diff --git a/docs/endpointprotector/admin/dc_module/globalsettings.md b/docs/endpointprotector/admin/dc_module/globalsettings.md index 6383835590..46e968c52c 100644 --- a/docs/endpointprotector/admin/dc_module/globalsettings.md +++ b/docs/endpointprotector/admin/dc_module/globalsettings.md @@ -883,7 +883,7 @@ Use the Debug level mode, as it contains more than error and warning type inform ![Use this feature to collect logs for a specific issue](debuglogging.webp) -### Debug Logging Usage +### Debug Logging Activation To use the debug feature and collect logs, follow these steps: @@ -935,7 +935,7 @@ logging option. Logs will be sent to the Endpoint Protector Server on the Logs Report page, Artifact Received events are registered when diagnostic data are received. -### Debug Logging Actions +### Getting Debug Logs via EPP Server To view the log actions, go to the **Device Control** module, on the **Computer**s page and click the **Actions** column. @@ -964,6 +964,42 @@ the **Actions** column. ![Forced Restart Computer - this option sends a force reboot command to the computer](forcedrestarttwo.webp) +### Getting Debug Logs locally on Endpoint + +If the EPP Client can't communicate with the Endpoint Protector Server, collect debug logs directly +on the endpoint with the diagnostic collection script instead. + +:::note +If Tamper Mode is enabled, the script only works on Windows. +::: + +#### Windows + +**Step 1 –** Run the following script from PowerShell or Command Prompt: + +`"C:\Program Files\CoSoSys\Endpoint Protector\Resources\epp_collect_dpi_info.bat"` + +**Step 2 –** Wait for the script to finish. Some steps, such as listing installed apps and +collecting console logs, can take a few minutes. Don't interrupt the script. + +**Step 3 –** Collect the generated files from the output folder the script prints at the end of the +run, for example `C:\Users\\AppData\Local\Temp\epp_logs`. + + +#### macOS + +**Step 1 –** Run the following command as root: + +- With Deep Packet Inspection (DPI) on: `sudo /Applications/EndpointProtectorClient.app/Contents/Resources/epp_collect_dpi_info_mac.sh 1` +- With DPI off: `sudo /Applications/EndpointProtectorClient.app/Contents/Resources/epp_collect_dpi_info_mac.sh` + +**Step 2 –** Enter the password when prompted. The script must run as root. + +**Step 3 –** Wait for the script to finish. Some steps, such as listing installed apps and +collecting console logs, can take a few minutes. Don't interrupt the script. + +**Step 4 –** Collect the generated files from the output folder the script prints, `/tmp/epp_logs`. + ### Data Obfuscation Rules Endpoint Protector obfuscates all data according to these rules: @@ -973,7 +1009,7 @@ Endpoint Protector obfuscates all data according to these rules: Specific use cases: -1. For credit cards, the PCI Security Standards were implemented +1. For credit cards, the PCI Security Standards were implemented with full text obfuscation 2. For SSNs, the last 4 characters are displayed 3. For Brazil ID (CPF), the first 3 and the last 2 characters are obfuscated @@ -995,6 +1031,10 @@ Endpoint Protector doesn't obfuscate file-type, file-size, and date threats. From this section you can allow EasyLock to be installed and run only on computers that have Endpoint Protector installed or in relation to a list of trusted Endpoint Protector Servers. +:::note +Before you use these settings, ensure that you configure a Master Password. See [Enforced Encryption](/docs/endpointprotector/admin/ee_module/eemodule.md) for how to configure it. +::: + ![Allow EasyLock to be installed](easylocksettings.webp) - **Endpoint Protector Client Presence Required** — When enabled, EasyLock (Enforced Encryption) runs only on computers where the Endpoint Protector (EPP) Client is installed. diff --git a/docs/endpointprotector/install/intune/addapp.webp b/docs/endpointprotector/install/intune/addapp.webp index f2176d9025..2a6dbaa1b9 100644 Binary files a/docs/endpointprotector/install/intune/addapp.webp and b/docs/endpointprotector/install/intune/addapp.webp differ diff --git a/docs/endpointprotector/install/intune/apppackagefile.webp b/docs/endpointprotector/install/intune/apppackagefile.webp index 96f36773dc..69e3d07487 100644 Binary files a/docs/endpointprotector/install/intune/apppackagefile.webp and b/docs/endpointprotector/install/intune/apppackagefile.webp differ diff --git a/docs/endpointprotector/install/intune/appsoverview.webp b/docs/endpointprotector/install/intune/appsoverview.webp index f235aeedcf..ed69f4f103 100644 Binary files a/docs/endpointprotector/install/intune/appsoverview.webp and b/docs/endpointprotector/install/intune/appsoverview.webp differ diff --git a/docs/endpointprotector/install/intune/apptype.webp b/docs/endpointprotector/install/intune/apptype.webp index 8c39082c32..b5470071ae 100644 Binary files a/docs/endpointprotector/install/intune/apptype.webp and b/docs/endpointprotector/install/intune/apptype.webp differ diff --git a/docs/endpointprotector/install/intune/assignmentspage.webp b/docs/endpointprotector/install/intune/assignmentspage.webp index 03ca0445b8..d19bbf4e13 100644 Binary files a/docs/endpointprotector/install/intune/assignmentspage.webp and b/docs/endpointprotector/install/intune/assignmentspage.webp differ diff --git a/docs/endpointprotector/install/intune/msipackage.webp b/docs/endpointprotector/install/intune/msipackage.webp deleted file mode 100644 index 898d541ed0..0000000000 Binary files a/docs/endpointprotector/install/intune/msipackage.webp and /dev/null differ diff --git a/docs/endpointprotector/install/intune/msipackagedownload.webp b/docs/endpointprotector/install/intune/msipackagedownload.webp index c67e3531d5..cbf6023bfb 100644 Binary files a/docs/endpointprotector/install/intune/msipackagedownload.webp and b/docs/endpointprotector/install/intune/msipackagedownload.webp differ diff --git a/docs/endpointprotector/install/intune/reviewpage.webp b/docs/endpointprotector/install/intune/reviewpage.webp index 634061e294..a4872291c0 100644 Binary files a/docs/endpointprotector/install/intune/reviewpage.webp and b/docs/endpointprotector/install/intune/reviewpage.webp differ diff --git a/docs/endpointprotector/install/intune/windowsdeployment.md b/docs/endpointprotector/install/intune/windowsdeployment.md index 73d4e6532a..7d7a949f77 100644 --- a/docs/endpointprotector/install/intune/windowsdeployment.md +++ b/docs/endpointprotector/install/intune/windowsdeployment.md @@ -1,6 +1,6 @@ --- -title: "Windows Deployment" -description: "Windows Deployment" +title: "Intune Windows Deployment" +description: "Microsoft Intune EPP Client Windows Deployment" sidebar_position: 10 --- @@ -15,23 +15,24 @@ Protector MSI package; ![Downloading the Windows Endpoint Protector MSI Package](msipackagedownload.webp) +:::note +`EPPClientSetup.2608.1.1.3_x86_64.msi` is an example filename. Always download and deploy the +latest available EPP Client version. +::: + :::warning When deploying the .msi package, delete the information in the brackets as -well as the underscore that precedes it - EPPClientSetup.5.6.3.1_x86_64.msi +well as the underscore that precedes it - EPPClientSetup.2608.1.1.3_x86_64.msi ::: - -![When deploying the .msi package, delete the information in the brackets as well as the underscore that precedes it - EPPClientSetup.5.6.3.1_x86_64.msi](msipackage.webp) - - -**Step 3 –** Go to the Microsoft Endpoint Manager admin center and sign in; +**Step 3 –** Go to the Microsoft Intune admin center (also known as Microsoft Endpoint Manager) and sign in; **Step 4 –** Go to Apps from the left-hand side menu, and on the Apps Overview page, select the Windows platform; ![Apps Overview Page](appsoverview.webp) -**Step 5 –** On the Windows App page, click Add, select the Line of business app type, and then +**Step 5 –** On the Windows App page, click Create, select the Line of business app type, and then click Select; ![Selecting the Line of business app type](apptype.webp) @@ -46,7 +47,7 @@ Protector MSI file and click OK; - Name – add Endpoint Protector and optional, the package version (Endpoint Protector 5.7.3.6) - Description – click Edit Description and add installation details - Publisher – add NetwrixLtd. -- Command-line argument – add the following command line in the text box +- Command-line argument – add the following command line in the text box and complete it with the required information (server IP, port): - WSIP="EPP_server_IP" WSPORT="443" /q REBOOT=ReallySuppress diff --git a/docs/endpointprotector/install/jamf/addingpackage.webp b/docs/endpointprotector/install/jamf/addingpackage.webp index 4dd5467af3..b5628005cd 100644 Binary files a/docs/endpointprotector/install/jamf/addingpackage.webp and b/docs/endpointprotector/install/jamf/addingpackage.webp differ diff --git a/docs/endpointprotector/install/jamf/configuration.md b/docs/endpointprotector/install/jamf/configuration.md index a2c880c11e..11ea3bdbd0 100644 --- a/docs/endpointprotector/install/jamf/configuration.md +++ b/docs/endpointprotector/install/jamf/configuration.md @@ -21,13 +21,12 @@ available configuration profiles, click **+New**. On the New macOS Configuration Profile section, you can manage profile settings and select the devices and users to which you want to deploy the profile. +## General Settings + :::note -Click **Save** after you have managed all settings and the profile scope. +Click **Save** only after you have managed all settings and the profile scope. ::: - -## General Settings - On the default General section, enter the following information: - Name – enter a name to use for this configuration profile. @@ -56,17 +55,20 @@ certifications. ![Enabling Deep Packet Inspection Certificate and then downloading Client CA Certificate](dpicertificate.webp) -**Step 3 –** Go to Jamf, the Certificate section, and click **Configure**. +**Step 3 –** Return to Jamf and go to the Certificate section of the profile you created earlier, +and then click **Configure**. **Step 4 –** Enter a Certificate name and then select and upload the downloaded Client CA Certificate in .cer format. +**Step 5 –** Save the changes. + ![Entering the required information on New macOS Configuration Profile](macosconfiguration.webp) ## Privacy Preferences Policy Control Settings -On the Privacy Preferences Policy Control section, click **Configure** and then enter the following -information: +Edit the profile you created earlier, go to the Privacy Preferences Policy Control section, click +**Configure**, and then enter the following information: - Identifier - `com.cososys.eppclient`. - Identifier Type – go with the default Bundle ID type. @@ -83,6 +85,12 @@ this command line. - Select the **Validate the Static Code Requirement** check-box. - Click **Add** and **Save** to allow access to SystemPolicyAllFiles and Accessibility services. +:::note +Jamf may list **Accessibility** as **(Deprecated)** in this dropdown. Apple has publicly earmarked +this service for retirement, so Jamf flags it ahead of time. You can still select it — this is an +advance notice, not a functional issue. +::: + ![Configuring Privacy Peferences Policy Control](privacypreferences.webp) ## Allow EppNotifier Settings @@ -132,6 +140,12 @@ this command line. - Click **Add** and then **Save** to allow access to SystemPolicyAllFiles and Accessibility services. +:::note +Jamf may list **Accessibility** as **(Deprecated)** in this dropdown. Apple has publicly earmarked +this service for retirement, so Jamf flags it ahead of time. You can still select it — this is an +advance notice, not a functional issue. +::: + ![Configuring Enforced Encryption settings](enforcedencryption.webp) ## System Extension Settings @@ -173,31 +187,6 @@ This setting applies starting with MacOS 12 (Monterey). ![Adding a new policy that will allow the removing of system extensions](removeableextensions.webp) -### Managed Login Items - -Administrators can quickly disable Endpoint Protector Items in Jamf Configuration Profiles with -Ventura's (macOS 13) new capability. This can be accomplished by taking the following steps: - -**Step 5 –** Log in to your Jamf account. - -**Step 6 –** Click **Computer** from the main navigation bar. - -**Step 7 –** Select **Configuration Profiles** from the sidebar menu on the left. - -**Step 8 –** Click **New** in the upper right-hand corner. - -**Step 9 –** On the left, under the Options box, select **Managed Logged In Items**. - -Disable Endpoint Protector Items in your Jamf Configuration Profiles. Uncheck the box next to the Endpoint ProtectorItems you want to disable, and then click -**Save** to save your changes. - -:::note -Disabling Endpoint Protector Items may have an impact on the security of your system. Only -disable these items if you are positive it is essential and you have taken every precaution -necessary to keep your system secure. -::: - - ## VPN Settings :::note @@ -230,7 +219,9 @@ this command line. ![First section to configuring VPN settings](vpnsettings.webp) -![Second section to configuring VPN settings](vpnconfiguration.webp) +![Second section to configuring VPN settings](vpnsettings2.webp) + +![Third section to configuring VPN settings](vpnconfiguration.webp) ## Notifications Settings @@ -248,6 +239,40 @@ On the Notifications section, click **Configure** and then enter the following i ![Optional Notifiaction Settings](notificationsettings.webp) +![Optional Notifiaction Settings continued](notificationsettings2.webp) + +## Managed Login Items + +Administrators can quickly disable Endpoint Protector Items in Jamf Configuration Profiles with +Ventura's (macOS 13) new capability. This can be accomplished by taking the following steps: + +**Step 5 –** Log in to your Jamf account. + +**Step 6 –** Click **Computer** from the main navigation bar. + +**Step 7 –** Select **Configuration Profiles** from the sidebar menu on the left. + +**Step 8 –** Click **New** in the upper right-hand corner. + +**Step 9 –** On the left, under the Options box, select **Managed Logged In Items**. + +Disable Endpoint Protector Items in your Jamf Configuration Profiles. Uncheck the box next to the Endpoint ProtectorItems you want to disable, and then click +**Save** to save your changes. + +:::note +Disabling Endpoint Protector Items may have an impact on the security of your system. Only +disable these items if you are positive it is essential and you have taken every precaution +necessary to keep your system secure. +::: + +On the Managed Login Items section, click **Configure** and then enter the following information: + +- Rule Type – select **Team Identifier**. +- Rule Value – `TV3T7A76P4`. +- Enable the **Include** toggle. + +![Configuring Managed Login Items](managedloginitems.webp) + ## Scope After you manage all settings, go to the Scope tab and select the devices and users to deploy the new profile. diff --git a/docs/endpointprotector/install/jamf/configurationprofile.webp b/docs/endpointprotector/install/jamf/configurationprofile.webp index 7c643b6e97..46cbc6474e 100644 Binary files a/docs/endpointprotector/install/jamf/configurationprofile.webp and b/docs/endpointprotector/install/jamf/configurationprofile.webp differ diff --git a/docs/endpointprotector/install/jamf/creatingpolicy.md b/docs/endpointprotector/install/jamf/creatingpolicy.md index 5f0c44c9d0..0c7359cb25 100644 --- a/docs/endpointprotector/install/jamf/creatingpolicy.md +++ b/docs/endpointprotector/install/jamf/creatingpolicy.md @@ -28,7 +28,7 @@ sidebar menu, select **Policies**, and then click **+ New**. ![Configuring Script under Policies](scripts.webp) **Step 4 –** On the Packages section, click **Configure** and then add the package -EndpointProtector.pkg. +`EndpointProtectorClient2608.2.1.3.pkg`. ![Adding the Endpoint Protector package to policy](addingpackage.webp) diff --git a/docs/endpointprotector/install/jamf/dpicertificate.webp b/docs/endpointprotector/install/jamf/dpicertificate.webp index 5f93ba6817..fd0801b1d0 100644 Binary files a/docs/endpointprotector/install/jamf/dpicertificate.webp and b/docs/endpointprotector/install/jamf/dpicertificate.webp differ diff --git a/docs/endpointprotector/install/jamf/enforcedencryption.webp b/docs/endpointprotector/install/jamf/enforcedencryption.webp index 8db62c7365..dcb960f104 100644 Binary files a/docs/endpointprotector/install/jamf/enforcedencryption.webp and b/docs/endpointprotector/install/jamf/enforcedencryption.webp differ diff --git a/docs/endpointprotector/install/jamf/generalsettings.webp b/docs/endpointprotector/install/jamf/generalsettings.webp index d58f477fbf..bc55fea973 100644 Binary files a/docs/endpointprotector/install/jamf/generalsettings.webp and b/docs/endpointprotector/install/jamf/generalsettings.webp differ diff --git a/docs/endpointprotector/install/jamf/macosconfiguration.webp b/docs/endpointprotector/install/jamf/macosconfiguration.webp index b96f29e251..39c444fe5e 100644 Binary files a/docs/endpointprotector/install/jamf/macosconfiguration.webp and b/docs/endpointprotector/install/jamf/macosconfiguration.webp differ diff --git a/docs/endpointprotector/install/jamf/managedloginitems.webp b/docs/endpointprotector/install/jamf/managedloginitems.webp new file mode 100644 index 0000000000..eefbd72b9e Binary files /dev/null and b/docs/endpointprotector/install/jamf/managedloginitems.webp differ diff --git a/docs/endpointprotector/install/jamf/newpackage.webp b/docs/endpointprotector/install/jamf/newpackage.webp index 67e8375186..f1f0ac383d 100644 Binary files a/docs/endpointprotector/install/jamf/newpackage.webp and b/docs/endpointprotector/install/jamf/newpackage.webp differ diff --git a/docs/endpointprotector/install/jamf/newpolicy.webp b/docs/endpointprotector/install/jamf/newpolicy.webp index 0a94ef0d53..161a67fe71 100644 Binary files a/docs/endpointprotector/install/jamf/newpolicy.webp and b/docs/endpointprotector/install/jamf/newpolicy.webp differ diff --git a/docs/endpointprotector/install/jamf/newscript.webp b/docs/endpointprotector/install/jamf/newscript.webp index cef1c33b5c..18f1c8bc16 100644 Binary files a/docs/endpointprotector/install/jamf/newscript.webp and b/docs/endpointprotector/install/jamf/newscript.webp differ diff --git a/docs/endpointprotector/install/jamf/notificationsettings.webp b/docs/endpointprotector/install/jamf/notificationsettings.webp index 2637c4286d..dc51d3ba17 100644 Binary files a/docs/endpointprotector/install/jamf/notificationsettings.webp and b/docs/endpointprotector/install/jamf/notificationsettings.webp differ diff --git a/docs/endpointprotector/install/jamf/notificationsettings2.webp b/docs/endpointprotector/install/jamf/notificationsettings2.webp new file mode 100644 index 0000000000..37e1511f98 Binary files /dev/null and b/docs/endpointprotector/install/jamf/notificationsettings2.webp differ diff --git a/docs/endpointprotector/install/jamf/policies.webp b/docs/endpointprotector/install/jamf/policies.webp index 022e248f64..3b23ad1d1f 100644 Binary files a/docs/endpointprotector/install/jamf/policies.webp and b/docs/endpointprotector/install/jamf/policies.webp differ diff --git a/docs/endpointprotector/install/jamf/policyscope.webp b/docs/endpointprotector/install/jamf/policyscope.webp index fb631d772b..6efb910943 100644 Binary files a/docs/endpointprotector/install/jamf/policyscope.webp and b/docs/endpointprotector/install/jamf/policyscope.webp differ diff --git a/docs/endpointprotector/install/jamf/privacypreferences.webp b/docs/endpointprotector/install/jamf/privacypreferences.webp index b4509c7031..7791549fc3 100644 Binary files a/docs/endpointprotector/install/jamf/privacypreferences.webp and b/docs/endpointprotector/install/jamf/privacypreferences.webp differ diff --git a/docs/endpointprotector/install/jamf/removeableextensions.webp b/docs/endpointprotector/install/jamf/removeableextensions.webp index 4da60160b7..b78b3d9e9e 100644 Binary files a/docs/endpointprotector/install/jamf/removeableextensions.webp and b/docs/endpointprotector/install/jamf/removeableextensions.webp differ diff --git a/docs/endpointprotector/install/jamf/scope.webp b/docs/endpointprotector/install/jamf/scope.webp index 9aff56e4c1..562808bb52 100644 Binary files a/docs/endpointprotector/install/jamf/scope.webp and b/docs/endpointprotector/install/jamf/scope.webp differ diff --git a/docs/endpointprotector/install/jamf/scriptandpackage.md b/docs/endpointprotector/install/jamf/scriptandpackage.md index 00409287d9..469a54f21d 100644 --- a/docs/endpointprotector/install/jamf/scriptandpackage.md +++ b/docs/endpointprotector/install/jamf/scriptandpackage.md @@ -6,9 +6,14 @@ sidebar_position: 20 # Uploading the Script and Package -To deploy the Endpoint Protector Client, upload the `EndpointProtector.pkg` package along with the +To deploy the Endpoint Protector Client, upload the `EndpointProtectorClient2608.2.1.3.pkg` package along with the `epp_change_ip.sh` script. +:::note +`EndpointProtectorClient2608.2.1.3.pkg` is an example filename. Always download and deploy the +latest available EPP Client version. +::: + :::warning To obtain the `epp_change_ip.sh script`, customers should submit a support ticket through the [Netwrix Customer Portal](https://www.netwrix.com/sign_in.html?rf=my_products.html). @@ -17,14 +22,13 @@ through the [Netwrix Customer Portal](https://www.netwrix.com/sign_in.html?rf=my To upload the script and package, follow these steps: -**Step 1 –** In your Jamf account, from the main navigation bar, click **Computer**, and then from -the left sidebar menu, select **Management Settings**. +**Step 1 –** In your Jamf account, from the main navigation bar, click **Settings**, and then select +**Computer Management**, then **Scripts**. -**Step 2 –** From the Computer Management section, select **Scripts** and then, in the upper right, -click **+ New**. +**Step 2 –** From the Scripts section, in the upper right, click **+ New**. **Step 3 –** On the General section, add a name for the profile, and then select the **Script tab** -and add the `epp_change_ip.sh` script. +and paste the content of the `epp_change_ip.sh` script. **Step 4 –** Add your Server IP to the EPP_SERVER_ADDRESS field. @@ -39,6 +43,6 @@ Protector Client on specific departments or custom ports. **Step 5 –** From the Computer Management section, select **Package** and then, in the upper right, click **+ New**. -**Step 6 –** On the General tab, add a name and then upload the package `EndpointProtector.pkg`. +**Step 6 –** On the General tab, add a name and then upload the package `EndpointProtectorClient2608.2.1.3.pkg`. ![Uploading the new Package](newpackage.webp) diff --git a/docs/endpointprotector/install/jamf/scripts.webp b/docs/endpointprotector/install/jamf/scripts.webp index fa3e146c2a..bf3b4dff32 100644 Binary files a/docs/endpointprotector/install/jamf/scripts.webp and b/docs/endpointprotector/install/jamf/scripts.webp differ diff --git a/docs/endpointprotector/install/jamf/systemextensions.webp b/docs/endpointprotector/install/jamf/systemextensions.webp index 6eab04f6ac..8f157cb82f 100644 Binary files a/docs/endpointprotector/install/jamf/systemextensions.webp and b/docs/endpointprotector/install/jamf/systemextensions.webp differ diff --git a/docs/endpointprotector/install/jamf/vpnconfiguration.webp b/docs/endpointprotector/install/jamf/vpnconfiguration.webp index 437d180ef0..01322f3075 100644 Binary files a/docs/endpointprotector/install/jamf/vpnconfiguration.webp and b/docs/endpointprotector/install/jamf/vpnconfiguration.webp differ diff --git a/docs/endpointprotector/install/jamf/vpnsettings.webp b/docs/endpointprotector/install/jamf/vpnsettings.webp index 7b691162de..81034f5a8f 100644 Binary files a/docs/endpointprotector/install/jamf/vpnsettings.webp and b/docs/endpointprotector/install/jamf/vpnsettings.webp differ diff --git a/docs/endpointprotector/install/jamf/vpnsettings2.webp b/docs/endpointprotector/install/jamf/vpnsettings2.webp new file mode 100644 index 0000000000..7efa59fba8 Binary files /dev/null and b/docs/endpointprotector/install/jamf/vpnsettings2.webp differ diff --git a/docs/endpointprotector/install/migrationprocedure/bestpractices.md b/docs/endpointprotector/install/migrationprocedure/bestpractices.md index 4e8265b1d2..c31a08c74a 100644 --- a/docs/endpointprotector/install/migrationprocedure/bestpractices.md +++ b/docs/endpointprotector/install/migrationprocedure/bestpractices.md @@ -49,7 +49,7 @@ The following best practices come from the complete migration workflow and apply |---|---| | 21 | Always reuse the same IP/FQDN for the new server. Changing it creates cascading certificate and Enforced Encryption (EE) trust failures. | | 22 | Fill both DNS fields only on unpatched 2509 or early 2510 environments. Patch 2604 fixed the DNS field-saving bug, so 2608 needs no workaround. | -| 23 | Disable client communications on the new server before restoring a backup to prevent partial-state registrations. | +| 23 | Block client connectivity to the new server (firewall rule, routing block, or disconnected network cable, depending on your environment) before restoring a backup, to prevent partial-state registrations. | | 24 | After migration, monitor SIEM connectivity — it may require reconfiguration and Netwrix Support may need to provide a restoration script. | ## Client Management @@ -59,7 +59,7 @@ The following best practices come from the complete migration workflow and apply | 25 | The 2608 client requires no new bridge version — any client on 5.9.4.3 Hotfix 1 or on any 2511–2605 client version can upgrade directly. If you are using the EPP Server Client Upgrade feature and still have clients on 5.9.4.1 or older, upgrade them to 5.9.4.3 Hotfix 1 first as the signature bridge before proceeding to 2608. | | 26 | Use enterprise deployment tools (Intune, SCCM, Jamf) for client upgrades rather than relying solely on EPP's built-in client upgrade feature, which limits uploads to 50 machines per hour. | | 27 | Always run a pilot deployment of 10–20 endpoints before mass client rollout. | -| 28 | For Enforced Encryption (EE) environments, upload both Windows and macOS EE clients to the server before enabling client communications — the server requires both packages regardless of which OS your endpoints use. | +| 28 | For Enforced Encryption (EE) environments, upload both Windows and macOS EE clients to the server before restoring client connectivity — the server requires both packages regardless of which OS your endpoints use. | | 29 | Update EE clients to the latest version **immediately** after migration — don't leave them on an older version the way you might stage regular EPP client rollouts. Since the **2509** release, Enforced Encryption changed its communication logic with the server, so a delayed EE client update can cause EE-protected drives to lose synchronization or fail to communicate. | | 30 | Plan client updates for off-peak hours to minimize end-user disruption. | | 31 | If a Client Upgrade task is stuck, clean up all existing Client Upgrade tasks on the EPP Server and create a new task — stale tasks can block the upgrade queue. | diff --git a/docs/endpointprotector/install/migrationprocedure/faq.md b/docs/endpointprotector/install/migrationprocedure/faq.md index 651f55fbc7..c40703d359 100644 --- a/docs/endpointprotector/install/migrationprocedure/faq.md +++ b/docs/endpointprotector/install/migrationprocedure/faq.md @@ -144,7 +144,7 @@ See also [Endpoints Not Checking In After Migration](/docs/endpointprotector/ins **Checklist:** 1. Confirm the new server's IP/FQDN is reachable from endpoints (firewall, DNS). -2. Confirm you enabled client communications on the server (**System Configuration → System Settings**). +2. Confirm you've reversed whatever mechanism you used to block client connectivity to the new server (firewall rule, routing block, disconnected network cable, and so on). 3. Confirm you uploaded the client packages to the server — 2608 (the target version), plus 5.9.4.3 Hotfix 1 only if any endpoints are still below that bridge version. 4. Check the **Device Control → Computers** page and sort by **Last Seen**. 5. If clients were on 5.9.4.1 or older and you didn't deploy 5.9.4.3 Hotfix 1 first, they can't receive the 2608 client package directly — deploy 5.9.4.3 Hotfix 1 first via your software distribution tool before upgrading to 2608. See [Client Upgrade Management](/docs/endpointprotector/install/migrationprocedure/clientupgrade) for the full client upgrade path. diff --git a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md index 50b80b50da..bee36dee81 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-current-image.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-current-image.md @@ -4,7 +4,7 @@ description: "Netwrix Endpoint Protector — migrating a 2509–2604 image-based sidebar_position: 13 --- -Document version: 1.0 +Document version: 1.1 --- @@ -232,16 +232,17 @@ If you use SSO (Single Sign-On) and choose a different IP address instead of an 4. Power on the new VM and access the console at `https://:443`. -### Temporarily Disabling Client Communications +### Blocking Client Connectivity to the New Server -Immediately after you provision the new VM and it's reachable, disable client communications before performing any further configuration. This prevents endpoints from discovering and connecting to the new server while you're still preparing it. +Immediately after you provision the new VM and it's reachable, consider blocking client connectivity to it before performing any further configuration. This prevents endpoints from discovering and connecting to the new server while you're still preparing it. -1. Log in to the new server console. -2. Navigate to **System Configuration → System Settings**. -3. Disable client communication. +How you do this depends on how you host and manage your environment. Options include: +- Disabling routing to the new server's IP address +- Disconnecting the physical or virtual network cable until you're ready +- Blocking the relevant EPP communication port at your perimeter or host-based firewall :::tip -Disabling client communications prevents endpoints from registering with an incomplete server configuration. Re-enable only after the full restoration and verification is complete. +Blocking client connectivity prevents endpoints from registering with an incomplete server configuration. Restore connectivity only after the full restoration and verification is complete. ::: ### Activate Trial License on a Newly Deployed Image @@ -310,13 +311,12 @@ Complete all items in this checklist after you finish the migration. | Server responds to browser access | `https://:443` loads normally | | License imported successfully and active | System Configuration → System Licensing | -### Re-Enabling Client Communications +### Restoring Client Connectivity After you verify the restore and upload the client packages (see [Client Upgrade Management](/docs/endpointprotector/install/migrationprocedure/clientupgrade)): -1. Navigate to **System Configuration → System Settings**. -2. Re-enable client communications. -3. Monitor **Device Control → Computers** — endpoints should begin checking in within their configured communication interval. +1. Reverse whichever method you used to block client connectivity to the new server (re-enable routing, reconnect the network cable, or remove the firewall rule). +2. Monitor **Device Control → Computers** — endpoints should begin checking in within their configured communication interval. ### Endpoint Communication Check diff --git a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md index 65c866b0d7..c00f5260c3 100644 --- a/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md +++ b/docs/endpointprotector/install/migrationprocedure/migration-legacy-5x.md @@ -4,7 +4,7 @@ description: "Netwrix Endpoint Protector — migrating a legacy 5.7.0.0–5.9.4. sidebar_position: 12 --- -Document version: 1.0 +Document version: 1.1 --- @@ -344,16 +344,17 @@ On unpatched 2509 and early 2510 environments, IP network settings didn't save u 4. Power on the new VM and access the console at `https://:443`. -### Temporarily Disabling Client Communications +### Blocking Client Connectivity to the New Server -Immediately after you provision the new VM and it's reachable, disable client communications before performing any further configuration. This prevents endpoints from discovering and connecting to the new server while you're still preparing it. +Immediately after you provision the new VM and it's reachable, consider blocking client connectivity to it before performing any further configuration. This prevents endpoints from discovering and connecting to the new server while you're still preparing it. -1. Log in to the new server console. -2. Navigate to **System Configuration → System Settings**. -3. Disable client communication. +How you do this depends on how you host and manage your environment. Options include: +- Disabling routing to the new server's IP address +- Disconnecting the physical or virtual network cable until you're ready +- Blocking the relevant EPP communication port at your perimeter or host-based firewall :::tip -Disabling client communications prevents endpoints from registering with an incomplete server configuration. Re-enable only after the full restoration and verification is complete. +Blocking client connectivity prevents endpoints from registering with an incomplete server configuration. Restore connectivity only after the full restoration and verification is complete. ::: ### Activate Trial License on a Newly Deployed Image @@ -447,13 +448,12 @@ Complete all items in this checklist after you finish the migration. ![Appliance → Server Information — license](server_info_license.webp) -### Re-Enabling Client Communications +### Restoring Client Connectivity After you verify the restore and upload the client packages (see [Client Upgrade Management](/docs/endpointprotector/install/migrationprocedure/clientupgrade)): -1. Navigate to **System Configuration → System Settings**. -2. Re-enable client communications. -3. Monitor **Device Control → Computers** — endpoints should begin checking in within their configured communication interval. +1. Reverse whichever method you used to block client connectivity to the new server (re-enable routing, reconnect the network cable, or remove the firewall rule). +2. Monitor **Device Control → Computers** — endpoints should begin checking in within their configured communication interval. ### Endpoint Communication Check diff --git a/docs/endpointprotector/install/migrationprocedure/migrationguide.md b/docs/endpointprotector/install/migrationprocedure/migrationguide.md index 97dc24cf45..1bdd391d14 100644 --- a/docs/endpointprotector/install/migrationprocedure/migrationguide.md +++ b/docs/endpointprotector/install/migrationprocedure/migrationguide.md @@ -4,7 +4,7 @@ description: "Netwrix Endpoint Protector — Server Migration & Upgrade Guide" sidebar_position: 10 --- -Document version: 3.0 +Document version: 3.1 --- @@ -57,7 +57,7 @@ flowchart TD Trial --> Restore["Restore backup onto 2608
Upload client packages
→ imports your configuration backup"] Restore --> License["Import license on the restored server
→ verify it imported successfully"] License --> Verify["Post-Migration Verification"] - Verify --> ClientUpgrade["Client Upgrade to 2608, then
re-enable client communications"] + Verify --> ClientUpgrade["Client Upgrade to 2608, then
restore client connectivity"] ClientUpgrade --> Done(["✅ Done — running on 2608"]) classDef startPoint fill:#fdebd3,stroke:#d68910,color:#7e5109 diff --git a/docs/endpointprotector/install/migrationprocedure/troubleshooting.md b/docs/endpointprotector/install/migrationprocedure/troubleshooting.md index d70154a8b1..309e18602a 100644 --- a/docs/endpointprotector/install/migrationprocedure/troubleshooting.md +++ b/docs/endpointprotector/install/migrationprocedure/troubleshooting.md @@ -225,7 +225,7 @@ If errors appear instead: **Symptom:** Endpoints show as offline; Last Seen timestamps are old. **Checklist:** -1. Verify that you have re-enabled client communications on the new server. +1. Verify that you've reversed whatever mechanism you used to block client connectivity to the new server (firewall rule, routing block, disconnected network cable, and so on). 2. Confirm the new server is reachable on the expected IP/FQDN from endpoints. 3. Check that you uploaded the 2608 client package to the server. 4. Verify the old server is no longer running on the same IP if using same-IP strategy.