Automatically Restore a Computer from Local Approval to Normal Enforcement Policy
book
Article ID: 290538
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Carbon Black App Control
Issue/Introduction
For agents that are in the Local Approval Policy, create an Event Rule that automatically restores them back to normal enforcement level.
Environment
- App Control Console: All Supported Versions
Resolution
- Edit the built-in "Local Approval Alert" under Tools > Alerts
- Configure the maximum time period an agent is allowed to stay in Local Approval (e.g. 1 hour).
- Configure the Reset After to a very small interval (e.g. 1 minute), so that the alert triggers multiple times for multiple agents in Local Approval
- Enable and Save it
- Create an Event Rule under Rules > Event Rules > Create Rule
- Rule Name: Restore Computer To Normal Enforcement
- Description: Restores computer to normal enforcement level
- Status: Enabled
- Add Event Properties:
- Subtype is: Alert Triggered
- Policy is: Local Approval Policy
- Action: Move computer
- Target: Restore to normal enforcement level
- Save it
Feedback
thumb_up
Yes
thumb_down
No