Important
The following configuration only applies to Windows xAgent versions 35.31.0 and above.
The Wintrust Verification policy inspects the status of the Microsoft Wintrust subsystem by validating the WINTRUST.dll binary. This ensures that Endpoint Security (HX) protects the xAgent software on your endpoints from unauthorized manipulation of WINTRUST.dll. By default, the Wintrust Verification policy is turned on (enabled) for all Windows endpoints. The policy verifies the Subject Interface Package (SIP) provider, the Trust Provider (TP), and verifies that the WINTRUST.dll itself has not been tampered with.
Though not recommended, you can disable the Wintrust Verification policy. You may want to disable this policy exclusively for host endpoints in your environment running Endpoint Security (HX) xAgent 32.x or earlier. You may also want to disable this policy if future Windows updates create subsequent issues with WINTRUST.dll validation.
Use the Endpoint Security (HX) Server Web UI or API to modify your agent default policy and disable the Wintrust Verification policy for all host endpoints in your enterprise, or to create a custom policy to enable or disable the Wintrust Verification policy for selected host sets in your environment.
This section covers how to use the Web UI to enable or disable each component of the Wintrust Verification policy. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your tamper protection policies.