A localized space to talk about EPM, specifically for Windows And Mac OS's.
Recently active
Good morning. We don’t allow the use of mail.app on our enterprise devices so we’ve put a block on it. No big deal - it was working exactly how we intended. Now, however, after upgrading to Sequoia, we’re seeing MailCacheDelete.appexauto-launching to delete the cache and EPM is seeing mail.app being opened, causing a block. While this, generally, isn’t bad, it does cause a bad user experience. Now, the user gets, seemingly, random blocks for mail.app when they didn’t even launch it.I’d like to block and suppress the message for just this deletion process. I’d also like to have it continue to provide a blocked message when a user tries to open it manually.Any thoughts on how best to accomplish this? Sample logs:com.beyondtrust.endpointsecurity: [com.beyondtrust.endpointsecurity:EndpointSecurity] Blocking 23252 /System/Applications/Mail.app/Contents/PlugIns/MailCacheDelete.appex/Contents/MacOS/MailCacheDelete2025-01-06 13:53:50.286695-0600 0x699701 Default 0x0
I’m interested in auditing certain software and/or commands using EPM, but if I create an audit rule with an application that matches what I’m looking for high in my Workstyle hierarchy, rules that would match lower down will not fire, and if I create it low in the hierarchy the inverse is true. I understand that this is pretty foundational behavior for EPM, but I feel like i’m missing something simple here, or it’s just not possible. It seems like if i want this data, whether it be simply for visibility, or for measuring expected impact of a planned change, I could do one of the following…LOG ALL THE THINGS!!! Update all of my rules to raise a local even and report events, then filter what I want in my SIEM. The downside is that this would be expensive, and result in a lot of noise in the EPM console. Not really an option. Duplicate Groups and Rules!!! Create duplicate “logging” application groups + rules with raise a local event and report events enabled for any rules we aren’t alre
The following articles were published last week. New Knowledge Base Articles: KB0021898 - EPM-W and BITS transfer - How to allow installation KB0021899 - How to block users from accessing Users & Groups with EPM-M KB0021900 - EPM-M and third party system extensions KB0021923 - Elevation Method or Authorization Method column missing in exported Analytics csv file KB0021937 - EPM-W block message replaced by Windows 11 message - This app has been blocked by your system administrator
How to Block Delete from /Applications in MAC? how to allow Install specific apps in /Applications in MAC?Is there a common configuration for all versions of MAC, as we see its behaving different on every version of MAC.
Starting to use PM Cloud now and looking to see if it is possible to update group assignment using a local scripting job. We used to do this before with stopping services, changing some registry keys, and starting services. This is helpful if we want group membership to change dynamically based on something that might not be in AD.
Hi,Is their any alternative for the port 445 to manage discovery scans for asset in BI-EPM.
Hi Team, "We have configured a policy in EPM-MAC to block the installation of unknown applications. However, when attempting to install an unknown application, the block action does not prevent standard users from proceeding with the installation. When we configure the policy to either 'Allow' or 'Request EPM Message,' it functions as expected, based on the action set (Allow/Request). The issue appears only for the 'Block' action within the application rule, as it is not being enforced properly."Is their any suggestions why it is happening with the policy?
Has anyone implemented a solution that changes the Challenge Response “key” on a frequent basis (Ideally daily). We have CyberArk, so theoretically could store in their vault but looking to see what options might be available.
For EPM Windows, is there any way to remove the policy on endpoint agent.I want the turn them into first no policy “monitoring” state in certain conditions. thinking about changing the smart rule. I gave empty smart rule to the machine but latest policy on it remains there.Can I do it on smart rules or something without and rdp? Or I always need to delete the xml under Program Data?
The following articles were published last week. New Knowledge Base Articles: KB0021855 - EPM-W installation fails with error 1603 on Windows 24H2 ARM devices
Hello,What is the best way to apply specific rule(s) to a group of users e.g. a team wants to have yes/no message for elevation for certain commands run in CMD. (others will have Password prompt). I see I can create a new workstyle and assign to AD based user group, but there is a possibility of many such requests and I will end up creating 50-100 workstyles. Alternatively, I can use the SG as designated user group in Password (authentication) Message, but I want yes/no prompt which doesn’t have designated user option.
if a user is in high-flex, ia user can access the users & groups and then turn themselves into a local admin. we’re going to block this access by doing the following but I was wondering if there was a better way?Remove from (Recommended) Restricted Functions: Type: System Preference pane; Filename: *; Auth Request URI: system.preferences.accounts Remove from (Recommended) Restricted Functions: Type: System Preference pane; Filename: /System/Library/ExtensionKit/Extensions/UsersGroups.appex; Auth Request URI: * Add to Blocked - Blocked Apps: Type: System Preference pane; Filename: *; Auth Request URI: system.preferences.accounts Add to Blocked - Blocked Apps: Type: System Preference pane; Filename: /System/Library/ExtensionKit/Extensions/UsersGroups.appex; Auth Request URI: *
The following articles were published last week. New Knowledge Base Articles: KB0021840 - How to add and use a local AD connector in EPM Cloud KB0021847 - EPM-W client failing to install "Error 2738. Could not access VBScript run time for custom action" KB0021852 - EPM with SentinelOne on Windows 11 24H2 - Looping install popups KB0021855 - EPM-W installation fails with error 1603 on Windows 24H2 ARM devices KB0021862 - How to upgrade EPM-W on-prem (BI, GPO etc.)
Hi All,I am trying to get more details on how EPM handles the privileges ( there are few helpful KB articles. Thanks BT team).Q.1 How the agent assigns elevated token? Is there a local admin user created by EPM or the defendpoint service assigns the elevated tokens to processes when requested.Q.2 How the OS log ( and SIEM log monitoring will be affected) . In Widows Event Viewer I see two additional events per elevated action e.g. if I run an installer that needs elevated right I see1. ID 4688 The standard user account as subject who ran installer with elevated token. I also see two additional EPM events -2. ID 4688 - Create process “PGMessageHostExt.exe” by creator “ DefendpointService.exe”3. ID 4733 Primary token assigned by DefendpointService.exe to the installer service. Token has standard user.I think event number 1 stays as is (with EPM / without EPM while user is local admin)Q3. How AV scanning is affected. As AV typically works at kernel level will it get priority in hooki
has anyone gotten the new pmw 24.7 arm64 client installed? the same method weve been using to install pmw x64 msi results in 1603 error. thanks.
Hi All, Any Admins out there have users using Visual Studio 2022 connecting to Github Repos while on EPM? Did you guys have to do anything different to get it to work?
A few things not mentioned in the release notes of the latest EPM Client:It might have been a mix of QuickStart Policy "flaws" or a EPM Client "bug" still unknown to me.However, I have seen a few customers out there that I have been working with who have had benefit from this.If you are running the EPM Client above 24.5.361 you can ignore this.From around EPM Client 21.x 22.x, a change happened in the EPM Client that made it look at the content of our application groups differently. It caused the EPM Client to miss reporting vital data of applications when launching. For example, a PowerShell script (*.PS1) would show reporting for powershell.exe and a command line containing the script_name.ps1. This prevents us from creating a rule for the PowerShell script that the EPM Client supports, as the metadata is for PowerShell and not the PowerShell script. This was also true for *.bat, *.com, *.vbs, and *.msi files, all of which would report the main process exe file associated with the la
The following articles were published last week. New Knowledge Base Articles: KB0021821 - PMR Database error - The database collation cannot be changed if a schema-bound object depends on it KB0021822 - Local passwords not rotating after upgrade to Endpoint Privilege Management for Mac 24.5.3 KB0021825 - Is it possible to filter by local AD workgroups in WPE? KB0021826 - EPM Cloud JIT Admin Access information and walkthrough
Hi Team, We are unable to run the CaptureConfig tool without entering administrative credentials.When launching the tool on the user's system, it opens successfully; however, upon execution, an EPM message prompt appears, and requesting the entry of admin credentials.To clarify, the user does have administrative privileges, yet the tool still requires admin credentials to run.
Hi team,Is it possible to change the default SQL port to a customized port in the BeyondInsight configuration tool.
Hi Team, The EPM agent was installed manually on the endpoints using the Jamf file. The EPM console has now been upgraded to the latest Build Version 24.7, but the agents installed on the endpoints are still on the older version. If we want to upgrade the agents on all endpoints using the package manager, do we need to remove the existing agents installed manually through the Jamf file, or will the package manager upgrade and replace them automatically when we push the new package to the endpoints? Product: Endpoint Privilege management -Mac
I am curious if anyone else in the community has attempted to leverage PowerShell to bulk create xml files for application group items based on results from exporting analytics?I have recently began working towards setting up my organization with a test policy to provide more restrictive settings and exceptions and currently trying to do these in bulk through web policy editor is not very fun. I know there are likely enhancements coming in this regard, but without a tentative release date I have a mountain of work ahead of myself as the sole individual administering the application for an organization.This got me thinking more along the lines of bulk creation to import the settings into the PMC policy leveraging PowerShell and CSV exports from analytics. Reason I bring this up, I have over 150k unique applications from 26k publishers that will eventually be in the policy in various high, medium, low, block process, with leveraging JIT as a means for unknown applications pumped through
The following articles were published last week. New Knowledge Base Articles: KB0021792 - Wrong application type displayed in EPM reports
I am interested to learn how other customers are elevating cmd.exe / PowerShell.exe to allow developers to install/test applications.
Hi,Unable to install and run the CaptureConfig Tool on the macOS endpoint. To Clarify :Added the Privilege Management application group to the policy, and the CaptureConfig app definition has been created within that group, but we still cannot install the CaptureConfig Tool on the macOS endpoint.The Capture Config tool was downloaded from PMC console. To clarify, the PMC console has been upgraded to the latest build version(24.7) and we are currently downloading the latest version of the Capture Config tool.(24.7.0.1) However, the agent still shows an old version of EPM(23.7.1.1) As observed this issue is on the mac OS version 15.0 who has upgraded OS with Sonoma to sequin The version of macOS installed on this endpoint is: macOS 15.0
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.