Excluding host sets from the removal protection policy

Prev Next

By default, removal protection is turned off (disabled) for all of your host endpoints. If you enable this feature for all of your host endpoints by modifying the xAgent but want to disable it for one or more host sets, you can create a custom exclusion policy using the Web UI or the API. A custom exclusion policy will exclude assigned host sets from your default removal protection policy.

This section covers how to use the Web UI to create a custom policy that excludes host sets from removal protection. See the Endpoint Security (HX) REST API Guide for information on using the API to manage your removal protection policies.

To exclude selected host sets from the removal protection policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Click Create Custom Policy to go to the Create Policy page.

  4. Enter a policy name in the Name field and a policy description in the Description field.

    UI_Policy_Custom_Create.png
  5. Click Categories to access a list of the policy categories.

    UI_Policy_Category_Select.png
  6. Select the Removal Protection checkbox and click Apply.

  7. Toggle the Removal Protection switch OFF to completely disable this feature.

    Policy_RemovalProtection_Exclude.png
  8. Click Save.

After you create a custom policy that disables removal protection, you can use the steps outlined in Assigning Host Sets to Agent Policies to assign specific host sets to your custom policy. This will disable removal protection for all of the selected host sets.