Agent Extension Policies

Manage profiles for additional endpoint capabilities, such as configuring third-party integrations, managing agent extension modules, and defining extension deployment policies.

Note

Agent Extension Policies enable access to configure extension policies, profiles, and exceptions. Device Control rules perform device control actions within the extension policies.

Permissions Description Roles Example
None Cannot view the Agent Extensions menu (InventoryEndpointsPolicy ManagementExtensions, which includes Policy Rules, Profiles, Device Permanent Extensions, and Device Temporary Extensions. SOC Tier-1 Analyst: Extension policies are typically not needed for basic triage. Although it may provide context for understanding additional agent capabilities
View View the Agent Extensions menu and read-only access for the Policy Rules, Profiles, Device Permanent Extensions, and Device Temporary Extensions. <ul><li>SOC Tier-2 Analyst: Understanding extension policies helps explain additional agent capabilities during investigations. Extensions like Device Control or Host Firewall affect endpoint behavior.</li><li>SOC Tier-3 Analyst: Full visibility needed for advanced analysis of agent extensions and their impact on endpoint protection and telemetry.</li><li>Threat Hunter: Extension visibility helps understand the full agent capability set for hunting. Hunters need to know what protections are active.</li></ul>
View/Edit All view capabilities, plus managing Policy Rules, Profiles, Device Permanent Extensions, and Device Temporary Extensions. Security Engineer: Responsible for extension configuration and deployment. Manages which extensions are enabled for different endpoint groups.

Required and recommended permissions

Consider adding the following permissions:

Permission Permission Level Reason
Agent Groups View Required for policy targeting.
Device Control View Strongly Recommended. Extension profiles include Device Control settings. The Device Control view provides violation data that complements the extension policy context. For View/Edit, required, as Extension profiles contain Device Control settings. Device Control edit access is needed to manage violations and add exceptions from the violations view.
Agent Administrations View Strongly Recommended. View endpoints to validate extension deployment and verify feature enablement after changes.
Host Firewall View Strongly Recommended. Extension profiles include Host Firewall settings. Firewall view provides event data that complements the extension policy context.
Agent Profiles View Strongly Recommended. Extension profiles work alongside agent profiles. Understanding both prevents configuration conflicts.
Cases & Issues View Recommended. Review security events related to Device Control and Host Firewall to inform extension policy decisions.