Trellix Application and Change Control 8.4.2 Windows Release Notes

Prev Next

The Trellix Application and Change Control 8.4.2 release includes enhancements and resolved issues.

Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.

Rating

The rating defines the urgency for installing this update.

This release is recommended for all environments. Apply this update at the earliest convenience.

Release details

For release dates and build numbers, see KB87944.

Upgrade support

This release supports upgrading from:

  • TACC extension 8.2.x, 8.3.0–8.3.8, 8.4.0, and 8.4.1

    When you upgrade from the existing TACC extension, you must not change any existing rules and configuration until the Solidcore: Migration server task is completed. The migration task usually takes a few hours to a day, depending on the inventory data volume of your environment.

    Note

    Trellix recommends disabling General Policy enforcement before upgrading to TACC 8.4.x from any version earlier to TACC 8.4.x as it can override configuration values integrated with the extension in TACC 8.4.x to their default values. For details, see KB96798.

  • TACC client 8.2.x, 8.3.0–8.3.7, 8.4.0, and 8.4.1

For information about the TACC extension and client upgrade supported path, see KB87944.

New or changed

Approval Request Management—Denial events requested for approval from the Application and Change Control Events dialog box are now tagged with Approval Request and sent to the Policy Discovery page on the ePO - On-prem console by default. If sending requests to the Policy Discovery page fails due to the unavailability of file information or unsupported event IDs, they are sent to the preconfigured email server. A notification in the Application and Change Control Events dialog box indicates whether the approval request is sent to ePO - On-prem or the email server. With this enhancement in approval request management, a new Approval Request column is introduced on the Policy Discovery and Queries and Reports pages. The Approval Request tag groups Policy Discovery requests along with the checksum and MP violation flag. Actions for Policy Discovery requests remain unchanged. Sending denial event requests to the Policy Discovery page applies only to specific events such as write denial, execution denial, package modification prevented, NX violation, process hijacked, and network path. All other event requests are sent through the email server.

Note

Denial events generated by policy rules or reputation flow will not enter the Policy Discovery flow.

Known issues

For a list of current known issues, see Application and Change Control 8.x Known Issues (KB87839) and KB87838.

Resolved issues

This release resolves known issues.

TACC extension

Category

Reference

Resolution

User interface

MACC-13172

The Apply rule to events option remains available in SP1 Update 2 after upgrading the TACC extension to version 8.4.2.

TACC client

Category

Reference

Resolution

Interoperability

MACC-13216

The BSOD 6B no longer occurs because the Kernel Memory Leak issue is now resolved.

Interoperability

MACC-13196

TACC now blocks USB or SSD devices when a policy is created to block them.

Interoperability

MACC-11129

When MP-CASP is enabled on Application Control, Windows now boots successfully without pausing at the boot screen.

Fixes to features

MACC-11953

Renaming of directory paths is no longer permitted once the update mode has ended.