys), they should have all the necessary permissions.

 

I fixed the issue by creating a custom role with the permissions from the Migrate role bindings feature. With these IAM permissions, the users were able to work with the cases as intented.