Hardening the ePO and Agent handler environment

Prev Next

Secure the host operating systems running ePO - On-prem and remote Agent Handlers to protect core management infrastructure from unauthorized access.

  • Apply updates: Install the latest Cumulative Update (CU) immediately upon release to remediate known vulnerabilities. Keeping the application up to date minimizes the impact of applicable Common Vulnerabilities and Exposures (CVEs).

  • Manage certificates: Replace the default self-signed console certificate with a trusted, customer-signed TLS certificate to mitigate man-in-the-middle (MITM) attacks, eliminate browser security warnings, and satisfy organizational audit standards.

    For configuration steps, see SSL certificates.

  • Harden TLS:Restrict weak ciphers and enforce the minimum required TLS versions for ePO and SQL Server communications to guarantee data confidentiality and integrity across the network (see KB91519).

  • Configure endpoint security: Install Trellix Endpoint Security (ENS) on the server host. Define precise file and path exclusions for ePO processes to prevent performance degradation.

  • Restrict directory permissions: Grant full directory access exclusively to local Administrators and the SYSTEM account. Limit permissions for all other users to restrict unauthorized modifications while ensuring necessary operational access.

  • Monitor the environment: Review the ePO Audit Log daily to track administrator logins, configuration changes, and anomalous activity. To configure logging views, see Audit log and View user actions.