To allow your system administrators to stop and restart agent services or turn off xAgent process injection and inspection protection on all of your Windows endpoints, you can disable the Tamper Protection policy by modifying the agent default policy in the Web UI.
Important
: Trellix does not recommend disabling your Tamper Protection policy because it may allow users with administrative rights, threat actors, and malware to compromise your endpoint protection.
To allow the stop and restart of agent services on all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Tamper Protection tab.
Toggle the ON/OFF switch next to Deny local admin permission to Start and Stop to OFF.
Click Save to save the policy settings.
To allow agent process injection and inspection on all host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Tamper Protection tab.
Toggle the ON/OFF switch next to Protect the agent process from injection and inspection to OFF.
Click Save to save the policy settings.
To stop preventing unauthorized users and processes from tampering with agent files and folders:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Tamper Protection tab.
Toggle the ON/OFF switch next to Prevent unauthorized users and processes from tampering with Trellix agent files and folders to OFF.
Click Save to save the policy settings.
To disable strict certificate validation of Agent files:
Important
The default value for this setting is ON. However, if you are experiencing PKI failure in your environment, you can use these steps to turn strict certificate validation offn. Only endpoints running Endpoint Security (HX) xAgent version 34 or later can enable or disable strict certificate signing.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.
Select the Tamper Protection tab.
Toggle the ON/OFF switch next to Perform strict certificate validation on agent binaries to OFF.
Click Save to save the policy settings.