Enabling Tamper Protection for selected host sets

Prev Next

If you disable Tamper Protection on all of your Windows endpoints but need to enable protection on selected hosts in your environment, you can create a custom policy that applies to the selected host sets only. This custom policy will prevent your system administrators from stopping or restarting the agent services and protect the xAgent process from injection and inspection on the selected host sets only.

To prevent the stop and restart of xAgent services on selected host sets:

Note

NOTE: See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

Important

When the Tamper Protection policy is enabled for selected host sets only through a custom policy, only Windows endpoints running Endpoint Security (HX) xAgentAgent version 29 or later will prevent the stop and restart of agent services on the selected host sets.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click link for the custom policy you want to modify.

  4. Click the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Deny local admin permission to Start and Stop to ON.

  6. Click Save to save the policy settings.

To protect the agent process from injection and inspection on selected host sets:

Important

When the Tamper Protection policy is enabled for selected host sets only through a custom policy, only Windows endpoints running Endpoint Security (HX) Agent version 20 or later will protect the agent process from injection and inspection on the selected host sets.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click link for the custom policy you want to modify.

  4. Click the Tamper Protection tab.

  5. Toggle the ON/OFF switch to ON.

  6. Click Save to save the policy settings.

To prevent unauthorized users and processes from tampering with agent files and folders:

Important

When the Tamper Protection policy is enabled through the Agent Default Policy, only Windows endpoints running Endpoint Security (HX) xAgent version 33 or later will prevent unauthorized users from tampering with files and folders.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click link for the custom policy you want to modify.

  4. Click the Tamper Protection tab.

  5. Toggle the ON/OFF switch to next to Prevent unauthorized users and processes from tampering with Trellix agent files and folders to ON.

  6. Click Save to save the policy settings.

After creating your custom policy, you can assign host sets and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

To enable strict certificate validation of xAgent files:

Important

The default value for this setting is ON. However, if you have previously turned strict certificate validation off, you can use these steps to turn it back on. Only endpoints running Endpoint Security (HX) xAgent version 34 or later can enable or disable strict certificate signing.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Perform strict certificate validation on agent binaries to ON.

  6. Click Save to save the policy settings.