Client Configuration for TACC

Prev Next

Configuration Name

Summary

Details

Customer configuration associated

ServiceStartFinetune

This configuration handles boot performance issues faced in few of the operating systems.

ServiceStartFinetune=7 settings can be configured on system to minimize the boot performance issues (if any). This can be configured using client task from ePO - SaaS using SC:Run command.

NA

UsernameRetryCountInUMode

This configuration handles boot performance issues happening due to username retrial.

User-mode lookup for the username will be retried only after a first successful resolution of the username. This ensures that Solidcore are not retrying the username unnecessarily and thereby delaying the boot. A configuration that specifies the number of retries is also added. UsernameRetryCountInUMode default value is 4 and it is configurable with client task from ePO - SaaS using SC:Run command.

CustomerConfig2 bit (8) need to be configured to revert to the original behavior where username is retried based on the retry count configured even after unsuccessful resolutions of username many times.

Example: If customerConfig2 value is 0, the CustomerConfig2 value in this case is decimal 256. This value varies based on default customerconfig2 value set. 8th bit needs to be added to default value.

PackageControlCmdlineFull MatchBinaries

This configuration is introduced as a generic option to fine-tune package control and resolve performance issues related to installation package.

This configuration can be configured from ePO - SaaS as client task using SC:Run command.

You must reboot the client for this configuration to take place.

NA

PackageControlFinetune1

This configuration is introduced as a generic option to fine-tune package control and resolve performance issues related to installation package.

This configuration can be configured from ePO - SaaS as client task using SC:Run Command.

For resolving slow performance issue during install when Trellix GTI is enabled, the configuration PackageControlFineTune1 bit introduced is 29 decimal equivalent 536870912.

NA

InventoryCaseSensitivity Enabled

This configuration is introduced to enable/disable case-sensitivity on inventory. After turning on case-sensitivity, cleaning inventory and re-solidification are required.

This configuration can be configured from ePO - SaaS as client task using SC:Run command.

InventoryCaseSensitivity Enabled=1 for Enabling Case sensitivity for Trellix Application and Change Control.

InventoryCaseSensitivity Enabled=0 for Disabling Case Sensitivity for Trellix Application and Change Control.

NA

PathsWritableOnlyByUpdater

Paths added under this configuration will be write protected and only updater process can do updates to this path. This is applicable for trusted directories as well.

Refer to the secure Policy Section for default values, this can be configured from ePO - SaaS as client task using SC:Run Command.

You must reboot the client for this configuration to take place.

Setting bit (14) (decimal 16384) will make the paths under PathsWritableOnlyBy Updater write-protected even if they are in trusted directory.

PackageControlCopyBinaries

This configuration prevents observation and event generation when a new msi file is created.

By default, this configuration prevents observation and event generation for three processes - explorer.exe, xcopy, and robocopy.

NA

PackageControlDisableInstallerObservations

This configuration prevents only observation generation for all processes when a new msi file is created.

To stop generating these observations, you need to set the value of this config as 1.

NA

CksumCalcMode

This configuration handles TACC checksum calculation when you create any process.

The default set value is 0.

When you set CksumCalcMode to 0, it takes checksum from MPT cache and does not calculate checksum always on process creation. If set to 1, the checksum stored in inventory compares with the calculated checksum. If there is a mismatch, TACC denies the process execution.

NA

CustomerConfig2

This configuration helps to protect the integrity of the Solidcore directory and the Solidcore install directory in all modes except Disabled mode.

CustomerConfig2=262144 setting can be configured on the system to protect Solidcore related files to be deleted or modified in all modes except Disabled mode.

CustomerConfig2 needs to be configured to 262144 (Decimal).

CustomerConfig2

This configuration can be used to fetch the attributes of the files over the network path.

CustomerConfig2=524288 setting can be configured if the user needs file attribute details for the network path getting monitored.

By default, there is an improvement in performance. If the user needs file attributes over performance, they can set CustomerConfig2=524288(Decimal)

AvoidVolumeNameExtractionWherePossible

This configuration helps in improving solidification time

We can configure AvoidVolumeNameExtractionWherePossible to improve the solidification time by optimizing the relative path extraction of files.

AvoidVolumeNameExtractionWherePossible needs to be set to 1.

IgnoreContainerIO

This configuration helps in the co-existence of Docker and TACC

The IgnoreContainerIO=1 configuration allows docker services to run with TACC enabled.

IgnoreContainerIO needs to be set to 1.

DisableCertCheck

This configuration helps to improve boot time performance by bypassing the checks on solidified binary in execution if it is Microsoft (from system 32 or wow 64) or Trellix signed. This configuration does not apply to scripts.

The default set value is 0.

When you set DisableCertCheck=1, it will not perform checks on the execution of solidified file from:

  • system 32 or wow 64 paths if it is Microsoft signed

  • any Trellix signed binary

NA

MPCompat

This configuration allows third-party applications to run in a sandbox environment.

The default set value is 1.

This configuration has three values: 0, 1, and 2. When set to 0, it deactivates the MPCompact feature. When set to 1, it applies the MPCompact feature to applications with the 'h' attribute set. When set to 2, it applies the MPCompact feature to all applications except those with the 'j' attribute set. The "sadmin attr" command is used to include or exclude a binary from MPCompat enforcement. Two new flags, "-h" and "-j," have been introduced. The "-h" flag adds a binary to the MPCompat include list, while the "-j" flag adds it to the MPCompat exclude list.

NA

DisableDeviceGuardCompat

This configuration determines whether to call LoadLibraryW from kernel32.dll or LdrLoadDll from ntdll.dll.

The default set value is 0.

When the configuration is 0, we call LoadLibraryW from kernel32.dll and do not inject any code in target process.

When the config is 1, we call LdrLoadDll in ntdll.dll and inject our code in target process.

NA

IsInvBackupEnabled

This configuration allows or blocks inventory backup on managed clients.

The default set value is 0.

When set to 1, this configuration initiates the usermode inventory backup.

NA

IsInvBootBackupEnabled

This configuration is used to back up the inventory before restarting the client.

The default set value is 0.

When set to 1, this configuration backs up the inventory before restarting the client.

NA

SoIsTidOptimizationEnabled

This configuration is used for optimizing the solidification thread (excluding Disable mode)

The default set value is 0.

A stack is called every time a file is created/executed. We can prevent this by checking if the current process is scsrvc.exe. This is done by disabling an optimization added for the initial solidification (whitelist creation) by setting this configuration to 0.

NA

CksumParallelCalcMode

This configuration enables the checksum calculation in parallel thread.

The default set value is 0.

When set to 1, this enables the feature to calculate checksum in parallel.

NA

EnableBinAllowedByCert OrChecksumToBeUpdaters

This configuration allows file execution based on a combination of certificate and updater name rule.

The default set value is 0.

When set to 1, this will enable the feature.

NA

VolumeMountRefCountDisabled

This configuration disables volume mount/unmount reference counting.

The default set value is 0.

When set to 1, this will disable the ref counting of volume reference.

NA

UnloadUnmountedVolumeDisabled

This configuration disables code unloads in inventory memory for volumes that are not present in the system. It is activated after the inventory merge.

The default set value is 0.

When set to 1, this will disable the feature.

NA

InventoryCaseSensitivityEnabled

This configuration is used to enable or disable case sensitivity on inventory. After enabling case sensitivity, cleaning inventory and re-solidification are needed.

The default set value is 0.

When set to 1, Inventory will be case-sensitive.

NA

SkipValidateFileLength

This configuration will skip the validation of file paths longer than QFILE_MAX_PATH characters, which causes file creation failures on some machines.

The default set value is 1.

When set to 0, the file length validation will be checked.

NA

IsTrustedLocalGroupEnabled

This configuration is used to enable or disable the Trusted Local Group feature.

The default set value is 1.

When set to 0, this feature will be disabled.

NA