> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-administrations.md).

# Agent Administrations

Agent Administration provides comprehensive endpoint and agent management capabilities, such as viewing all managed endpoints and their status, monitoring agent health, version, and connectivity, and performing agent operations (upgrade, uninstall, restart).

| Permissions | Description                                                                                                                                                              | Roles Example                                                                                                                                                                                                                                                         |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None        | No access to the Endpoints menu (**Inventory** → **Endpoints**, including access to the **All Endpoints** page. Limited access to endpoint data in cases and in widgets. |                                                                                                                                                                                                                                                                       |
| View        | Read-only access to the Endpoints menu, including the **All Endpoints** page, which enables users to view, for example, endpoint lists, details, upgrade, and uninstall. | <ul><li>SOC Tier-1 Analyst: Should focus on triage and escalation, not endpoint management. Accidental changes could impact protection.</li><li>Threat Hunter: Focus on detection, not endpoint management. Should request actions through proper channels.</li></ul> |
| View/Edit   | All view capabilities. When selecting View/Edit, you can select separate permissions, such as Agent Management, Retrieve Agent Data, and Agent Scan.                     | <ul><li>SOC Tier-2 and 3 Analysts: May need specific sub-options (like Isolate) for incident response, but full edit access is not required.</li><li>Security Engineer: Responsible for agent lifecycle management, upgrades, and configuration.</li></ul>            |

**Agent Administrations sub-permissions**

| Sub-permission         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Roles Example                                                                                                                                                |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Agent Management       | <p>High risk. Controls core agent lifecycle and the following configuration operations by right-clicking an endpoint from the <strong>All Endpoints</strong> page (<strong>Inventory</strong> → <strong>Endpoints</strong> → <strong>All Endpoints</strong> → <strong>Endpoint Control</strong>):</p><ul><li><p>Open in Interactive Mode</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Opens an interactive terminal session on the selected endpoint where you can run scripts in real-time. You need to add View/Edit permission for Agent Script and Scripts under Investigation and Response permissions.</p></div></li><li>Perform Heartbeat</li><li>Change Endpoint Alias</li><li>Upgrade Agent version</li><li>Set/Disable Agent Proxy</li><li>Uninstall Agent</li><li>Delete Endpoint</li><li>Disable Capabilities</li><li>Force Check-in</li><li>Restart Agent</li><li>Clear Agent Database</li><li>Exclude/Include endpoints from auto upgrade</li><li>Assign/Remove Endpoint Tags</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>To access advanced endpoint actions like Force Check-in, Restart, and Clear Agent Database, users must hold Alt/Option while right-clicking the endpoint to open the advanced Endpoint Control menu.</p></div> | <ul><li>Security Engineer: Primary responsibility for agent deployment, upgrades, and maintenance.</li></ul>                                                 |
| Retrieve Agent Data    | <p>Enables retrieval of detailed agent diagnostic information, logs, and operational data by right-clicking an endpoint and selecting <strong>Endpoint Control</strong> → <strong>Retrieve from Support File</strong> from the <strong>ALL Endpoints</strong> page.</p><p>Users can also select <strong>Retrieve Support File Password</strong> from the Key icon on the <strong>All Endpoints</strong> page (top right-hand corner).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | SOC 2 and 3 Analysts, and Security Engineer: Agent troubleshooting and support.                                                                              |
| Agent Scan             | Initiate on-demand malware scans on endpoints by right-clicking an endpoint,**Security Operations** → **Initiate Malware Scan**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | All roles. SOC Tier-1 Analysts may need View permission with approval workflow. Initiating scans can impact endpoint performance. Should escalate to Tier-2. |
| Change Managing Server | Reassign agents to different Cortex XDR management servers by right-clicking an endpoint and selecting **Endpoint Control** → **Change managing server**. Useful for disaster recovery, load balancing across management infrastructure, and migrating endpoints between environments (development/production). For more information, see [Move agents between managing servers](/cortex-xdr-5.x/protect-your-endpoints/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Security Engineer: May be needed for infrastructure changes or disaster recovery (with change management approval).                                          |
| Pause Protection       | <p>High risk. Temporarily disable agent protection modules on endpoints by right-clicking an endpoint and selecting <strong>Endpoint Control</strong> → <strong>Pause Endpoint Protection</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Caution</strong></p><p>Pausing protection leaves endpoints vulnerable to threats. This should only be used for troubleshooting or software installation that conflicts with protection.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                              |
| Agent Token Management | <p>High risk. Manage agent authentication tokens and credentials by right-clicking an endpoint and selecting <strong>Endpoint Control</strong> → <strong>View Token</strong>, or <strong>Set Temporary Token</strong>. Tokens can also be managed on the All Endpoints page when clicking the <strong>Key</strong> button (top right-hand side of the page). For more information, see <a href="/spaces/cyIgISZgANJYkmLlnwdK/pages/SZZ0aKy0c53Np691eo0W">Manage agent tokens</a>.</p><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Caution</strong></p><p>Token regeneration will temporarily disconnect agents until they receive the new token. Token revocation will permanently disconnect agents until they are manually re-enrolled.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |                                                                                                                                                              |

**Required and recommended permissions**

Consider adding the following permissions:

| Permission                | Permission Level  | Reason                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ------------------------- | ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases & Issues            | View or View/Edit | <ul><li>View: Strongly recommended. Without case access, users cannot follow endpoint-to-case investigation links. Also, Agent Scans are often triggered during case response. Case context helps correlate scan results with active investigations.</li><li>View: Recommended for Retrieve Agent Data and Pause Protection. Retrieval is often triggered during case investigation. Case context helps document why data was retrieved. Pausing protection should only be done in the context of an active investigation or documented change. Case access provides the justification context.</li></ul>                                                                                                                                                                                                                                                                  |
| Host Insights             | View              | Strongly recommended. Provides detailed endpoint security data, including vulnerability assessment and compliance status. Enhances endpoint context.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Action Center             | View              | <p>Strongly recommended for response actions on endpoints. In particular:</p><ul><li>Agent Scan: Strongly recommended. Scan status and results are tracked in Action Center. Without it, users cannot monitor scan progress or view results.</li><li>Retrieve Agent Data: Strongly recommended. Retrieval results appear in the Action Center. Without it, users cannot track retrieval status or download completed files.</li><li>Pause Protection: Strongly recommended. Track when protection was paused and resumed. Essential for audit trail and ensuring protection is re-enabled.</li></ul><p>Recommended for the following:</p><ul><li>Agent Management: Track the status and history of agent management operations (upgrades, uninstalls).</li><li>Agent Token Management: Recommended. Track token generation and usage history for audit purposes.</li></ul> |
| Agent Groups              | View              | <p>Required. Endpoints are organized into groups. Without group visibility, users cannot understand policy targeting and endpoint organization. In particular:</p><ul><li>Agent Management: Agent upgrades, uninstalls, and proxy changes are often performed by group. Without group visibility, bulk operations lack context.</li><li>Change Management Server: Server migration affects group membership and policy assignment. Understanding the current group structure is essential before migration.</li></ul>                                                                                                                                                                                                                                                                                                                                                      |
| Agent Prevention Policies | View              | <p>Strongly recommended. Before modifying endpoints, administrators need to understand what security policies are applied to avoid disrupting protection. In particular:</p><ul><li>Agent Management: Before uninstalling or downgrading agents, understanding applied policies prevents leaving endpoints unprotected.</li><li>Change Management Server: Policies may differ between servers. Understanding current policy assignment prevents protection gaps after migration.</li><li>Pause Protection: View (minimum). Strongly recommended. Understanding what protection modules are active helps assess the risk of pausing protection.</li></ul><p>Recommended for Agent Scan. Understanding prevention policy settings helps interpret scan results and determine if additional scanning is needed.</p>                                                           |
| Agent Installations       | View              | <p>Recommended when upgrading agents, visibility into available installation packages helps select the correct version.</p><p>Strongly recommended for Agent Management. Agent upgrade requires knowing available versions. Installation packages determine what versions can be deployed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Agent Profiles            | View              | Strongly recommended for Change Management Server. Profiles may differ between servers. Understanding the current profile assignment prevents configuration changes after migration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Retrieve Agent Data       | Checked           | Strongly recommended for Agent Token Management. Both are often needed together.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/role-based-access-control/inventory-agent-permissions/agent-administrations.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
