Permissions needed to install or remove the DLP endpoint agent
search cancel

Permissions needed to install or remove the DLP endpoint agent

book

Article ID: 184282

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention

Issue/Introduction

If you use a tool called Avecto" https://www.avecto.com/ for privilege elevation, it stops the ability to install\uninstall DLP agents.

Resolution

In order to successfully install the endpoint agents, the proper rights are needed on the machines or the agent will either fail to install or not install correctly.
Without the proper rights, you will also face issues with agent uninstalls and stopping or starting the edpa and wdp services.
If Avecto can elevate your user privileges to the system level; such as SCCM does; it should work. 
Using SCCM to deploy endpoint agents works as it essentially elevates the user to System User