cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Identity Agent - disable exiting for existing agents

I've configured the global properties such that nac_agent_disable_quit has been enabled, however agents that are already deployed are able to exit the agent still. New deploys are correctly receiving this setting.

What have people done to ensure this setting is changed for agents that are already deployed?

Thanks

0 Kudos
5 Replies

Re: Identity Agent - disable exiting for existing agents

Hi David,

You've got a good one there. I am thinking that this may be a bug. As I can't find official documentation that suggests that is normal behaviour. 

I'd get a TAC case raised to investigate further. 

Just out of interest are the existing clients running the latest version of the identity agent? Or an older one?

Regards

Mark

0 Kudos

Re: Identity Agent - disable exiting for existing agents

Hi Mark,

I'll get one open and see what their recommendation is. 

we have our clients running on the latest version, R80.174

0 Kudos

Re: Identity Agent - disable exiting for existing agents

This sounds like "as-it-is" as explained in the IA Admin Guide:

You can change settings for Endpoint Identity Agent parameters to control Endpoint Identity Agent behavior. You can change some of the settings in SmartConsole and others using the Endpoint Identity Agent Configuration tool.

In SmartConsole you can comfigure e.g. "Allow user to save password", but for nac_agent_disable_quit you have to use the Endpoint Identity Agent Configuration tool. To configure these settings from Dashboard and deploy it to the users would be a RFE.

0 Kudos

Re: Identity Agent - disable exiting for existing agents

I'm seeing the opposite of what you're saying here. 

We can configure the nac_agent_disable_quit in smartconsole dashboard, it's under global properties->advanced->identity awareness->agent. These settings just don't seem to push out to the agents during their authenticated sessions.

I don't see changing this setting as an option in the Endpoint Identity Agent Configuration Tool, and I don't see it stating that it can in the IA admin guide. Could you clarify where this can be done in the tool?

0 Kudos
Highlighted

Re: Identity Agent - disable exiting for existing agents

Sorry, i did mix things up a bit Smiley Sad - you are absolutely right in that this global property should be enforced for all users, so we certainly have a bug here. A workaround may be available by tweaking the Win Registry (see sk88520: Best Practices - Identity Awareness Large Scale Deployment for a complete List of Windows Registry Tweaks on Identity Agent Client), but TAC is the right place to report that.