Is it possible to deny access to certain Roles to certain BigFix sites like BES Support?
Or is it possible to only allow Roles to see certain Custom Sites?
You can certainly control site access via Roles (https://www.ibm.com/support/knowledgecenter/SSQL82_9.5.0/com.ibm.bigfix.doc/Platform/Console/Dialogs/role_sites_tab.html), but it is not possible to remove ‘read’ access to BES Support (which is required for general Console functionality). Also, note that permissions are additive (i.e. if an operator is assigned two different roles, and one role has read access to a specific site, but the other does not have read access to the same site, the operator will effectively have read access to the site).
A master operator can globally hide content in BES Support which prevents non-master operators from seeing it or using it. It also has the effect of uncluttering non-master operator consoles.
I generally like to go and globally hide things that are superseded that do not have any applicable computers and that I’m fairly confident that they are not going to be needed in my environment.