Steps to troubleshoot issues with Trusted Directory Approvals.
Environment
App Control Agent: All Supported Versions
App Control Server: All Supported Versions
Resolution
Reminder: Trusted Directory approvals are not sent to Agents immediately upon activation of the directory or addition of files. There are three conditions that cause a Trusted Directory Approval to be sent to endpoints:
Blocked Files: If the Server has a record of a file being blocked on any endpoint, and that file is later approved via Trusted Directory, the Server sends the Approvals to the Agents immediately.
Execution Attempts: If a user attempts to execute an instance of a file approved by Trusted Directory on a computer connected to the Server, the Server allows the Agent to run the file immediately and sends the Approval to other Agents.
Installers: If a file approved by Trusted Directory is identified as an Installer, the Server begins sending the Approval to the Agents immediately.
Verify the details of the Trusted Directory in: Rules > Software Rules > Directories:
Computer Name should not be grey for the relevant Trusted Directory, if it is the Agent is currently Disconnected.
Path should still exist on the relevant endpoint.
Do not create multiple Trusted Directories for the same path.
Paths must have correct directory delimiters and characters for the relevant Operating System.
Case sensitivity is determined by the Operating System.
Paths should not include Removable Drives, as the drive letter may change and Removable Drives are not re-scanned when removed/re-attached.
Status should not be red (Inaccessible), if it is the Agent or folder might be deleted.
If Agent is connected, path exists, and is accessible: continue.
Click View Details on the relevant Trusted Directory.
Status should be Enabled.
Policies should match expected Policies.
Progress is an indicator of Crawl Jobs.
Each folder is a Crawl Job, and each archive is a Crawl Job.
One folder with 3 archives is 4 Crawl Jobs.
The Progress field is cumulative and the numbers do not reset.
The Progress numbers might actually increase, even if files have not been added.
From the endpoint hosting the Trusted Directory
Use a command prompt to authenticate with the Agent:
cd "C:\Program Files (x86)\Bit9\Parity Agent\" dascli password GlobalPassword
Verify the relevant file shows as Crawlable using the crawlinfo command, example:
Check for current Crawl Jobs to verify the file is not actively being Crawled:
dascli crawljobs
If the Agent is not actively crawling the relevant file, and it shows as Crawlable, an On Demand Crawl may be issued with the dascli crawlfile command, example:
Attempt to execute the file on the endpoint hosting the Trusted Directory.
If a user attempts to execute an instance of a file Approved via Trusted Directory, the Server allows the Agent to run the file immediately and sends the Approval to the other Agents.
If the issue persists, open a case with Support and provide:
Screenshot from the Console > Rules > Software Rules > Directories > relevant Trusted Directory