Disabled Capabilities of XDR on instaallation

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Disabled Capabilities of XDR on instaallation

L1 Bithead

Hi all,

 

in one of our customers with the installation of XDR agent version 8.5 the Response Capabilities (File Retrieval, Live Terminal, Script Execution) were disabled from the very beginning on many of the endpoints. As there is no other way, the agents were uninstalled and reinstalled as a solution. But we could not identify the main reason. Eventhough they did not change anything on the installation process they dont have the problem with the new installation now.

 

What could the reason be? Has anyone experienced sth similar?

 

Thanks in advance for your answers. 

2 REPLIES 2

L4 Transporter

Hello @AbdBgc 

 

Thanks for reaching out on LiveCommunity!

There are two ways to disable these XDR capabilities. One is by setting specific flags in msiexec command line during installation. Second is from XDR tenant, by going to specific endpoint in all endpoints then right click -> Endpoint control -> Disable capabilities. 

If flags were not set during installation then someone must have disabled capabilities from XDR tenant. You can monitor this activity in management audit logs with type "Response" and sub type "disable capability".

 

Please click Accept as Solution to acknowledge that the answer to your question has been provided.

L1 Bithead

Hi @nsinghvirk ,

 

thanks for your reply. The ways to disable and monitor the capabilities are clear.

 

The problem is they were not disabled during or after the installation. "After" is confirmed once more over the Audit Logs. For "During" the customer says they have not disabled it during installation using any flags or so.

 

Thats why I asked if anyone else has experienced sth similar.

  • 391 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!