After installation, we recommend placing selected endpoints in Observe mode to perform a test run for the Application Control product.
Select at least one endpoint for each type you have in your environment. Use one of these client tasks to place the endpoints in Observe mode.
SC: Enable — Use this client task to place the endpoints in Observe mode after fresh installation of Application Control.
SC: Observe Mode — Use this client task to place the existing endpoints (running in Enabled mode) in Observe mode.
On the ePO - On-prem console, select Menu → Systems → System Tree.
Perform one of these actions.
Group — Select the group in the System Tree and click the Assigned Client Tasks tab.
Endpoint — Select the endpoint on the Systems page and click Actions → Agent → Modify Tasks on a Single System.
Click Actions → New Client Task Assignment to open the Client Task Assignment Builder page.
Select Solidcore 8.x.x → SC: Enable, then click Create New Task to open the Client Task Catalog page.
Specify the task name and add any descriptive information.
Select Windows for the platform, All except NT/2000 for the subplatform, then select Application Control.
Specify the scan priority.
The set scan priority determines the priority of the thread that is run to create the allow list on the endpoints. We recommend setting the scan priority to Low. This makes sure that Application Control causes minimal performance impact on the endpoints but might take longer (than when you set the priority to High) to create the allow list.
Specify the activation option.
Limited Feature Activation — Endpoints are not restarted, allow list created, and limited features of Application Control are activated. Memory protection and Script As Updater (SAU) features are available only after the endpoint is restarted.
Full Feature Activation — Endpoints are restarted, allow list created, and all features of Application Control including memory protection are active. Restarting the endpoints is needed to enable the memory protection features. The endpoint is restarted 5 minutes after the client task is received at the endpoint. A pop-up message is displayed on the endpoint before the endpoint is restarted.
Select Start Observe Mode.
(Optional) Select Pull Inventory.
If you select this option, the inventory (including the created allow list) is sent to ePO - On-prem. Select this option because inventory information is used in multiple workflows available from ePO - On-prem.
Click Save.
Click Next to open the Schedule page.
Specify scheduling details, then click Next.
Review and verify the task details, then click Save.
(Optional) Wake up the agent to send your client task to the endpoint immediately.