This article explains how to manage the EPP agents you have installed on your endpoints.
After you have installed agents in your environment, you may need to take actions on endpoints for the day-to-day management of your EPP solution.
You can review the protected endpoints in your environment, and if necessary, take various actions to manage the EPP. Agents perform one action at a time, you can choose to terminate an action any time and after 7 days if an action is not taken it expires.
Some of the actions you can trigger in the CMA to take on an endpoint are:
-
Full System Scan (for more information, see Configuring Endpoint Protection)
-
Uninstall Agent
-
Remove the agent from an endpoint
-
Restore from quarantine (for more information, see Monitoring and Responding to Endpoint Protection Threats)
-
Upload Logs/Reinstall Drivers (for more information, see Installing the Endpoint Protection Solution)
If necessary, you can also manually upgrade the agent on an endpoint.
After registering Endpoints with your Agent Token, the solution starts reporting data in real time, for example:
-
The version used on each endpoint
-
The profile applied to each endpoint
To review protected endpoints:
-
From the navigation menu, click Access > Protected Endpoints.
The Protected Endpoints screen opens.
The following table is an explanation of the columns in the Protected Endpoints table.
Column |
Explanation |
---|---|
Endpoint ID |
Unique ID of the EEP agent. |
Endpoint Name |
Computer name of the endpoint. |
User |
Last user to log into the endpoint. On shared devices, the user may change over time. |
IP |
IP address of the endpoint. |
OS Version |
Endpoint operating system. |
EPP Version |
Version of the EPP solution installed on the Endpoint. |
Profile |
EPP profile assigned to the Endpoint. The clock symbol displayed in this column means the Endpoint has not yet received the EPP profile. The EPP profile is assigned the next time the endpoint is online. |
Quarantine Files |
Number of quarantined files on the endpoint. |
Status |
Status of the EPP solution. The possible statuses are:
|
You can export the contents of the Protected Endpoints Table to a CSV file to align with an MDM and make sure all of the relevant endpoints appear in the table.
Cato's EPP has Anti-Tampering protection enabled by default. This protects the processes, files, services, and registries used by the EPP solution from malicious modifications or kill attempts. This also protects against unintentional enduser actions that might compromise security.
You can temporarily unlock the Anti-Tamping protection for 15 minutes, for example, if you need to uninstall the solution. After this time, or if the endpoint is rebooted, Anti-Tampering protection is reenabled.
If EPP is no longer required on an endpoint, it can be uninstalled and, if necessary, deleted from your account. After the solution is uninstalled, the EPP engines cannot scan for malicious activity and no Events are reported. The endpoint remains on the Protected Endpoint table until it is deleted.
You can uninstall EPP from an endpoint and delete the endpoint from your account in a single action.
Note
Note: Supported from EPP Agent v1.1. If you try to delete and uninstall EPP Agent v1.0, no action is taken until the Agent is upgraded to v1.1.
To uninstall and Delete an Endpoint:
-
From the navigation menu, click Access > Protected Endpoints.
The Protected Endpoints screen is displayed.
-
Click on the three dots (
) on the endpoint that you are deleting.
-
Click Remove Endpoint.
The Remover Endpoint dialog box is displayed.
-
Click Remove Endpoint & Uninstall Agent.
EPP is uninstalled from the endpoint and the endpoint is deleted from your account.
You can uninstall EPP on an endpoint so that the EPP engines cannot scan for malicious activity and no Events are reported. Until the endpoint is deleted, it is visible on the Protected Endpoint table.
To uninstall an endpoint:
-
From the navigation menu, click Access > Protected Endpoints.
The Protected Endpoints screen is displayed.
-
Click on the three dots (
) on the endpoint that you are uninstalling.
-
Click Uninstall Agent.
The Uninstall Agent dialog box is displayed.
-
Click Uninstall Agent.
EPP is uninstalled from the endpoint.
If EPP is no longer installed on an endpoint, the endpoint can be deleted from the Protected Endpoint table.
Note
Note: Do not delete an endpoint from the Protected Endpoint table before EPP has been uninstalled.
To delete an endpoint:
-
From the navigation menu, click Access > Protected Endpoints.
The Protected Endpoints screen is displayed.
-
Click on the three dots (
) on the endpoint that you are deleting.
-
Click Remove Endpoint.
The Remove Endpoint dialog box is displayed.
-
Click Remove Endpoint.
The endpoint is deleted from the Protected Endpoints screen.
After an action is created, you can terminate it at any time.
You can view the near real-time status and history of actions sent to the EPP agent. The EPP agent sends an update on the status of an action it has received every 30 seconds.
Note
Note: Actions can be reviewed from agent version 1.2 and higher.
To review endpoint actions:
-
From the navigation menu, click Access > Protected Endpoints.
-
Click the Actions History tab.
The following describes the Actions History table.
Column |
Explanation |
---|---|
Action ID |
Unique reference of the action. |
Endpoint ID |
Unique ID of the EPP agent. |
Created On |
Time stamp of when the action was created. |
Endpoint Name |
Computer name of the endpoint. |
Action |
Action taken on the endpoint. |
Status |
The near real-time status of the action. Possible statuses are:
|
Details |
Additional information about the action. |
Last Update Time |
Time stamp of the last time an update on the action was received. |
Created By |
The admin that created the action. |
Endpoint Status |
The status of the endpoint. |
When a new agent version is released, agents in your account are automatically gradually upgraded to the latest version. For various reasons, you may need to manually upgrade an agent.
To upgrade an agent manually:
-
Disable Anti-Tamper on the endpoint:
-
In the CMA, from the navigation menu, click Access > Client Rollout and download the EPP agent.
-
Distribute the agent with an MDM or install manually on an endpoint.
Note:
-
If you disabled Anti-Tamper from the CMA, you must distribute the agent within 15 minutes of disabling Anti-Tamper
-
If you disabled Anti-Tamper with a file, delete the file after the upgrade is complete
-
0 comments
Article is closed for comments.