Hello, I have searched high and low and cannot find where to set this. I have technicians and programmers that need to disable On-Access Scanner and Access Protection when installing or troubleshooting applications in the field. Is there an easy way to permit them to do this under their login credentials or with a shared password?
We have our Console locked and have our tech's type in the password to unlock the console. Then they can disable whatever they wish. Only issue is the policy enforcement interval (Default is 5 minutes), it will turn everything back on.
If you want to give your tech's the ability to have it off longer, then you could either change the policy enforcement to longer or change the access protection policy to allow the framework service to be turned off. (Prevent McAfee services from being stopped.) Then the tech's could stop the framework service resulting in no policy enforcement. Then disable any options in the console....
So if they had the ability to disable the framework service and you are no longer able to enforce policies. How would you restore that ability? Force install the agent on non-compliant systems? Or walk around and manually re-enable the framework service?
What about an audit log of when the service was disabled to match to a user login in the event log? So I have something to show management to justify not giving them the ability to disable AV. 😄
I know it’s sad that I have to babysit and worry about Tech's & Programmers doing things like that but I do.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.