Kaspersky Anti Targeted Attack Platform

Managing Kaspersky Endpoint Agent policies

This section describes how to create Kaspersky Endpoint Agent policies and enable policy settings.

In this section

Creating Kaspersky Endpoint Agent policy

Enabling settings in Kaspersky Endpoint Agent policy

See also

Configuring Kaspersky Endpoint Agent settings

Managing Kaspersky Endpoint Agent tasks

Page top
[Topic 193603]

Creating Kaspersky Endpoint Agent policy

This section provides information related to Kaspersky Endpoint Agent for Windows. This information may be partially or completely inapplicable to Kaspersky Endpoint Agent for Linux. For complete information about Kaspersky Endpoint Agent for Linux, please refer to the Help of the solution that includes the application: Kaspersky Anti Targeted Attack Platform or Kaspersky Managed Detection and Response.

To create a Kaspersky Endpoint Agent policy in Kaspersky Security Center:

  1. Open Kaspersky Security Center Administration Console.
  2. In the console tree, open the Policies folder.
  3. Click Create a policy.

    The policy creation wizard starts.

  4. In the Selecting an application for creating a group policy window, select Kaspersky Endpoint Agent.
  5. Click Next.
  6. In the Enter group policy name window, perform the following actions:
    1. Enter the name that will be used for the new policy in the policy list.
    2. If you want to import the settings of an existing Kaspersky Endpoint Agent policy to a new policy:
      1. Select the Use the policy settings for previous application version check box.
      2. Click Select and in the window that opens, select the policy whose settings you want to import.
      3. Click ОК.
    3. Click Next.
  7. In the New policy window, select one of the following options:
    • Create a new policy and configure its settings.
    • Create a new policy with default settings.

    If you enabled the Use the policy settings for previous application version setting at the previous step, the Create a new policy and configure its settings option is selected by default, and the settings specified in the imported policy are displayed during the policy creation. In this case, the switch in the upper right corner of each section with the policy settings, which shows if the policy is applied, depends on the position of the switches

    .

  8. Click Next.
  9. In the Select policy type window, select the required Kaspersky Endpoint Agent deployment method:
    • Integration with Kaspersky Sandbox
    • Endpoint Detection and Response Expert (KATA EDR), Kaspersky Industrial CyberSecurity for Networks
  10. Click Next.
  11. If you select the Create a new policy and configure its settings option, perform one of the following actions in all sequentially displayed settings windows:
    • To configure the application settings in the displayed sections during policy creation:
      1. Click Configure next to the name of the required section.
      2. In the window that opens, configure the required settings and click OK.
      3. Click Next.
    • To configure the application settings in the displayed section later, click Next.

    Configuration of the application settings consists of the following steps:

    The composition of the steps depends on the type of policy selected during the previous step and may differ from the one described.

    • Configuring integration between Kaspersky Endpoint Agent and Kaspersky Sandbox.
    • Configuring integration of Kaspersky Endpoint Agent with Endpoint Detection and Response Expert (KATA EDR) and Kaspersky Industrial CyberSecurity for Networks (KICKS for Networks) components.
    • Configuring threat response settings.
    • Configuring application repositories.
    • Configuring application security settings.
    • Configuring general application settings.
  12. In the Target group window, select the Kaspersky Security Center administration group to which the created policy will be applied by performing the following steps:
    1. Click Browse.

      The administration group selection window will open.

    2. Select the administration group from the list.

      For example, you can select the Managed devices group.

    3. If you want to create a subgroup in the Managed devices group:
      1. Click New group.
      2. In the window that opens, enter the name of the device subgroup.
      3. Click OK.
    4. Click Next.
  13. In the Creating a group policy for the application window, select one of the following policy statuses:
    • Active policy to activate the policy as soon as it is created.
    • Inactive policy to activate the policy later.
    • Out-of-office. The policy becomes active when the computer leaves the corporate network.
  14. Select the Open policy properties after creation check box if you want to perform additional configuration of the policy immediately after creating it.
  15. Click Finish.

The created policy will now appear in the policy list.

See also

Enabling settings in Kaspersky Endpoint Agent policy

Page top
[Topic 193099]

Enabling settings in Kaspersky Endpoint Agent policy

When you configure Kaspersky Endpoint Agent policy settings, by default these settings are saved, but are not applied until you enable them. The settings in the policy sections are divided into groups. You can enable either individual groups or all groups within one policy.

To enable the group of settings in Kaspersky Endpoint Agent policy:

  1. Open Kaspersky Security Center Administration Console.
  2. In the console tree, open the Policies folder.
  3. Select Kaspersky Endpoint Agent policy and open its properties window in one of the following ways:
    • Double-click the policy name.
    • Select Properties in the policy context menu.
    • Select the Configure policy settings item in the right part of the window.
  4. Select the policy for which you want to enable the settings.
  5. In the window that opens, select the section and group of settings to which the required setting belongs.
  6. In the upper right corner of the settings group, change the switch from Unaffected by policy to Under policy.

All the settings of the group will be applied in the policy after the changes are saved.

See also

Creating Kaspersky Endpoint Agent policy

Page top
[Topic 206438]