Prisma Access HIP object Windows patch management

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Prisma Access HIP object Windows patch management

L0 Member

We have created a HIP profile and configured windows patch management. However, the options under this is not very clear. I have to get some clarifications on this

Missing Patches - Severity

    1. When the operator is set to Greater Than or Equal To, what values are valid in the field?
    2. We currently use 3, assuming this represents Critical Windows security patches. Please clarify whether this is correct and what the other values represent.
    3. What do each of the three options in the Check drop-down mean?
    4. How does each option behave when the Item Table is populated or left empty?
      Enforcement outcome
    1. If the HIP profile is attached to a deny security policy, which combinations would block a Windows endpoint with missing Critical security patches?
    2. What other useful enforcement outcomes can be achieved through different combinations of these settings?

      GlobalProtect Prisma Access 
1 REPLY 1

Community Team Member

Hi @K.Herath ,

 

The patch severity values are:

 

0 = Low

1 = Moderate

2 = Important

3 = Critical.

 

So your current setting of Greater Than or Equal To 3 is correct if you want the HIP object to match endpoints with missing Critical patches.

 

The Check options evaluate the missing patches reported by the endpoint:

has-any: Matches when the endpoint is missing any patch that meets the configured criteria.

has-none: Matches when none of the configured patch entries are reported as missing.

has-all: Matches when all configured patch entries are reported as missing.

 

When the Item Table is populated, the Check selection is evaluated against the patches entered in that table, together with the configured severity.

 

When the Item Table is empty, the severity becomes the primary condition. For example:

 

Severity: Greater Than or Equal To 3

Check: has-any

Item Table: empty

 

This should match a Windows endpoint reporting at least one missing Critical patch.

 

To block those endpoints, add the HIP object to a HIP profile and reference that profile in a deny security policy above the applicable allow rule.

I would recommend validating the behavior first using the endpoint’s HIP report and the HIP Match logs before applying the deny rule broadly.

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 82 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!