- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Identity Agent - disable exiting for existing agen...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Agent - disable exiting for existing agents
I've configured the global properties such that nac_agent_disable_quit has been enabled, however agents that are already deployed are able to exit the agent still. New deploys are correctly receiving this setting.
What have people done to ensure this setting is changed for agents that are already deployed?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi David,
You've got a good one there. I am thinking that this may be a bug. As I can't find official documentation that suggests that is normal behaviour.
I'd get a TAC case raised to investigate further.
Just out of interest are the existing clients running the latest version of the identity agent? Or an older one?
Regards
Mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Mark,
I'll get one open and see what their recommendation is.
we have our clients running on the latest version, R80.174
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This sounds like "as-it-is" as explained in the IA Admin Guide:
You can change settings for Endpoint Identity Agent parameters to control Endpoint Identity Agent behavior. You can change some of the settings in SmartConsole and others using the Endpoint Identity Agent Configuration tool.
In SmartConsole you can comfigure e.g. "Allow user to save password", but for nac_agent_disable_quit you have to use the Endpoint Identity Agent Configuration tool. To configure these settings from Dashboard and deploy it to the users would be a RFE.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm seeing the opposite of what you're saying here.
We can configure the nac_agent_disable_quit in smartconsole dashboard, it's under global properties->advanced->identity awareness->agent. These settings just don't seem to push out to the agents during their authenticated sessions.
I don't see changing this setting as an option in the Endpoint Identity Agent Configuration Tool, and I don't see it stating that it can in the IA admin guide. Could you clarify where this can be done in the tool?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry, i did mix things up a bit - you are absolutely right in that this global property should be enforced for all users, so we certainly have a bug here. A workaround may be available by tweaking the Win Registry (see sk88520: Best Practices - Identity Awareness Large Scale Deployment for a complete List of Windows Registry Tweaks on Identity Agent Client), but TAC is the right place to report that.
