Endpoint Protection

 View Only
Expand all | Collapse all

How to change from managed clietn to unmanaged

  • 1.  How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:03 AM

    I installed SEP 12.1 on a Windows 2008 Server, the server was moved in our DMZ so now I have to change the client from managed to unmanaged in order to be able to change Live Update Settings; is it possible whithout unininstalling/installing the client (I can't restart the server)?



  • 2.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:08 AM

    Solution 1: Uninstall managed SEP client, reboot and install unmanaged SEP client using install routine from Symantec DVD or ISO image.

     

    Solution 2:

    1. Logon SEPM management console, click Clients and build a new group
    2. Move the SEP client to this new group
    3. Edit the Liveupdate Settings policy, choose “create Non-Shared Policy from copy” , enter “Server Settings”, choose use a liveupdate Server.
    4. Choose Advanced Settings->check “Allow the user to manually launch liveupdate” “Allow the user to modify Liveupdate schedule” “Download Symantec Endpoint Protection product updates using a LiveUpdate server” Then click “OK “ to save
    5. Expand the Location-specific Settings, click on the “Server Control” ,change it to “Client control”. Ok to save.
    6. After a while, right click on SEP client icon and update policy.
    7. Click Start -> Run -> input command “smc -stop”
    8. Locate to “C:\Program files\Symantec\Symantec Endpoint Protection\”, use Notepad to edit the sylink.xml file, delete the content and save. Then the sylink.xml file will be a empty file.
    9. Delete the sylink.bak and sylinkex.bak file in the same folder
    10. Click Start -> Run -> input command “smc -start”

    How to change managed Symantec Endpoint Protection(SEP) client to unmanaged SEP client?

    Article:HOWTO36107 | Created: 2010-11-21 | Updated: 2011-01-31 | Article URL http://www.symantec.com/docs/HOWTO36107

     



  • 3.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:10 AM

    You can do that without doing it as unmanged, 

    create a new group in SEPM, move this client to that group

    then Go to the Client page

    Policies tab

    Under Location specific policies and settings click on Location specific settings

    Next to Client user interface control settings click on Tasks >> Edit Settings

    Click the radio button for Client control

    Now the client will have full control all options are visible. change whatever you want. Thats it.



  • 4.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:17 AM

    Our SEPM can't communicate with servers in DMZ.



  • 5.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:19 AM

    You need to open firewall port.

    http://www.symantec.com/business/support/index?page=content&id=TECH178325

    Firewall Configuration (bi-directional):

    Refer to the Management Server List assigned to the client group to determine the communications port the SEP clients will use to communicate to the SEPM. Default values are:

     

    TCP 80 (MR2 and earlier)

    TCP 8014 (MR3 and later)

    TCP 443 (secure communications)

     

     



  • 6.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 05:22 AM

    Replace the Sylink file , thats the easiest method.



  • 7.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 06:14 AM

    I can't open the firewal, DMZ server can only acces to internet, there's no way to communicate whitt SEPM. Installing the managed client was a mistake, I want only understand if is possible to unmanaged it without restart the server.



  • 8.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 06:20 AM

    Yeah, when you export as managed package it will have all the policies from SEPM. 

    That policy includes tamper protection as well which you need to disable while copying the Sylink.xml file.

    I doubt you would be able to replace the sylink. If your current Installation has only Antivirus and antispyware then you can run an umnaged client without reboot.( It might say pending file rename but that can be tricked)

    or do any policy changes on a client which is accessible to you . then transfer it on to your server

    How to Export and Import a Symantec Endpoint Protection client policy

    http://www.symantec.com/business/support/index?page=content&id=TECH190053

     



  • 9.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 06:20 AM

    You can follow above steps.

     

    How to change managed Symantec Endpoint Protection(SEP) client to unmanaged SEP client?

    Article:HOWTO36107 | Created: 2010-11-21 | Updated: 2011-01-31 | Article URL http://www.symantec.com/docs/HOWTO36107


  • 10.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 06:27 AM

    The key here is switching to Client mode as it will give the end use full control over the settings.

    Again, the recommended way by Symantec is to reinstall but if you can't do that, set to Client mode and replace the sylink with the one from the download ISO and it should take care of it.



  • 11.  RE: How to change from managed clietn to unmanaged

    Posted Nov 20, 2014 09:44 AM

    Reinstall... 

    But if you prefer to replace the sylink, ensure that the client has all the rights before you put to unmanged.



  • 12.  RE: How to change from managed clietn to unmanaged

    Posted Mar 31, 2023 10:02 AM
    Edited by UmDaMan Mar 31, 2023 11:02 AM

    I know this is a very old topic.  But for others, the easiest method to change from managed to unmanaged is to get the SyLink.xml from the install package that you received from Symantec.  The one in the folder SEP or SEPx64.  Then go to your installed folder then go into the version folder then BIN.   In the BIN folder just load SylinkDrop.exe.  Click on browse and load up the SyLink.xml then just click on Update SyLink.
    You may need to do some registry edits if the managed client had restrictions.   I would always move them to a group first that has no restrictions before doing this.  But since this person already had moved his to a DMZ that no longer has access to the manager, he may need to do some registry edits after making it unmanaged.  Hope this helps others in the future.  

    v14 RU5 and above they removed SylinkDrop.exe   you can do the following:
    smc -stop
    smc -importsylink c:\SyLink.xml   Or other location where you saved the SyLink.xml file.