Endpoint Protection Client functionality in Windows Safe Mode.
search cancel

Endpoint Protection Client functionality in Windows Safe Mode.

book

Article ID: 246930

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security

Issue/Introduction

Endpoint Protection Client functionality in Windows Safe Mode.

Environment

SEP 14.x

Cause

Endpoint Protection does not work in Windows Safe Mode. The Tamper Protection does not prevent SEP files and registry keys from being tampered.

Resolution

Windows Safe mode is a boot option in which the operating system starts in diagnostic mode rather than in normal operating mode. Safe mode is intended primarily for maintenance or troubleshooting. In this mode, the operating system loads only a minimal set of drivers and services to allow the isolation of problems causing system instability.
 
Basically safe mode restricts 3rd party services as well as drivers being loaded. Windows even does not load all of its drivers but minimal drivers to operate. 
 
Since the BASH driver is not loaded we cannot protect files or registry. This is an expected behavior and working as per the design.