Trellix Application and Change Control 8.4.0 Windows Release Notes

Prev Next

The Trellix Application and Change Control 8.4.0 release includes enhancements to features and resolved issues.

Release details

For release dates and build numbers, see KB87944.

Upgrade support

This release supports upgrading from:

  • TACC extension 8.2.x and 8.3.0–8.3.8

    When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.

  • TACC client 8.2.x and 8.3.0–8.3.7

For information about the TACC extension and client upgrade supported path, see KB87944.

New or changed

Customize client configurationTACC client configurations are now integrated with the extension, making it easy to modify these configurations by pushing them through policy changes. For details, see KB96798.

Note

Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values.

Windows major updates in Enable modeTACC 8.4.0 supports Windows major updates directly in Enable mode. You no longer need to switch the endpoint to Update mode before updating. After the Windows update is complete, proceed with resolidification. For details, see KB86551.

Rebranding changes in TACC Extension UI—Default policy names are now updated to replace McAfee Default with Trellix Default.

Rebranding changes in TACC Client UI—Event descriptions in Event Viewer are now updated to replace McAfee with Trellix.

Enhanced registry key securityTACC 8.4.0 supports enhanced integrity protection for the TACC registry key in update mode. Previously, registry entries of TACC were editable in update mode. Now, with version 8.4.0, these entries are secured against unauthorized changes in update mode. To disable integrity protection, run sadmin config set CustomerConfig=0x1229a (value is for example). By disabling this protection, users can proceed with updates as usual. For details, see KB97058.

Removed feature

In this release, we have removed some deprecated TACC UI features from Server Tasks, Queries & Reports, Policy Catalog, Dashboard, Solidcore rules, and Other tabs. For more information, see KB96942.

Known issues

For a list of current known issues, see Application Control 8.x Known Issues (KB87839) and Change Control 8.x Known Issues (KB87838).

Resolved issues

This release resolves known issues.

TACC extension

Category

Reference

Resolution

User interface

MACC-11381

Automatic Response configured to send threat events to the syslog server now runs successfully in ePO - On-prem 5.10 CU12 and above.

User interface

MACC-11394

Solidcore Inv/PD/CCT/ClientTasks event IDs now get registered on Event Filtering UI. Hence, these events can be restricted from going to the syslog server using the Event Filtering option.

TACC client

Category

Reference

Resolution

Fixes to features

MACC-11372

The files are now successfully submitted to Trellix Intelligent Sandbox for analysis using port 443.

Fixes to features

MACC-11302

TACC events now get prioritized based on the Trellix Agent forwarding time interval.

User interface

MACC-11467

Solidcore events (in XML file) now show the correct operating system information.

Fixes to features

MACC-11465

Parsed event no longer changes the original encoded values to lowercase.

Fixes to features

MACC-11865

The default list for updaters now remains the same for all versions of TACC 8.3.x.

Interoperability

MACC-12292

The Vagrant application now works as expected with TACC in enabled mode with the added configuration entries.

Performance

MACC-12397

Memory leak due to QSGa Paged & Pool Nonpaged is no longer seen.

Fixes to features

MACC-11920

TACC End User Notifications policy option now generates the correct URL to show event details.

Fixes to features

MACC-11642

Solidcore Execution Control no longer fails when the rule triggers the event.

Performance

MACC-11492

TACC application latency is not seen during login and switching between modes.