When you perform a clean installation and enable Application Control, you can permanently disable Script as Updater (SAU) and Memory-protection (MP) features.
Important
This initial feature configuration is available only in a clean install. If you upgrade from a previous version, the SAU feature is enabled. If after the upgrade you want to disable SAU, you must introduce the change with a policy.
On the ePO - SaaS console, select Menu → Systems → System Tree.
Select a group or an endpoint and go to Actions → Agent → Run Client Task Now.
Under Product, Select Solidcore 9.x.x.
Under Task Type, select SC: Enable.
Under Task Name, click Create New Task.
On the Run Client Task Now page:
Choose the Platform and Sub Platform.
Under Enable, select Application Control.
For Initial Feature configuration, you can select:
MP disabled
SAU disabled
Select an option for activation:
Limited Feature Activation
Full Feature Activation
(Optional) Select Start Observe Mode to place the endpoints in Observe mode.
(Optional) Select Pull Inventory to manage the inventory with ePO - SaaS.
Click Run Task Now.
Important
Disabling SAU and MP features in the Initial Feature configuration is permanent. You can’t enable them again after installation. Any change of MP or SAU status through a policy is ignored by the endpoint.