Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformMedium

A security administrator is configuring user access to Prisma Cloud and needs to restrict certain users to only view compliance dashboards and reports for a specific business unit's cloud accounts, without allowing them to modify any policies or configurations. Which access control mechanism should be used to achieve this granular level of control?

  1. ASAML Group Mapping
  2. BCustom Roles with Resource Groups
  3. CDefault Admin Roles
  4. DAccount Groups
Show answer & explanation

Correct answer: B. Custom Roles with Resource Groups

Custom Roles in Prisma Cloud allow defining precise permissions (e.g., 'view only' for compliance). Combining these with Resource Groups (which logically group cloud accounts) enables granular control, restricting users to specific actions on specific sets of resources.

Why the other options are wrong

  • A. SAML Group Mapping connects external identity provider groups to Prisma Cloud roles, but the roles themselves (default or custom) define the permissions.
  • C. Default Admin Roles are broad and typically provide more permissions than 'view only' for specific accounts.
  • D. Account Groups organize cloud accounts but do not, by themselves, define permissions for users; they are used in conjunction with roles.

Prisma Cloud Custom Roles & Resource Groups

Custom Roles define specific permissions in Prisma Cloud, which can then be applied to users or groups, often in conjunction with Resource Groups to limit access to a subset of cloud assets.

  • Custom Roles enable least privilege access.
  • Resource Groups logically segment cloud accounts.
  • Together they provide granular, context-aware access control.

Memory trick: Custom roles define 'what' you can do, Resource Groups define 'where'.

More Prisma Cloud Platform questions