Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vincent_tx
Participant

Stop Endpoint Agent Script

Hello Everyone,

I have an on-prem system with 1 virtual Management Server (R81.10), and some 10K connected Windows machines running on E88.50. I need a script to stop/disable (start/re-enable) the Endpoint agent.

How can I make this mission possible?

Thanks,

 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Not sure this is possible with Endpoint Management, particularly on the versions listed.
You should be able to stop/restart the relevant services on the client possibly using a remote scripting tool. 

jorgeluiznim
Advisor

Hi @vincent_tx ,

I looked into this for a similar need, and the short answer has a catch worth sharing.

There is no documented way to start or stop the Endpoint agent itself from the management. The documentation does not provide a management action that stops the client processes on the machines.

What does exist in the management is a feature called Disable Capabilities, under Client Settings. The important part: it does not stop anything on its own. It only enables the Edit Capabilities option on the client, so that the user (or you, locally on the machine) can turn protections off from the client UI. In that policy you choose which capabilities can be disabled, set a timeout in minutes after which they are automatically re-enabled, and optionally require a password. So it is a permission plus a time window, not a remote stop. This password and timeout behavior is available from client E88.30 onward, so your E88.50 fleet has it.

The reason you cannot simply script sc stop or taskkill against the services is Self-Protection (Tamper Protection). It is designed exactly to prevent the agent from being stopped or killed, so a plain service-stop script will not work while it is active.

As far as I can tell, there is no management option to force-stop the agent at scale. When the processes really need to be stopped, for example during troubleshooting with Check Point to check whether a specific blade is interfering with a genuine Windows/OS service, that is done through a dedicated Check Point tool for this purpose, and it also requires the disable/uninstall password to stop the services on Windows.

Given all that, my suggestion is to open a TAC case describing exactly what you want to achieve, so they confirm the right path:

  • If it is temporary suspension for maintenance, Disable Capabilities with a timeout and a password is the supported route, and it scales through computer groups.
  • If you truly need to stop the services (troubleshooting a blade against an OS service), TAC can point you to the proper tool and the password requirement.
  • If the goal is removal, that is the uninstall path using the uninstall password (central Uninstall push operation, or MSI with UNINST_PASSWORD).

Hope this helps.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events