When Application Control is running in Enabled mode, the only programs that are allowed to run are trusted and authorized. Malicious or unauthorized programs are not allowed to run.
Use the SC: Pull Inventory client task to fetch the inventory details from the endpoints before placing them in Enabled mode. This ensures that the inventory is loaded and updated in ePO - On-prem database and prevent any mismatch.
On the ePO - On-prem console, select Menu → Systems → System Tree.
Select a group or an endpoint:
Group — Go to System Tree and click the Assigned Client Tasks tab.
Specific endpoint — On the Systems tab, select the endpoint you want to work with and click Actions → Agent → Modify Tasks on a Single System.
Click Actions → New Client Task Assignment to open the Client Task Assignment Builder page.
For Product, select Solidcore 8.x.x.
For Task Type, select SC: Enable.
For Task Name, click Create New Task to open the Client Task Catalog page.
Enter the task name and add any descriptive information.
Select the platform and sub-platform, then select Application Control, Change Control, or both.
Based on the sub-platform, perform these actions, then click Save.
Windows NT/2000 — Select Reboot endpoint to restart the endpoints when solidification is complete, which enables the software.
All except NT/2000
Select the initial scan priority of the thread that creates the allow list on the endpoints:
Low — Minimal performance impact
High — Faster results
Select an option for activation
Limited Feature Activation — Endpoints aren't restarted and limited features of Application Control are activated. Memory Protection and Script As Updater (SAU) features are available only after the endpoint is restarted.
Full Feature Activation — Endpoints are restarted, allow list created, and all features including Memory Protection are active.
(Optional) Select Start Observe Mode to place the endpoints in Observe mode.
(Optional) Select Start Inventory Mode to place the endpoints in Inventory mode.
(Optional) Select Pull Inventory to manage the inventory with ePO - On-prem.
Five minutes before the endpoint is restarted, a message is displayed at the endpoint to allow the user to save important work and data.
Click Next to open the Schedule page.
Specify scheduling details, then click Next.
Review and verify the task details, then click Save.
(Optional) Wake up the agent to send your client task to the endpoint immediately.