
susab (susab) asked a question.
I need to create a Read_Only account and request an API token to provide to our SOC/SIEM. I created the Admin account (under Security - Administrators) and assigned the Reports Administrator role to it. When creating the token for the SOC (read only), do I do that as my Org Admin role, or is there a way to create it as the Read_Only user? I do not see an option to create token under the Read-Only user that I created.

Don't use your own Org Admin account. API tokens always have the same rights as the account used to create them. The Reports Admin role does not have the right to create API tokens. You want to assign it the Read-Only Admin role, and then sign in with it and generate the token. Once you have the token, then go back and remove the Read-Only Admin role (leaving the Reports Admin role intact). The token will now have the same rights as the account - Reports Admin.