Access to Forescout Console tools permissions

Action Thresholds
Implement Action Thresholds when working with blocking and restrictive actions. See Working with Action Thresholds for details.
Assets Portal -Host State
View and change the host state from the Assets Portal.
Assets Portal -Login Information
View user login information for a specific address, an endpoint name, a server, within a group.
Assets Portal -Network Services
View information about open network services.
Assets Portal -Security Information
View security information, such as information about antivirus installations.
Audit Trail
View reports on user activities during a specified time period. See Monitoring User Activity.
Backup
Back up and restore system and component settings. See Backing Up System and Component Settings.
CounterACT Appliance Configuration
Configure the Appliance using a variety of configuration tools, including Channels, Organizational Units tools and more.
CounterACT Appliance Control
Start, restart, or stop Appliances, and define mark-naming rules. The rules can be designed so that they reflect naming conventions used in your organization or network environment. This makes the marks more realistic. See About Mark Rules.
CounterACT Crypto Administration
Import, edit, and remove trusted and system certificates in the eyeSight and configure certificate-related settings, such as certificate expiration monitoring and checking for new CRLs and ongoing TLS sessions.
CounterACT Device Script Management
Work with pre-defined scripts in Tools > Options > Advanced > Configuration Script.
Enforcement Mode
Control the Forescout Enforcement mode. Full Enforcement mode allows complete functionality. Partial Enforcement mode lets you monitor network traffic with limited ability to respond. Partial Enforcement mode is recommended for evaluation purposes only.
Enterprise Manager Control
Start, restart, or stop Enterprise Managers.
Event Log
View the Event Log that displays system events. See Work with System Event Logs.
eyeSegment
For users with an eyeSegment license, view and change the eyeSegment matrix and the eyeSegment policy. For specific permission settings, refer to the Assign eyeSegment User Permissions section in the eyeSegment Module Configuration Guide.
Group Management
Add, edit, remove, or update Forescout Groups. The Group Management permission cannot be changed (to read-only or view only) if the Policy Management permission is selected.
Host State Override
Update the state of endpoints and how long the state is maintained. See Changing the Host State and Changing the Host State Maintenance Time.
IPS Scheduled Reports
Work with scheduled Threat Protection Reports.
Legitimate Traffic
Define the addresses of legitimate traffic at your network. See View Legitimate Traffic.
License Management
Install and manage Forescout licenses. See License Management.
Dashboards: Access
View and change information in the Dashboards and Assets views of the Forescout Web Client. See Dashboards and Assets View.
Dashboards: Device Compliance (OOTB)
Enabling this option permits a user to access the Device Compliance dashboard.
Dashboards: Device Visibility (OOTB)
Enabling this option permits a user to access the Device Visibility dashboard.
Dashboards: Health Monitoring (OOTB)
Enabling this option permits a user to access the Device Health dashboard.
Dashboards: Policies, Segments and Groups in Assets Tab
Enabling this option permits a user to view the Policies, Segments, and Groups in the Assets tab.
Malicious Traffic
View malicious traffic. See Threat Protection.
Module Control
Start, stop, test, and get help on plugins and modules.
Module Management
Install and uninstall plugins and modules.
Multiple CounterACT Appliance Management
Manage a number of Appliances within the network. See Managing Appliances, Enterprise Managers, and Consoles.
Policy Control
Start, stop, pause, test, and clear all policy actions without changing the policy definitions. See The Policy Manager.
Policy Management
Create, edit, delete, import, and export either policies, segments, groups, or lists.
Policy Reports
View NAC reports. See Policy Reports and Logs.
Reports
Work with the Reports Portal. See Reports.
Software Upgrade
Upgrade Appliance / Enterprise Manager software.
Refer to About this Upgrade Guide in the Forescout eyeSight Upgrade Guide, which covers the software upgrade procedures.
Threat Protection Policy
View and manage Threat Protection Policy settings.
User Management
View and edit user management features. See Managing Users.
User Portal Builder
Create, duplicate, preview, or export / import customized Guest Management Portal and HTTP pages.
Virtual Firewall
Protect specific services by allowing or preventing traffic and defining various traffic rules. See Managing Your Virtual Firewall Policy.