IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: How to disable Endpoint Standard Reporting & Enforcement with Policy Rules

Endpoint Standard: How to disable Endpoint Standard Reporting & Enforcement with Policy Rules

Environment

  • Endpoint Standard (was CB Defense): All Versions

Objective

How to disable Endpoint Standard with Policy Rules

Resolution

At this time Endpoint Standard cannot be fully disabled using the default Policy settings available. However, as a workaround Endpoint Standard Enforcement & Reporting can be partially disabled using Policy Rules with a few exceptions and caveats. See Additional Notes for details.
  1. Log into the Carbon Black Console
  2. Go to Enforce > Policies > Prevention Tab
  3. Select Add Application Path
  4. Enter Application(s) at path: 
**
  1. Select OPERATION ATTEMPT "Performs any operation"
  2. Select ACTION "Bypass"
  3. Select the Confirm button
  4. Select Save (top or bottom of the page)

Additional Notes

  • This KB will be updated when official support for disabling Endpoint Standard at the policy level is available.
  • If a standalone double wildcard, ** , is used, the sensor is still active, but (defense) Endpoint Standard policy enforcement is disabled and the sensor will not report events.
  • Disabling Endpoint Standard using standalone double wildcard can have some unintentional side effects. i.e. Background Scan Completes without scanning bypassed files and never runs again
  • The sensor will continue to perform signature pack updates, scan for malicious services, evaluate dynamic rules, enforce tamper protection and Enterprise EDR dynamic rules will continue to report events since those rules aren't enforced by Endpoint Standard policies
  • Some Core Prevention rules can only be disabled using API bypass and other Core Prevention rules will continue to be evaluated and enforced regardless of bypass policy rules

Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎01-04-2022
Views:
1090
Contributors