Follow these recommendations and guidelines to successfully deploy the software in Observe mode.
Task | Recommendation | Description | ||
|---|---|---|---|---|
Identify and place the endpoints in Observe mode to analyze product impact on the endpoints and identify and define the needed rules. | Deployment | Identify endpoints in pilot phase. | ||
Number of endpoints | Total number must not exceed 200, use criteria discussed under "deployment strategy". | |||
Pre-deployment tasks | Complete these activities for your endpoints:
| |||
Place a batch in Observe mode by running the SC: Enable client task. | Pulling inventory | If a software inventory is needed by your organization, make sure to select the box within the SC:Enable client task to collect an inventory. | ||
Verifying placement | Verifying placement runs the Application Control Agent Status query to verify that selected endpoints are placed in Observe mode. | |||
Number of endpoints | Total number must not exceed 200, use criteria discussed under "deployment strategy". At any point, only 2 batches can run simultaneously in Observe mode. | |||
Determining scan priority | The scan priority determines the priority of the thread that creates the allow list on the endpoints. For most scenarios, we recommend that you set the scan priority to Low. For systems that are in the Production mode, use Low priority to make sure there is minimal impact. Also, you must use Low priority if the system can't be restarted. If you can restart the system and you want the initial scan to be completed as soon as possible, select High priority. | |||
Selecting activation | Wherever possible, use Full Feature Activation to make sure the highest level of security. Use Full Feature Activation if the system does not have an alternate Memory Protection mechanism, such as the one provided by antivirus or McAfee Host Intrusion Prevention software. | |||
Perform day-to-day operations and tasks to generate corresponding requests. | Based on the requests, you can define relevant rules needed for your setup. Also, if you are using a specific tool for product updates or new deployments, use the tool in the initial two-week deployment period. If you are aware of activities or applications that run periodically, such as monthly payroll, make sure that the deployment period includes these activities. | |||
Review the requests received from endpoints and define relevant rules for each request to make sure that Application Control is optimally configured for your setup. | Specifying processing ownership | The ePO - On-prem administrator must process requests. Based on your setup, you might need to make sure there is collaboration between global and site administrators. | ||
Determining frequency |
| |||
Analyzing requests | Process requests received from network paths. Then, process requests for updaters and installers on priority (for Software Installation activity type). If you trust the certificate associated with a request, define certificate-based rules for the request. | |||
Determining the action to take | You can create custom rules or approve globally based on your choice and setup. Regardless of the action, the same rule is created. If the application is common to your setup, you can approve globally to add rules that apply to all endpoints in your enterprise. This allows for quick and simple processing. Or, create custom rules that you can add to a rule group and apply to selected endpoints. | |||
Criteria for processing | Review each request and verify its prevalence and associated application. You can sort the view based on request prevalence. For more information, review the reputation and publisher for the application. | |||
Running reports | Review the Top 10 Pending Policy Discovery Requests and Systems with Most Pending Requests Generated in Observe Mode monitors on the Solidcore: Health Monitoring dashboard. | |||
User Comments | You can record additional information for each request. For example, add a similar piece of information inside User Comments field for a few requests for request identification. | |||
Rule identification | Rules are identified for requests based on event and activity type. | |||
Event type | Activity type | Rule type | ||
File Write Denied | File Modification | Updater process rule | ||
Installation Denied | Software Installation | Installers rule | ||
ActiveX Installation Prevented | ActiveX Installation | Certificates rule | ||
NX Violation Detected | Memory Protection Violation | Exclusions rule | ||
Process Hijack Attempted | Memory Protection Violation | Exclusions rule | ||
VASR Violation Detected | Memory Protection Violation | Exclusions rule | ||
Execution Denied | Software Installation | Installer rule | ||
Execution Denied | Application Execution | Executable file rule to permit execution or allow locally to add to the allow list | ||
File Write Denied | File Addition | Updater rule | ||