Agent Profiles ↗
Defines agent behavior and configuration settings, including agent communication settings and proxy configurations.
| Permissions | Description | Roles Example |
|---|---|---|
| None | Cannot view the Prevention Profiles page (Inventory → Endpoints → Policy Management → Prevention → Profiles and is limited to the profile name when viewing the profile in endpoint details. | SOC Tier-1 Analyst: Profile details are typically not needed for basic triage. Although it may be useful for understanding why certain agent features are enabled/disabled on specific endpoints |
| View | View the Agent Profiles menu and read-only access for the Profiles list, details, settings, and view assigned groups. | <ul><li>SOC Tier-2 Analyst: Understanding agent profiles helps explain agent behavior and capabilities during investigations. Profiles determine what data the agent collects and reports</li><li>SOC Tier-3 Analyst: Full profile visibility needed for advanced analysis and understanding agent configuration. Critical for determining if an agent was properly configured during a case.</li><li>Threat Hunter: Profile visibility helps understand agent capabilities and potential detection gaps. Hunters need to know what telemetry is available from each endpoint.</li></ul> |
| View/Edit | All view capabilities, plus managing profiles, assigning to groups, and configuring all settings. | Security Engineer: Responsible for profile configuration and optimization. Creates and maintains profiles for different endpoint types. |
Required and recommended permissions
Consider adding the following permissions:
| Permission | Permission Level | Reason |
|---|---|---|
| Agent Groups | View | Required. Profiles are assigned to groups. Without group visibility, users cannot understand which endpoints use which profiles. |
| Agent Administrations | View | Required. Must see endpoints to validate profile deployment and verify agent configuration after changes. |
| Agent Prevention Policies | View | Strongly recommended. Profiles define settings within policies. Understanding policy context prevents conflicting configurations. |
| Network Configuration | View | Strongly recommended. Profiles include proxy and network settings. Network configuration visibility ensures profile settings align with network infrastructure. |
| Agent Installations | View | Recommended. Profile settings may depend on the agent version. Installation visibility helps ensure profile compatibility. |