App Control: Agents Going Into Default Policy
book
Article ID: 288372
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Agents are being found in the "Default" policy, as opposed to their intended policy
Environment
- App Control Agent: All Supported Versions
- App Control Console: All Supported Versions
Cause
- AD Mapping enabled
- Original policy has been deleted or renamed
- Event Rule enabled
Resolution
AD Mappings:
- Login to the App Control Console
- Navigate to Rules > Policies > Mappings tab
- Confirm if proper mapping exist for device in question
Policy Deleted or Renamed:
- Obtain the agent installation logs
- In the logs search for "Host Group"
- "Host Group obtained from branding" indicates the name of the policy the agent is looking for
- Login to the App Control console
- Navigate to Rules > Polices
- Confirm policy exists/has not been renamed
Event Rule:
- Login to the App Control Console
- Navigate to Rules > Event Rules
- Determine if any rules with Action "Move Computer" are in use/at play
Additional Information
- Agent installation logs can generally be found in c:ProgramData\Bit9\Parity Agent\Logs\
- The URL https://<EnterServerNameHere/testrules.php may be useful in testing AD Mappings
Feedback
thumb_up
Yes
thumb_down
No