Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 43 additions & 3 deletions docs/endpointprotector/admin/dc_module/globalsettings.md
Original file line number Diff line number Diff line change
Expand Up @@ -883,7 +883,7 @@ Use the Debug level mode, as it contains more than error and warning type inform

![Use this feature to collect logs for a specific issue](debuglogging.webp)

### Debug Logging Usage
### Debug Logging Activation

To use the debug feature and collect logs, follow these steps:

Expand Down Expand Up @@ -935,7 +935,7 @@ logging option.
Logs will be sent to the Endpoint Protector Server on the Logs Report page, Artifact Received events
are registered when diagnostic data are received.

### Debug Logging Actions
### Getting Debug Logs via EPP Server

To view the log actions, go to the **Device Control** module, on the **Computer**s page and click
the **Actions** column.
Expand Down Expand Up @@ -964,6 +964,42 @@ the **Actions** column.

![Forced Restart Computer - this option sends a force reboot command to the computer](forcedrestarttwo.webp)

### Getting Debug Logs locally on Endpoint

If the EPP Client can't communicate with the Endpoint Protector Server, collect debug logs directly
on the endpoint with the diagnostic collection script instead.

:::note
If Tamper Mode is enabled, the script only works on Windows.
:::

#### Windows

**Step 1 –** Run the following script from PowerShell or Command Prompt:

`"C:\Program Files\CoSoSys\Endpoint Protector\Resources\epp_collect_dpi_info.bat"`

**Step 2 –** Wait for the script to finish. Some steps, such as listing installed apps and
collecting console logs, can take a few minutes. Don't interrupt the script.

**Step 3 –** Collect the generated files from the output folder the script prints at the end of the
run, for example `C:\Users\<username>\AppData\Local\Temp\epp_logs`.


#### macOS

**Step 1 –** Run the following command as root:

- With Deep Packet Inspection (DPI) on: `sudo /Applications/EndpointProtectorClient.app/Contents/Resources/epp_collect_dpi_info_mac.sh 1`
- With DPI off: `sudo /Applications/EndpointProtectorClient.app/Contents/Resources/epp_collect_dpi_info_mac.sh`

**Step 2 –** Enter the password when prompted. The script must run as root.

**Step 3 –** Wait for the script to finish. Some steps, such as listing installed apps and
collecting console logs, can take a few minutes. Don't interrupt the script.

**Step 4 –** Collect the generated files from the output folder the script prints, `/tmp/epp_logs`.

### Data Obfuscation Rules

Endpoint Protector obfuscates all data according to these rules:
Expand All @@ -973,7 +1009,7 @@ Endpoint Protector obfuscates all data according to these rules:

Specific use cases:

1. For credit cards, the PCI Security Standards were implemented
1. For credit cards, the PCI Security Standards were implemented with full text obfuscation
2. For SSNs, the last 4 characters are displayed
3. For Brazil ID (CPF), the first 3 and the last 2 characters are obfuscated

Expand All @@ -995,6 +1031,10 @@ Endpoint Protector doesn't obfuscate file-type, file-size, and date threats.
From this section you can allow EasyLock to be installed and run only on computers that have
Endpoint Protector installed or in relation to a list of trusted Endpoint Protector Servers.

:::note
Before you use these settings, ensure that you configure a Master Password. See [Enforced Encryption](/docs/endpointprotector/admin/ee_module/eemodule.md) for how to configure it.
:::

![Allow EasyLock to be installed](easylocksettings.webp)

- **Endpoint Protector Client Presence Required** — When enabled, EasyLock (Enforced Encryption) runs only on computers where the Endpoint Protector (EPP) Client is installed.
Expand Down
Binary file modified docs/endpointprotector/install/intune/addapp.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/intune/apppackagefile.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/intune/appsoverview.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/intune/apptype.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/intune/assignmentspage.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file not shown.
Binary file modified docs/endpointprotector/install/intune/msipackagedownload.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/intune/reviewpage.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
21 changes: 11 additions & 10 deletions docs/endpointprotector/install/intune/windowsdeployment.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
title: "Windows Deployment"
description: "Windows Deployment"
title: "Intune Windows Deployment"
description: "Microsoft Intune EPP Client Windows Deployment"
sidebar_position: 10
---

Expand All @@ -15,23 +15,24 @@ Protector MSI package;

![Downloading the Windows Endpoint Protector MSI Package](msipackagedownload.webp)

:::note
`EPPClientSetup.2608.1.1.3_x86_64.msi` is an example filename. Always download and deploy the
latest available EPP Client version.
:::

:::warning
When deploying the .msi package, delete the information in the brackets as
well as the underscore that precedes it - EPPClientSetup.5.6.3.1_x86_64.msi
well as the underscore that precedes it - EPPClientSetup.2608.1.1.3_x86_64.msi
:::


![When deploying the .msi package, delete the information in the brackets as well as the underscore that precedes it - EPPClientSetup.5.6.3.1_x86_64.msi](msipackage.webp)


**Step 3 –** Go to the Microsoft Endpoint Manager admin center and sign in;
**Step 3 –** Go to the Microsoft Intune admin center (also known as Microsoft Endpoint Manager) and sign in;

**Step 4 –** Go to Apps from the left-hand side menu, and on the Apps Overview page, select the
Windows platform;

![Apps Overview Page](appsoverview.webp)

**Step 5 –** On the Windows App page, click Add, select the Line of business app type, and then
**Step 5 –** On the Windows App page, click Create, select the Line of business app type, and then
click Select;

![Selecting the Line of business app type](apptype.webp)
Expand All @@ -46,7 +47,7 @@ Protector MSI file and click OK;
- Name – add Endpoint Protector and optional, the package version (Endpoint Protector 5.7.3.6)
- Description – click Edit Description and add installation details
- Publisher – add NetwrixLtd.
- Command-line argument – add the following command line in the text box
- Command-line argument – add the following command line in the text box and complete it with the required information (server IP, port):

- WSIP="EPP_server_IP" WSPORT="443" /q REBOOT=ReallySuppress

Expand Down
Binary file modified docs/endpointprotector/install/jamf/addingpackage.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
91 changes: 58 additions & 33 deletions docs/endpointprotector/install/jamf/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,13 +21,12 @@ available configuration profiles, click **+New**.
On the New macOS Configuration Profile section, you can manage profile settings and select the
devices and users to which you want to deploy the profile.

## General Settings

:::note
Click **Save** after you have managed all settings and the profile scope.
Click **Save** only after you have managed all settings and the profile scope.
:::


## General Settings

On the default General section, enter the following information:

- Name – enter a name to use for this configuration profile.
Expand Down Expand Up @@ -56,17 +55,20 @@ certifications.

![Enabling Deep Packet Inspection Certificate and then downloading Client CA Certificate](dpicertificate.webp)

**Step 3 –** Go to Jamf, the Certificate section, and click **Configure**.
**Step 3 –** Return to Jamf and go to the Certificate section of the profile you created earlier,
and then click **Configure**.

**Step 4 –** Enter a Certificate name and then select and upload the downloaded Client CA
Certificate in .cer format.

**Step 5 –** Save the changes.

![Entering the required information on New macOS Configuration Profile](macosconfiguration.webp)

## Privacy Preferences Policy Control Settings

On the Privacy Preferences Policy Control section, click **Configure** and then enter the following
information:
Edit the profile you created earlier, go to the Privacy Preferences Policy Control section, click
**Configure**, and then enter the following information:

- Identifier - `com.cososys.eppclient`.
- Identifier Type – go with the default Bundle ID type.
Expand All @@ -83,6 +85,12 @@ this command line.
- Select the **Validate the Static Code Requirement** check-box.
- Click **Add** and **Save** to allow access to SystemPolicyAllFiles and Accessibility services.

:::note
Jamf may list **Accessibility** as **(Deprecated)** in this dropdown. Apple has publicly earmarked
this service for retirement, so Jamf flags it ahead of time. You can still select it — this is an
advance notice, not a functional issue.
:::

![Configuring Privacy Peferences Policy Control](privacypreferences.webp)

## Allow EppNotifier Settings
Expand Down Expand Up @@ -132,6 +140,12 @@ this command line.
- Click **Add** and then **Save** to allow access to SystemPolicyAllFiles and Accessibility
services.

:::note
Jamf may list **Accessibility** as **(Deprecated)** in this dropdown. Apple has publicly earmarked
this service for retirement, so Jamf flags it ahead of time. You can still select it — this is an
advance notice, not a functional issue.
:::

![Configuring Enforced Encryption settings](enforcedencryption.webp)

## System Extension Settings
Expand Down Expand Up @@ -173,31 +187,6 @@ This setting applies starting with MacOS 12 (Monterey).

![Adding a new policy that will allow the removing of system extensions](removeableextensions.webp)

### Managed Login Items

Administrators can quickly disable Endpoint Protector Items in Jamf Configuration Profiles with
Ventura's (macOS 13) new capability. This can be accomplished by taking the following steps:

**Step 5 –** Log in to your Jamf account.

**Step 6 –** Click **Computer** from the main navigation bar.

**Step 7 –** Select **Configuration Profiles** from the sidebar menu on the left.

**Step 8 –** Click **New** in the upper right-hand corner.

**Step 9 –** On the left, under the Options box, select **Managed Logged In Items**.

Disable Endpoint Protector Items in your Jamf Configuration Profiles. Uncheck the box next to the Endpoint ProtectorItems you want to disable, and then click
**Save** to save your changes.

:::note
Disabling Endpoint Protector Items may have an impact on the security of your system. Only
disable these items if you are positive it is essential and you have taken every precaution
necessary to keep your system secure.
:::


## VPN Settings

:::note
Expand Down Expand Up @@ -230,7 +219,9 @@ this command line.

![First section to configuring VPN settings](vpnsettings.webp)

![Second section to configuring VPN settings](vpnconfiguration.webp)
![Second section to configuring VPN settings](vpnsettings2.webp)

![Third section to configuring VPN settings](vpnconfiguration.webp)

## Notifications Settings

Expand All @@ -248,6 +239,40 @@ On the Notifications section, click **Configure** and then enter the following i

![Optional Notifiaction Settings](notificationsettings.webp)

![Optional Notifiaction Settings continued](notificationsettings2.webp)

## Managed Login Items

Administrators can quickly disable Endpoint Protector Items in Jamf Configuration Profiles with
Ventura's (macOS 13) new capability. This can be accomplished by taking the following steps:

**Step 5 –** Log in to your Jamf account.

**Step 6 –** Click **Computer** from the main navigation bar.

**Step 7 –** Select **Configuration Profiles** from the sidebar menu on the left.

**Step 8 –** Click **New** in the upper right-hand corner.

**Step 9 –** On the left, under the Options box, select **Managed Logged In Items**.

Disable Endpoint Protector Items in your Jamf Configuration Profiles. Uncheck the box next to the Endpoint ProtectorItems you want to disable, and then click
**Save** to save your changes.

:::note
Disabling Endpoint Protector Items may have an impact on the security of your system. Only
disable these items if you are positive it is essential and you have taken every precaution
necessary to keep your system secure.
:::

On the Managed Login Items section, click **Configure** and then enter the following information:

- Rule Type – select **Team Identifier**.
- Rule Value – `TV3T7A76P4`.
- Enable the **Include** toggle.

![Configuring Managed Login Items](managedloginitems.webp)

## Scope

After you manage all settings, go to the Scope tab and select the devices and users to deploy the new profile.
Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2 changes: 1 addition & 1 deletion docs/endpointprotector/install/jamf/creatingpolicy.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ sidebar menu, select **Policies**, and then click **+ New**.
![Configuring Script under Policies](scripts.webp)

**Step 4 –** On the Packages section, click **Configure** and then add the package
EndpointProtector.pkg.
`EndpointProtectorClient2608.2.1.3.pkg`.

![Adding the Endpoint Protector package to policy](addingpackage.webp)

Expand Down
Binary file modified docs/endpointprotector/install/jamf/dpicertificate.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/enforcedencryption.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/generalsettings.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/macosconfiguration.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/newpackage.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/newpolicy.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/newscript.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/policies.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/policyscope.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/privacypreferences.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/removeableextensions.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/endpointprotector/install/jamf/scope.webp
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
18 changes: 11 additions & 7 deletions docs/endpointprotector/install/jamf/scriptandpackage.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,14 @@ sidebar_position: 20

# Uploading the Script and Package

To deploy the Endpoint Protector Client, upload the `EndpointProtector.pkg` package along with the
To deploy the Endpoint Protector Client, upload the `EndpointProtectorClient2608.2.1.3.pkg` package along with the
`epp_change_ip.sh` script.

:::note
`EndpointProtectorClient2608.2.1.3.pkg` is an example filename. Always download and deploy the
latest available EPP Client version.
:::

:::warning
To obtain the `epp_change_ip.sh script`, customers should submit a support ticket
through the [Netwrix Customer Portal](https://www.netwrix.com/sign_in.html?rf=my_products.html).
Expand All @@ -17,14 +22,13 @@ through the [Netwrix Customer Portal](https://www.netwrix.com/sign_in.html?rf=my

To upload the script and package, follow these steps:

**Step 1 –** In your Jamf account, from the main navigation bar, click **Computer**, and then from
the left sidebar menu, select **Management Settings**.
**Step 1 –** In your Jamf account, from the main navigation bar, click **Settings**, and then select
**Computer Management**, then **Scripts**.

**Step 2 –** From the Computer Management section, select **Scripts** and then, in the upper right,
click **+ New**.
**Step 2 –** From the Scripts section, in the upper right, click **+ New**.

**Step 3 –** On the General section, add a name for the profile, and then select the **Script tab**
and add the `epp_change_ip.sh` script.
and paste the content of the `epp_change_ip.sh` script.

**Step 4 –** Add your Server IP to the EPP_SERVER_ADDRESS field.

Expand All @@ -39,6 +43,6 @@ Protector Client on specific departments or custom ports.
**Step 5 –** From the Computer Management section, select **Package** and then, in the upper right,
click **+ New**.

**Step 6 –** On the General tab, add a name and then upload the package `EndpointProtector.pkg`.
**Step 6 –** On the General tab, add a name and then upload the package `EndpointProtectorClient2608.2.1.3.pkg`.

![Uploading the new Package](newpackage.webp)
Binary file modified docs/endpointprotector/install/jamf/scripts.webp
Binary file modified docs/endpointprotector/install/jamf/systemextensions.webp
Binary file modified docs/endpointprotector/install/jamf/vpnconfiguration.webp
Binary file modified docs/endpointprotector/install/jamf/vpnsettings.webp
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ The following best practices come from the complete migration workflow and apply
|---|---|
| 21 | Always reuse the same IP/FQDN for the new server. Changing it creates cascading certificate and Enforced Encryption (EE) trust failures. |
| 22 | Fill both DNS fields only on unpatched 2509 or early 2510 environments. Patch 2604 fixed the DNS field-saving bug, so 2608 needs no workaround. |
| 23 | Disable client communications on the new server before restoring a backup to prevent partial-state registrations. |
| 23 | Block client connectivity to the new server (firewall rule, routing block, or disconnected network cable, depending on your environment) before restoring a backup, to prevent partial-state registrations. |
| 24 | After migration, monitor SIEM connectivity — it may require reconfiguration and Netwrix Support may need to provide a restoration script. |

## Client Management
Expand All @@ -59,7 +59,7 @@ The following best practices come from the complete migration workflow and apply
| 25 | The 2608 client requires no new bridge version — any client on 5.9.4.3 Hotfix 1 or on any 2511–2605 client version can upgrade directly. If you are using the EPP Server Client Upgrade feature and still have clients on 5.9.4.1 or older, upgrade them to 5.9.4.3 Hotfix 1 first as the signature bridge before proceeding to 2608. |
| 26 | Use enterprise deployment tools (Intune, SCCM, Jamf) for client upgrades rather than relying solely on EPP's built-in client upgrade feature, which limits uploads to 50 machines per hour. |
| 27 | Always run a pilot deployment of 10–20 endpoints before mass client rollout. |
| 28 | For Enforced Encryption (EE) environments, upload both Windows and macOS EE clients to the server before enabling client communications — the server requires both packages regardless of which OS your endpoints use. |
| 28 | For Enforced Encryption (EE) environments, upload both Windows and macOS EE clients to the server before restoring client connectivity — the server requires both packages regardless of which OS your endpoints use. |
| 29 | Update EE clients to the latest version **immediately** after migration — don't leave them on an older version the way you might stage regular EPP client rollouts. Since the **2509** release, Enforced Encryption changed its communication logic with the server, so a delayed EE client update can cause EE-protected drives to lose synchronization or fail to communicate. |
| 30 | Plan client updates for off-peak hours to minimize end-user disruption. |
| 31 | If a Client Upgrade task is stuck, clean up all existing Client Upgrade tasks on the EPP Server and create a new task — stale tasks can block the upgrade queue. |
Expand Down
2 changes: 1 addition & 1 deletion docs/endpointprotector/install/migrationprocedure/faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -144,7 +144,7 @@ See also [Endpoints Not Checking In After Migration](/docs/endpointprotector/ins

**Checklist:**
1. Confirm the new server's IP/FQDN is reachable from endpoints (firewall, DNS).
2. Confirm you enabled client communications on the server (**System Configuration → System Settings**).
2. Confirm you've reversed whatever mechanism you used to block client connectivity to the new server (firewall rule, routing block, disconnected network cable, and so on).
3. Confirm you uploaded the client packages to the server — 2608 (the target version), plus 5.9.4.3 Hotfix 1 only if any endpoints are still below that bridge version.
4. Check the **Device Control → Computers** page and sort by **Last Seen**.
5. If clients were on 5.9.4.1 or older and you didn't deploy 5.9.4.3 Hotfix 1 first, they can't receive the 2608 client package directly — deploy 5.9.4.3 Hotfix 1 first via your software distribution tool before upgrading to 2608. See [Client Upgrade Management](/docs/endpointprotector/install/migrationprocedure/clientupgrade) for the full client upgrade path.
Expand Down
Loading