Environment
- App Control Agent: All Versions
- Linux: All Supported Versions
Symptoms
After applying OS patches, Upgrade Status column in Assets > Computers screen reports machine(s) as 'Unprotected'.
Cause
Agents were not moved to a 'Disabled' Enforcement Policy before applying OS patch.
Resolution
- Open the Console > Assets > Computers page
- Select the check-box under the Action column for the effected machine(s)
- Open the Action drop-down menu
- Select a disabled Policy listed under 'Move Computers to policy ' listed, then OK
- Perform steps for applying OS patch
- Move agent(s) back to original enforcement policy
Additional Notes
- Moving agent back to original enforcement policy will cause the agent to re-initialize
- The App Control Linux agent is very kernel specific, therefore when applying a patch to the Linux OS it is strongly suggested to move the agent to a disabled enforcement policy prior to applying the patch, this suggestion is discussed on Pg 6 of the Release Notes: Cb Protection Linux Agent v7.2.4 -- Release Notes