Endpoint Policies

Apply security settings in bulk to your endpoint groups.

Important:

To use this feature, you must first complete the Initial Setup wizard.

Completing Initial Setup allows you to create endpoint groups, use policy-based settings management, and access other features.

The Endpoint Policies app allows you to enable or disable XDR Endpoint Sensor and Vulnerability Assessment on large numbers of endpoints by leveraging your endpoint groups.

  1. Go to Endpoint Security Operations > Endpoint Policies.
  2. Click any available endpoint group to open the Security Agent Settings panel.

    You can create or modify endpoint groups using the Endpoint Inventory app.

    For more information, see Managing Endpoint Groups.

  3. Click the toggle switch to enable or disable XDR Endpoint Sensor.

    XDR Endpoint Sensor collects the relevant endpoint activity data necessary to detect the majority of threats occurring on an endpoint without affecting endpoint performance

    Important:

    Endpoint groups inherit policies from parent groups. If you modify any settings on a parent group, all endpoints within that parent group and endpoints within any child group apply the same settings. You must manually modify specific child group settings to override new parent group settings.

  4. Optionally change the Detection mode settings.
    • Normal: Collects the relevant endpoint activity data necessary to detect the majority of threats occurring on an endpoint without affecting endpoint performance (Recommended)

    • Hypersensitive monitoring: Collects more endpoint activity data, which may generate false positives and increase bandwidth usage on endpoints.

      Important:

      Hypersensitive monitoring is only available after an authorized user has enabled the feature on the Support Settings app and automatically switches back to Normal after 7 days.

      For more information, see Support Settings.

  5. Click the toggle switch to enable or disable Vulnerability Assessment.

    Vulnerability Assessment checks endpoints for highly-exploitable operating system and application vulnerabilities.

    Important:

    Only supported on Windows platforms.

    Not supported on non-persistent virtual desktops.

  6. Click Save to apply the settings to the endpoint group.
    Note:

    Agents apply the new settings after connecting to the server.