Endpoint Protection

 View Only
  • 1.  Symantec Endpoint Protection and Patch Updates

    Posted Mar 04, 2015 07:40 PM

    Hi,

     

    I am currently whitelisting applications on desktops using the Symantec Endpoint Protection Manager. I take file hash of each application, add it to a fingerprint list and implement this list of hashes.

    Is there a way I can easily allow patch updates for applications? At present, all automatic updates cannot be run because that would involve installing an application with a hash that has not been registered on the whitelist. 

     

    Regards,

    Kimberley



  • 2.  RE: Symantec Endpoint Protection and Patch Updates

    Posted Mar 04, 2015 07:44 PM

    Best way to go is run system lockdown in test mode first for a couple of weeks. You can add exclusions for the Windows update directories. There will be a few different ones.

    About authorizing the use of applications, patches, and utilities



  • 3.  RE: Symantec Endpoint Protection and Patch Updates

    Posted Mar 04, 2015 07:50 PM

    Hi,

    Could you please check the link to that site? It doesn't seem to load.

     

    Thanks :)
    Kimberley

     

     



  • 4.  RE: Symantec Endpoint Protection and Patch Updates

    Posted Mar 04, 2015 08:10 PM

    Hi,

    Could you please check the link to that site? It doesn't seem to load.

    Thanks :)
    Kimberley



  • 5.  RE: Symantec Endpoint Protection and Patch Updates

    Posted Mar 04, 2015 08:11 PM

    Not sure what's going on, I can't get it to load now either.

    But in any event, you'll want to let it run in log mode so you can collect any necessary exclusions and add them accordingly:

    http://www.symantec.com/docs/HOWTO80850

    The closest I could find was for allowing SEP updates which also need to be added

    Symantec Endpoint Protection system lockdown blocks definitions updates



  • 6.  RE: Symantec Endpoint Protection and Patch Updates

    Broadcom Employee
    Posted May 06, 2015 05:50 PM

    I think this might be what you are looking for. 

     

    Automatically updating whitelists or blacklists for system lockdown

    https://support.symantec.com/en_US/article.HOWTO81094.html