App Control: Automatically Move Computer to a Policy After Initialization
search cancel

App Control: Automatically Move Computer to a Policy After Initialization

book

Article ID: 290458

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

To setup rules that automatically move a computer from a low enforcement policy to a high enforcement policy after the initialization completes.

Environment

  • App Control Console: All Supported Versions

Resolution

  1. Create an Install policy. This is the low enforcement policy which the event rule, suggested below, will be looking for.
  2. Navigate in your console to Rules > Event Rules and add a new rule. Enter the rule settings below:
    • Name: <Enter the Name of the Rule>
    • Description: <Enter the Description>
    • Status: It is highly recommended you test this in "Simulate Only" until you've verified it will work for your current process. Then move it into "Enabled"after testing.
    • Event Properties:
    • Subtype: is Cache Check Complete
    • Policy is <Enter the name of the Install Policy you created in Step 1>
    • Filter: None
    • Action: Move Computer (If this option is greyed out, or missing see related content)

Additional Information

Warning: It is highly recommended that you test the rule using the "Simulate Only" status prior to enabling.