Application Control Status showing Disabled/Malfunctioning
search cancel

Application Control Status showing Disabled/Malfunctioning

book

Article ID: 452411

calendar_today

Updated On:

Products

Endpoint Security Complete Endpoint Security

Issue/Introduction

Client is receiving the policy updates, however the Application Control feature fails to initialize correctly and endpoints are displaying a status of Disabled/Malfunctioning (Application Control) on Symantec Endpoint Security Console (SESC).

Environment

14.3 RU9 Symantec Endpoint Security (SES)

Cause

The issue is typically caused by an outdated or incompatible ASR (Attack Surface Reduction) engine component. In specific scenarios.
The existing AppHardening.dll version 1.5.12 fails to initialize correctly within the protected environment, leading to the "Disabled / malfunctioning" status despite successful policy updates.

Resolution

To resolve this issue, the ASR engine must be updated to a supported, functional version.

  • Verify the ASR Engine Version: Ensure the endpoint is attempting to load a compatible version of the AppHardening.dll.
  • Update the ASR Engine: Update the AppHardening.dll to version 1.5.1.33 or higher (or the latest version provided by Broadcom Support for your specific environment).
  • Deployment:
    Place the updated AppHardening.dll 1.5.1.33 in the appropriate EAS (Early Adopter System) location.
    Ensure the agent has received the updated component from the management console.
  • Verification:
    Restart the endpoint or the Symantec Endpoint Protection service to force a reload of the ASR engine.
    Verify that the Application Control status within the console returns to "Enabled" or "Active."
    Check the Windows System and Application logs to confirm no further Code Integrity or initialization errors for the AppHardening.dll 1.5.1.33 module.