The table below shows the Kaspersky Security Center Linux features with the access rights to manage the associated tasks, reports, settings, and perform the associated user actions.
To perform the user actions listed in the table, a user has to have the right specified next to the action.
All tasks, reports, settings, and installation packages that are missing in the table belong to the General features: Basic functionality functional area.
| Functional area | Right | User action: right required to perform the action | Task | Report | Other | 
| General features: Management of administration groups | Write | Add device to an administration group: WriteDelete device from an administration group: WriteAdd an administration group to another administration group: WriteDelete an administration group from another administration group: Write
 | None | None | None | 
| General features: Access objects regardless of their ACLs | Read | Get read access to all objects: Read | None | None | The General features: Access objects regardless of their ACLs functional area is intended for audit purposes. When users are granted Read rights in this functional area, they get full Read access to all objects and are able to execute any created tasks on selections of devices connected to the Administration Server via Network Agent with local administrator rights (root for Linux). We recommend granting these rights carefully and to a limited set of users who need them to perform their official duties. Access is granted regardless of other rights, even if they prohibit read access to specific objects. | 
| General features: Basic functionality | ReadWriteExecutePerform operations on device selections
 | Device moving rules (create, modify, or delete) for the virtual Server: Write, Perform operations on device selectionsGet Mobile (LWNGT) protocol custom certificate: ReadSet Mobile (LWNGT) protocol custom certificate: WriteGet NLA-defined network list: ReadAdd, modify, or delete NLA-defined network list: WriteView Access Control List of groups: ReadView the operating system log: ReadView the recovery key to restore access to a hard drive encrypted by BitLocker: Execute
 | "Download updates to the Administration Server repository""Deliver reports""Distribute installation package""Install application on secondary Administration Servers remotely"
 | "Report on protection status""Report on threats""Report on most heavily infected devices""Report on status of anti-virus databases""Report on errors""Report on network attacks""Summary report on mail system protection applications installed" "Summary report on workstation protection and Windows Server protection applications installed" "Summary report on perimeter defense applications installed""Summary report on types of applications installed""Report on users of infected devices""Report on security issues""Report on events""Report on activity of distribution points""Report on secondary Administration Servers""Report on Device Control events""Report on vulnerabilities" "Report on prohibited applications""Report on Web Control""Report on encryption status of managed devices""Report on encryption status of mass storage devices""Report on rights to access encrypted drives""Report on file encryption errors""Report on blockage of access to encrypted files""Report on effective user permissions""Report on rights"
 | None | 
| General features: Deleted objects |  | View deleted objects in the Recycle Bin: ReadDelete objects from the Recycle Bin: Write
 | None | None | None | 
| General features: Event processing | Delete eventsEdit event notification settingsEdit event logging settingsWrite
 | Change events registration settings: Edit event logging settingsChange events notification settings: Edit event notification settingsDelete events: Delete events
 | None | None | Settings: The maximum number of events stored in the databasePeriod of time for storing events from the deleted devices 
 | 
| General features: Operations on Administration Server | ReadWriteExecuteModify object ACLsPerform operations on device selections
 | Specify ports of Administration Server for the network agent connection: WriteSpecify ports of Activation Proxy launched on the Administration Server: WriteSpecify ports of Activation Proxy for Mobile launched on the Administration Server: WriteSpecify ports of the Web Server for distribution of standalone packages: WriteSpecify ports of the Web Server for distribution of MDM profiles: WriteSpecify SSL-ports of the Administration Server for connection via Web Console: WriteSpecify ports of the Administration Server for mobile connection: WriteSpecify the maximum number of events stored in the Administration Server database: WriteSpecify the maximum number of events that can be sent by the Administration Server: WriteSpecify time period during which events can be sent by the Administration Server: Write
 | "Backup of Administration Server data""Databases maintenance"
 | None | None | 
| General features: Kaspersky software deployment | Manage Kaspersky patchesReadWriteExecutePerform operations on device selections
 | Approve or decline installation of the patch: Manage Kaspersky patches | None | "Report on license key usage by virtual Administration Server""Report on Kaspersky software versions""Report on incompatible applications""Report on versions of Kaspersky software module updates""Report on protection deployment"
 | Installation package: "Kaspersky" | 
| General features: Key management |  | Export key file: Export key fileModify Administration Server license key settings: Write
 | None | None | None | 
| General features: Enforced report management |  | Create reports regardless of their ACLs: WriteExecute reports regardless of their ACLs: Read
 | None | None | None | 
| General features: Hierarchy of Administration Servers | Configure hierarchy of Administration Servers | Register, update, or delete secondary Administration Servers: Configure hierarchy of Administration Servers
 | None | None | None | 
| General features: User permissions | Modify object ACLs | Change Security properties of any object: Modify object ACLsManage user roles: Modify object ACLsManage internal users: Modify object ACLsManage security groups: Modify object ACLsManage aliases: Modify object ACLs
 | None | None | None | 
| General features: Virtual Administration Servers | Manage virtual Administration ServersReadWriteExecutePerform operations on device selections
 | Get list of virtual Administration Servers: ReadGet information on the virtual Administration Server: ReadCreate, update, or delete a virtual Administration Server: Manage virtual Administration ServersMove a virtual Administration Server to another group: Manage virtual Administration ServersSet administration virtual Server permissions: Manage virtual Administration Servers
 | None | None | None | 
| General features: Encryption Key Management | Write | Import the encryption keys: Write | None | None | None | 
| Mobile device management: General  | Connect new devicesSend only information commands to mobile devicesSend commands to mobile devicesManage certificatesReadWrite
 | Get Key Management Service restore data: ReadDelete user certificates: Manage certificatesGet user certificate public part: ReadCheck if Public Key Infrastructure is enabled: ReadCheck Public Key Infrastructure account: ReadGet Public Key Infrastructure templates: ReadGet Public Key Infrastructure templates by Extended Key Usage certificate: ReadCheck if Public Key Infrastructure certificate is revoked: ReadUpdate user certificate issuance settings: Manage certificatesGet user certificate issuance settings: ReadGet packages by  application name and version: ReadSet or cancel user certificate: Manage certificatesRenew user certificate: Manage certificatesSet user certificate tag: Manage certificatesRun generation of MDM installation package; cancel generation of MDM installation package: Connect new devices
 | None | None | None | 
| System management: Connectivity | Start RDP sessionsConnect to existing RDP sessionsInitiate tunnelingSave files from devices to the administrator's workstationReadWriteExecutePerform operations on device selections
 | Create desktop sharing session: The right to create desktop sharing sessionCreate RDP session: Connect to existing RDP sessionsCreate tunnel: Initiate tunnelingSave content network list: Save files from devices to the administrator's workstation
 | None | "Report on device users" | None | 
| System management: Vulnerability and patch management | ReadWriteExecutePerform operations on device selections
 | View third-party patch properties: ReadChange third-party patch properties: Write
 | "Fix vulnerabilities""Install required updates and fix vulnerabilities"
 | "Report on software updates" | None | 
| System management: Execute scripts remotely | ReadWriteExecutePerform operations on device selections
 | User can view the task properties: Read User can create, delete or modify an installation package: Write User can run a task: Write. On client Linux devices scripts are executed with root privileges. User can run a task or schedule it to run: Execute User can run a task on a selection of devices: Perform operations on device selections | "Execute scripts remotely" | None | None |