Secure SIR usage with custom permission sets
- Published on Aug 17, 2026
Prev Next Set permissions to decide which administrators can create or use potentially risky SIR policies.
Note
Only global administrators can create permission sets.
Navigate to → and click New Permission Set.
Enter a name and assign the desired users.
From the Permission Sets list, find your new set and click Edit next to System Information Reporter.
Select the appropriate permissions you want to grant for SIR policies (for example, read-only, full access), and then click Save.
Was this article helpful?
Related articles
ePolicy Orchestrator - On-Prem > ePolicy Orchestrator - On-prem 5.10.0 Product Guide > User accounts and permission sets > Permission sets
ePolicy Orchestrator - On-Prem > ePolicy Orchestrator - On-prem 5.10.0 Product Guide > Enforcing policies > Policy approval management
Endpoint Detection and Response with Forensics (EDRF) > Get started > Understand EDRF roles