This document describes how to configure Advanced Malware Protection (AMP) user privileges for Cisco ESA and SMA.
Cisco recommends knowledge of these topics:
The information in this document is based on these software and hardware versions:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
This feature provides a role for AMP configuration privileges. When this privilege is assigned to a user, the user can configure only AMP security settings.
To view AMP-related reports, this AMP configuration privilege also provides access to AMP configuration settings and AMP reports. AMP Reports access is provided for these four reports:
Create a new user role on Cisco Secure Email (ESA):

Create a new user and assign the user role created in the previous section:

Create a new user role on Cisco Secure Email and Web Manager (SMA):

Create a new user and assign the user role created in the previous section.

Confirm that the user can access only AMP configuration settings and the AMP reports allowed by the assigned role. ESA roles include AMP Configuration and related Email Reporting permissions. SMA roles apply to the selected appliance group or to all email appliances, depending on the selected scope.
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
01-Jul-2026
|
Initial Release |
1.0 |
29-Sep-2022
|
Initial Release |