Observe mode indicates that Application Control is running but it only monitors and logs observations. When running in Observe mode, the application doesn't prevent any execution or changes made to the endpoints. Instead, it monitors execution activities and it compares them with the local inventory and predefined rules.
Note
Observe mode is available only in a ePO - SaaS managed environment.
Observe mode also supports reputation-based execution. When you execute a file, Application Control fetches its reputation and that of all certificates associated with the file to determine whether to allow or ban the file execution. When running in Observe mode, Application Control emulates Enabled mode but only logs observations.
An observation is logged in Observe mode for actions that Application Control allows but would normally block in Enabled mode. These observations help refine policies, and the corresponding files are not automatically added to the allow list. An observation event is logged that corresponds to the action Application Control takes in Enabled mode. For example, if not authorized, the execution of Adobe Reader is prevented in Enabled mode. In Observe mode, the file is allowed to execute unless banned by a specific rule or has malicious reputation.
Observe mode offers two benefits.
It helps you develop policies and determine rules that allow applications to run in Enabled mode.
It performs a dry run for the product to run or install software without any blockages.