Outline steps to enable TLS 1.2 on App Control servers so they continue to connect to the CDC and force the deprecation of all previous version of SSL and TLS to prevent downgrade attacks.
Sometimes enabling TLS 1.2 requires less-secure protocols to be disabled. However, fresh installs of SQL Server did not support TLS 1.2 until SQL Server 2014, and sometimes disabling older protocols will render it impossible for the Server or Reporter to talk to SQL Server. This article describes each version of SQL Server and how to make it capable of communicating via TLS 1.2: https://support.microsoft.com/en-us/help/3135244/tls-1-2-support-for-microsoft-sql-server
Additional Information
The Carbon Black Collective Defense Cloud (CDC), which provides file trust and threat information and allows automatic updates of certain rules, requires a TLS 1.2 connection from the CB Protection Server. If you intend to connect to the CDC, use of .NET 4.6 (or later) is recommended. Earlier versions of .NET will default to pre-TLS-1.2 protocols, and this will prevent a CDC connection unless you disable those older protocols.
Disabling older TLS/SSL protocols may be a security issue for connections to other services from your App Control Server.