The Trellix Application and Change Control 8.3.6 release addresses known issues, new platform support, and performance improvements. It also addresses product rebranding changes.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
For release dates and build numbers, see KB87944.
This release supports:
Trellix ePolicy Orchestrator - On-premises 5.10.0
Trellix Agent 5.7.7 and 5.7.8
For details about supported ePO - On-prem and Trellix Agent versions, see KB87944.
Note
Before installing or upgrading to Trellix Application and Change Control 8.3.6, make sure to update the MsgBus Cert Updater package to the latest version available. This package is available on Software Catalog under the Trellix Agent product. For details, see KB95958.
As part of rebranding, the certificates used to sign our software have been updated. If your enterprise automatically updates root certificates, the software update/installation does not require any additional effort. However, if your enterprise manages root certificate updates manually, you need to install the new intermediate and root certificates. For information about downloading and installing the certificates, see KB91697.
Upgrade support
This release supports upgrading from:
TACC extension 8.0.x, 8.1.x, 8.2.x, 8.3.0, 8.3.1, 8.3.2, 8.3.3, 8.3.4 and 8.3.5.
When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.
For more information, see KB84651.
TACC client 8.0.x, 8.1.x, 8.2.x, 8.3.0, 8.3.1, 8.3.2, 8.3.3, 8.3.4 and 8.3.5.
For information about the TACC client upgrade supported path for Windows, see KB87944.
New or changed
Rebranding changes:
This is solely for informational purpose, there is no action required. You can continue to secure your organization with Trellix Application and Change Control as usual.
You will notice the following changes in the software:
Product Name — McAfee Application Control, McAfee Change Control, and McAfee Application and Change Control are renamed to Trellix Application Control, Trellix Change Control, and Trellix Application and Change Control. All features and options prefixed with the product names are renamed with the new product name.
Brand logo — McAfee logo is replaced with Trellix logo.
User interface — Color and typeface are updated to provide a better user experience.
Copyright — The Copyright is updated as per legal requirements.
Docker co-existence — Trellix Application and Change Control 8.3.6 co-exists with Windows Docker. For information about how to configure Trellix Application and Change Control to work with Windows Docker, see KB96249.
Solidification time improvement — 25% solidification time improvement is achieved with TACC 8.3.6. To see solidification improvements, you need to configure the command, AvoidVolumeNameExtractionWherePossible=1, from the CLI client or from Trellix ePO through SC: Run Commands.
Known issues
For a list of current known issues, see Application Control 8.x Known Issues (KB87839) and Change Control 8.x Known Issues (KB87838).
Resolved issues
This update resolves known issues.
TACC extension
Category | Resolution | Resolution |
|---|---|---|
Fixes to features | MACC-11242 | Reconciliation action is now available for Application Control events. |
User Interface | MACC-11211 | The PathWritableonlyByUpdater option on the Secure Policy page is now visible on the Trellix ePO - On-prem UI. |
User Interface | MACC-11326 | Multiple email recipients can be now added in the Mail-To field under End User Notifications when saving the Application Control Options (Windows) policy. |
Fixes to features | MACC-11412 | The Solidcore purge task no longer creates new orphan events. |
Fixes to features | MACC-11371 | Global Threat Intelligence communication related errors are no longer seen in logs as new Trellix GTI certificates are now incorporated with the TACC extension. |
TACC client
Category | Resolution | Resolution |
|---|---|---|
Fixes to features | MACC-11192 | Potentially sensitive Trellix Application and Change Control files can no longer be edited regardless of any mode. |
Fixes to features | MACC-11280 | CIFS file copy time is improved when the network-tracking option is enabled. |
Fixes to features | MACC-11380 | When the Trusted Local Group feature is enabled and the user is not part of any local group, applications no longer get blocked by default. |
Fixes to features | MACC-11275 | The file changed to non-binary is no longer blocked by Write Denied. |