Skip to content

Configure Forcepoint One Endpoint Integration

Last Updated: August 6, 2026

Applies To: HySecure Gateway 7.3 SP1 and above

Category: Third-Party Integrations & Endpoint Security

Overview

HySecure Gateway supports automatic deployment and lifecycle management of the Forcepoint One Endpoint agent on user endpoints. When configured, the Workspace Client downloads and installs the Forcepoint Agent on the endpoint during user login, using the settings defined in the assigned Client Profile. Password-protected uninstallation of the agent is also supported.

This integration uses the existing HySecure login workflow as the deployment vehicle. Administrators do not need a separate software distribution tool to push the Forcepoint Agent to endpoints. The agent is installed automatically when the user logs in and the configured Client Profile is applied, and it connects to the organization's Forcepoint tenant using the configured organization identifier.

Prerequisites

  • HySecure Gateway 7.3 SP1 or later.

  • Security Officer or Administrator access to the HySecure Management Console.

  • A valid Forcepoint One Endpoint subscription and tenant configured in the Forcepoint portal.

  • The Forcepoint Agent download URL, available from the Forcepoint portal or your Forcepoint account team.

  • The Organization Identifier (WSCONTEXT) for the Forcepoint tenant, available from the Forcepoint portal.

  • A Client Profile through which the profile will be applied to users.

Note

Support for this feature is not yet available in the Windows Workspace Client. It will be included in an upcoming release. This integration currently applies only to supported non-Windows platforms.

How it works

The Forcepoint integration is configured within a Client Profile under the Internet Security Configurations section. The Client Profile defines both the installation parameters (what agent to install and how to connect it to the Forcepoint tenant) and the uninstallation parameters (whether the agent can be removed and what password protects removal).

When a user logs in and the Client Profile is applied through the assigned Client Configuration ACL, the Workspace Client:

  1. Downloads the Forcepoint Agent from the configured download URL.

  2. Installs the agent on the endpoint.

  3. Connects the agent to the Forcepoint tenant using the configured Organization Identifier (WSCONTEXT).

From that point, the Forcepoint Agent operates independently on the endpoint, enforcing the internet security policies configured in the Forcepoint portal.

If uninstallation is configured, the Workspace Client can remove the Forcepoint Agent from the endpoint using the configured uninstallation password. This prevents users from removing the agent without authorization.

Configuration

Step 1: Configure installation parameters in the Client Profile

  1. Log in to the HySecure Management Console as Security Officer or Administrator.

  2. Navigate to Policies > Client Profiles.

  3. Create a new Client Profile or modify an existing one.

  4. Under Internet Security Configurations, configure the installation parameters:

    Parameter Description
    Install Forcepoint Agent on user login Enables automatic installation of the Forcepoint Agent on the endpoint during user login. Enable this to activate the integration.
    Forcepoint Agent download link The URL from which the Workspace Client downloads the Forcepoint Agent installer. Obtain this URL from the Forcepoint portal or your Forcepoint account team.
    Organization Identifier (WSCONTEXT) The identifier that connects the installed agent to the correct Forcepoint tenant. Obtain this value from the Forcepoint portal under your organization's account settings.

Step 2: Configure uninstallation parameters

  1. Configure the uninstallation parameters in the same Internet Security Configurations section:

    Parameter Description
    Uninstall Forcepoint Agent Enables the Workspace Client to remove the Forcepoint Agent from the endpoint. Enable only when automated uninstallation is required.
    Password to uninstall Forcepoint Agent The password the Workspace Client uses to remove the Forcepoint Agent. This prevents users from unauthorized removal of the agent.

    Important

    If Uninstall Forcepoint Agent is enabled without a password, the agent can be removed without credential verification. Always set a strong uninstallation password when this option is enabled.

  2. Click Submit to save the Client Profile.

Step 3: Associate the Client Profile with a Client Configuration ACL

The Forcepoint configuration in the Client Profile takes effect only when the profile is linked to a Client Configuration ACL that is applied to the relevant users.

  1. Navigate to Policies > ACL.

  2. Create a new Client Configuration ACL or modify an existing one.

  3. Under Client Profile, select the Client Profile configured in Steps 1 and 2.

  4. Click Submit to save the ACL.

  5. Assign the ACL to the appropriate users or user groups through the standard ACL assignment workflow.

Organization Identifier (WSCONTEXT)

The WSCONTEXT value is a unique identifier assigned to the organization's Forcepoint tenant. It is used by the Forcepoint Agent at installation time to register with the correct tenant and download the applicable internet security policies.

Obtain the WSCONTEXT from the Forcepoint portal. If the value is not available, contact your Forcepoint account team.

Endpoint behavior

At login: When the user logs in and the Client Profile is applied, the Workspace Client downloads the Forcepoint Agent installer from the configured URL and installs it silently on the endpoint. The agent connects to the Forcepoint tenant using the WSCONTEXT and begins enforcing the configured internet security policies.

During the session: The Forcepoint Agent runs independently of the HySecure session. Internet security policies are enforced continuously, regardless of HySecure session state.

At logout or session termination: The Forcepoint Agent continues to run on the endpoint after the HySecure session ends. It is not automatically removed at logout.

Note

If Uninstall Forcepoint Agent is configured in the Client Profile, the agent is installed at the time of login and removed at logout.

On subsequent logins: If the agent is already installed on the endpoint from a previous session, the Workspace Client checks whether installation is required and skips reinstallation if the agent is present and up to date.

Limitations

  • Support for this integration is not yet available in the Windows Workspace Client. It will be included in an upcoming release.

  • The Forcepoint Agent download URL must be publicly accessible or reachable from the endpoint at the time of login. If the endpoint cannot reach the download URL, installation will not proceed.

  • Each Client Profile supports one Forcepoint Agent configuration. To apply different Forcepoint configurations to different user groups, use separate Client Profiles linked to separate Client Configuration ACLs.