1. Forescout Platform and Base Modules Administration Guide 8.4.1, "Endpoint Detection" section, page 45. This section details how Forescout discovers endpoints, explicitly mentioning the DHCP Classifier plugin which "detects endpoints when they send DHCP requests to a DHCP server." This confirms DHCP requests are admission events.
2. Forescout Platform and Base Modules Administration Guide 8.4.1, "How Policies Are Evaluated" section, page 412. The documentation states, "Policy evaluation is triggered by events, for example, when an endpoint connects to the network, its IP address changes, or a user logs in." This confirms IP address changes and logins are admission events.
3. Forescout Authentication Module Configuration Guide 8.4, "About the Module" section, page 9. It describes how the module "learns about endpoints connecting to the network via RADIUS authentication and accounting messages," confirming authentication server logins are admission events.
4. Forescout VPN Concentrator Plugin Configuration Guide 8.4, "About the Plugin" section, page 8. The guide explains that the plugin "lets you monitor and control remote endpoints that connect to the network through VPNs," treating the connection as an event to be managed.