<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Users disabling GP through services.msc in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321078#M82188</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We run always-on VPN. Our users have found they can disable GP by going to services.msc and disabling the service, then killing GP from task manager.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Especially with everyone working from home at the moment this is quite a big deal and we need to find a way to prevent them from stopping the GP service (some kind of tamper protection similar to what Traps/XDR or other AV products have).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on how we can stop this behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
    <pubDate>Mon, 06 Apr 2020 23:32:39 GMT</pubDate>
    <dc:creator>SARowe_NZ</dc:creator>
    <dc:date>2020-04-06T23:32:39Z</dc:date>
    <item>
      <title>Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321078#M82188</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We run always-on VPN. Our users have found they can disable GP by going to services.msc and disabling the service, then killing GP from task manager.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Especially with everyone working from home at the moment this is quite a big deal and we need to find a way to prevent them from stopping the GP service (some kind of tamper protection similar to what Traps/XDR or other AV products have).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on how we can stop this behaviour?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 23:32:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321078#M82188</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2020-04-06T23:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321091#M82190</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With 5.1 GlobalProtect App, as an admin, you can set Disable Option to Not Allow on Dynamic App Config on the firewall to prevent users from disabling GlobalProtect. Or you can also set a time limit after which GlobalProtect tries to connect back to the portal / gateway. You can find more information here:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-user-guide/globalprotect-app-for-windows/disable-the-globalprotect-app-for-windows.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/5-1/globalprotect-app-user-guide/globalprotect-app-for-windows/disable-the-globalprotect-app-for-windows.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 00:48:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321091#M82190</guid>
      <dc:creator>vathreya</dc:creator>
      <dc:date>2020-04-07T00:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321093#M82192</link>
      <description>&lt;P&gt;We also a new GP Space and would encourage you to post there moving forward &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/GlobalProtect/ct-p/GlobalProtect" target="_blank"&gt;https://live.paloaltonetworks.com/t5/GlobalProtect/ct-p/GlobalProtect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 00:49:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321093#M82192</guid>
      <dc:creator>vathreya</dc:creator>
      <dc:date>2020-04-07T00:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321095#M82193</link>
      <description>&lt;P&gt;Thanks Varun,&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;With 5.1 GlobalProtect App, as an admin, you can set Disable Option to Not Allow on Dynamic App Config on the firewall to prevent users from disabling GlobalProtect."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will that also prevent users from stopping the actual GP service? We already have it configured to stop users from disabling it through the GP App, and that works, but they have found they can simply go into services.msc and disable the service, then kill the GP app through task manager. This effectively allows them to completely turn off GP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The only difference there is we are currently using agent version 4.1.x not 5.1.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 00:58:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/321095#M82193</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2020-04-07T00:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322043#M82398</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58478"&gt;@SARowe_NZ&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not think that there is a standard option (I did not find any at least) that would allow you to prevent users from disabling PanGPS service using the method you mentioned.&lt;/P&gt;&lt;P data-unlink="true"&gt;I would propose you to enable User Account Control&amp;nbsp;and to use domain/local Windows Group Policy settings&amp;nbsp;to disable an access to Windows administrator's tools like 'services.msc' for standard users. It is also possible to prevent&amp;nbsp;IT admins to stop particular service too. Search for 'group policy prevent user to stop service' to find how to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 01:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322043#M82398</guid>
      <dc:creator>DanilaKh</dc:creator>
      <dc:date>2020-04-10T01:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322380#M82469</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58478"&gt;@SARowe_NZ&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA GP settings can not control the actions taken under services.msc on end system. Best way is to make restriction on the endpoints through Windows Group policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Sun, 12 Apr 2020 13:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322380#M82469</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-04-12T13:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322533#M82489</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;I also found this article:&amp;nbsp;&lt;A href="http://michlstechblog.info/blog/windows-set-permissions-on-a-service/" target="_blank"&gt;http://michlstechblog.info/blog/windows-set-permissions-on-a-service/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This will resolve the issue but need to find a way to deploy it easily (eg via GPO). I will take a bit more detailed look at your suggestions as suspect a combination will provide the answer.&lt;/P&gt;&lt;P&gt;Surprised PAN don't have tamper protection enabled natively, like is available in Traps.&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Shannon&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2020 20:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/322533#M82489</guid>
      <dc:creator>SARowe_NZ</dc:creator>
      <dc:date>2020-04-13T20:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Users disabling GP through services.msc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/378673#M89501</link>
      <description>&lt;P&gt;I am very surprised too!&lt;/P&gt;&lt;P&gt;Tamper protection must be a basic feature for any endpoint products such as AVs and VPN clients. Remember, we are doing all this VPN connection to make sure that we have full control over internet traffic and policies. If a user can easily stop the service and GP process the goal is not achieved even if it is for a few minutes.&lt;/P&gt;&lt;P&gt;I do understand that if a user does not have admin rights this becomes difficult or impossible to do but again, there should be a built in function for GP service for tamper protection regardless of whether or not the end users have admin rights!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2021 18:49:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-disabling-gp-through-services-msc/m-p/378673#M89501</guid>
      <dc:creator>Shahin.A</dc:creator>
      <dc:date>2021-01-08T18:49:34Z</dc:date>
    </item>
  </channel>
</rss>

