Secure the host operating systems running ePO - On-prem and remote Agent Handlers to protect core management infrastructure from unauthorized access.
Apply updates: Install the latest Cumulative Update (CU) immediately upon release to remediate known vulnerabilities. Keeping the application up to date minimizes the impact of applicable Common Vulnerabilities and Exposures (CVEs).
Manage certificates: Replace the default self-signed console certificate with a trusted, customer-signed TLS certificate to mitigate man-in-the-middle (MITM) attacks, eliminate browser security warnings, and satisfy organizational audit standards.
For configuration steps, see SSL certificates.
Harden TLS:Restrict weak ciphers and enforce the minimum required TLS versions for ePO and SQL Server communications to guarantee data confidentiality and integrity across the network (see KB91519).
Configure endpoint security: Install Trellix Endpoint Security (ENS) on the server host. Define precise file and path exclusions for ePO processes to prevent performance degradation.
Restrict directory permissions: Grant full directory access exclusively to local Administrators and the SYSTEM account. Limit permissions for all other users to restrict unauthorized modifications while ensuring necessary operational access.
Monitor the environment: Review the ePO Audit Log daily to track administrator logins, configuration changes, and anomalous activity. To configure logging views, see Audit log and View user actions.