Agent Profiles

Defines agent behavior and configuration settings, including agent communication settings and proxy configurations.

Permissions Description Roles Example
None Cannot view the Prevention Profiles page (InventoryEndpointsPolicy ManagementPreventionProfiles and is limited to the profile name when viewing the profile in endpoint details. SOC Tier-1 Analyst: Profile details are typically not needed for basic triage. Although it may be useful for understanding why certain agent features are enabled/disabled on specific endpoints
View View the Agent Profiles menu and read-only access for the Profiles list, details, settings, and view assigned groups. <ul><li>SOC Tier-2 Analyst: Understanding agent profiles helps explain agent behavior and capabilities during investigations. Profiles determine what data the agent collects and reports</li><li>SOC Tier-3 Analyst: Full profile visibility needed for advanced analysis and understanding agent configuration. Critical for determining if an agent was properly configured during a case.</li><li>Threat Hunter: Profile visibility helps understand agent capabilities and potential detection gaps. Hunters need to know what telemetry is available from each endpoint.</li></ul>
View/Edit All view capabilities, plus managing profiles, assigning to groups, and configuring all settings. Security Engineer: Responsible for profile configuration and optimization. Creates and maintains profiles for different endpoint types.

Required and recommended permissions

Consider adding the following permissions:

Permission Permission Level Reason
Agent Groups View Required. Profiles are assigned to groups. Without group visibility, users cannot understand which endpoints use which profiles.
Agent Administrations View Required. Must see endpoints to validate profile deployment and verify agent configuration after changes.
Agent Prevention Policies View Strongly recommended. Profiles define settings within policies. Understanding policy context prevents conflicting configurations.
Network Configuration View Strongly recommended. Profiles include proxy and network settings. Network configuration visibility ensures profile settings align with network infrastructure.
Agent Installations View Recommended. Profile settings may depend on the agent version. Installation visibility helps ensure profile compatibility.