Review approval requests

Prev Next

Review the requests received from the endpoints.

On the Solidcore: Health Monitoring dashboard, check the Top 10 Pending Policy Discovery Requests monitor to take notice of the data that might require immediate action.

  1. On the ePO - On-prem console, select Menu Application Control Policy Discovery to open the Policy Discovery page.

    After the requests are received from the endpoints, Application Control collates and groups requests based on these parameters.

    • SHA-1 value of the executable file or .cab file (if there is a request for an ActiveX control) where the request is received.

      Note

      Although Application Control supports SHA-256 value of files, only SHA-1 values are used for collating and grouping requests on the Policy Discovery page.

    • Status of the request.

    Note

    The Activity field for each request indicates the action performed by the user on the endpoint. For example, if the user installs MSI-based software, the Activity field lists Software Installation for the request.

  2. Review the listed requests using one of these methods.

    • Specific interval — Select an option from the Time Filter list and click Update Results to view requests received in a specific interval.

    • Request status — Select a value for the request status from the Approval Status list and click Update Results to view requests that match the selected status.

    • Activity — Select a value from the Activity list and click Update Results to view requests for a certain activity.

    • Reputation — Select a value from the Final Reputation list and click Update Results to view requests for files that match the selected reputation level. For more information about how the software determines final reputation for files or certificates, click What's Final Reputation.

    • Specific endpoint — Enter an endpoint name in the System Name field and click Update Results to view requests received from the endpoint. Make sure that you specify the complete system name because no partial matches are performed.

    • Multiple criteria — Specify values for the Time Filter, Approval Status, Activity, Final Reputation, and System Name fields, as needed, and click Update Results to perform a search based on multiple criteria.

    • Specific search string — Enter a search string in the Quick find field and click Apply to view requests that match the specified search string. Partial matches are performed based on the text you specify.

      Note

      You can enter User Comments field value as a search string.

    • Sort — Sort the list based on the global prevalence, execution time, activity, object name, application name, certificate, final reputation, reputation source, or approval request by clicking the column heading.

    • Selected requests — Select requests of interest and click Show selected rows to review only the selected requests.

    Note

    The Policy Discovery page lists only the requests for which the ePO - On-prem administrator can make rules. To view other requests, such as those for software uninstall, run the Self-Approval Audit Report query. This report lists all requests received from the endpoints in the last month.

  3. Review individual requests that make up a collated request and detailed information for the file.

    1. Click a row to open the Request Details page.

    2. Review file details, such as name, version, path, parent process, files changed, and final reputation.

    3. Review the SHA-1, SHA-256, and MD5 information for the file.

    4. Click the file SHA-1 to review file details about the File Details page.

    5. Review the certificate vendor name for the file. The certificate vendor name for a file is color coded to indicate trusted (green), malicious (red), or unknown (orange) reputation.

    6. Click certificate name to view certificate details, such as issuer, certificate reputation, reputation source, public key algorithm, public key length, public key hash, certificate hash, valid from, and valid to.

    7. Review the individual requests that make up the collated request in the Enterprise Level Activity pane.

    8. Click Close.