Deployment recommendations and guidelines

Prev Next

Follow these recommendations and guidelines to successfully deploy the software in Observe mode.

Task

Recommendation

Description

Identify and place the endpoints in Observe mode to analyze product impact on the endpoints and identify and define the needed rules.

Deployment

Identify endpoints in pilot phase.

Number of endpoints

Total number must not exceed 200, use criteria discussed under "deployment strategy".

Pre-deployment tasks

Complete these activities for your endpoints:

  • Run an on-demand scan.

  • Update applications and operating system.

  • Scan and pull applications in enterprise.

  • Run GetClean to classify the gray applications.

  • Block unwanted applications.

Place a batch in Observe mode by running the SC: Enable client task.

Pulling inventory

If a software inventory is needed by your organization, make sure to select the box within the SC:Enable client task to collect an inventory.

Verifying placement

Verifying placement runs the Application Control Agent Status query to verify that selected endpoints are placed in Observe mode.

Number of endpoints

Total number must not exceed 200, use criteria discussed under "deployment strategy". At any point, only 2 batches can run simultaneously in Observe mode.

Determining scan priority

The scan priority determines the priority of the thread that creates the allow list on the endpoints. For most scenarios, we recommend that you set the scan priority to Low.

For systems that are in the Production mode, use Low priority to make sure there is minimal impact.

Also, you must use Low priority if the system can't be restarted. If you can restart the system and you want the initial scan to be completed as soon as possible, select High priority.

Selecting activation

Wherever possible, use Full Feature Activation to make sure the highest level of security. Use Full Feature Activation if the system does not have an alternate Memory Protection mechanism, such as the one provided by antivirus or McAfee Host Intrusion Prevention software.

Perform day-to-day operations and tasks to generate corresponding requests.

Based on the requests, you can define relevant rules needed for your setup. Also, if you are using a specific tool for product updates or new deployments, use the tool in the initial two-week deployment period.

If you are aware of activities or applications that run periodically, such as monthly payroll, make sure that the deployment period includes these activities.

Review the requests received from endpoints and define relevant rules for each request to make sure that Application Control is optimally configured for your setup.

Specifying processing ownership

The ePO - SaaS administrator must process requests. Based on your setup, you might need to make sure there is collaboration between global and site administrators.

Determining frequency

  • Process requests daily and define needed rules.

  • Run reports every week to gather request trend and summary.

  • Failure to process requests regularly results in a build-up of requests that become progressively harder to manage.

Analyzing requests

Process requests received from network paths. Then, process requests for updaters and installers on priority (for Software Installation activity type). If you trust the certificate associated with a request, define certificate-based rules for the request.

Determining the action to take

You can create custom rules or approve globally based on your choice and setup. Regardless of the action, the same rule is created.

If the application is common to your setup, you can approve globally to add rules that apply to all endpoints in your enterprise. This allows for quick and simple processing. Or, create custom rules that you can add to a rule group and apply to selected endpoints.

Criteria for processing

Review each request and verify its prevalence and associated application. You can sort the view based on request prevalence. For more information, review the reputation and publisher for the application.

Running reports

Review the Top 10 Pending Policy Discovery Requests and Systems with Most Pending Requests Generated in Observe Mode monitors on the Solidcore: Health Monitoring dashboard.

User Comments

You can record additional information for each request. For example, add a similar piece of information inside User Comments field for a few requests for request identification.

Rule identification

Rules are identified for requests based on event and activity type.

Event type

Activity type

Rule type

File Write Denied

File Modification

Updater process rule

Installation Denied

Software Installation

Installers rule

NX Violation Detected

Memory Protection Violation

Exclusions rule

Process Hijack Attempted

Memory Protection Violation

Exclusions rule

VASR Violation Detected

Memory Protection Violation

Exclusions rule

Execution Denied

Software Installation

Installer rule

Execution Denied

Application Execution

Executable file rule to permit execution or allow locally to add to the allow list

File Write Denied

File Addition

Updater rule