Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CP-Shark
Collaborator

Weird endpoint behaivior

Hello everyone,

I’ve found some weird behavior on our assets using a specific software (let's call it application.exe).

When a user tries to access application.exe, which is excluded in the policy assigned to the asset, it opens a prompt requesting a username and password (higher privileges).

I have tried disabling all endpoint capabilities, but the behavior remains the same. However, here is the strange part: Uninstalling the endpoint agent solves the problem, and it stays fixed even after I reinstall the agent.

I am looking for ideas on how to troubleshoot this further. How can I verify if this is a configuration drift or corruption issue rather than a direct defect in the endpoint software?


Version is E88.72 or E89.05

Cheers,
Oliver

CCES / CCSA / CCSE
0 Kudos
6 Replies
the_rock
MVP Platinum
MVP Platinum

Might be worth opening TAC case Oliver. 

Best,
Andy
0 Kudos
lluner
Advisor

@CP-Shark 

 

He tried to repair the "push operation".

(1)
the_rock
MVP Platinum
MVP Platinum

Definitely worth a try.

Best,
Andy
0 Kudos
CP-Shark
Collaborator

Tried it and no success

CCES / CCSA / CCSE
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Definitely open TAC case @CP-Shark 

Best,
Andy
0 Kudos
lluner
Advisor

@CP-Shark 

You removed the endpoint and the application still works?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events