Eset PROTECT Cloud Owner's Manual
Below you will find brief information for ESET PROTECT Cloud. This user guide provides instructions for using ESET PROTECT Cloud. It covers topics like getting started, managing endpoints, deployment, policies, reports, and more. The guide helps users understand the features and capabilities of ESET PROTECT Cloud to secure their environment.
Advertisement
Advertisement
ESET PROTECT Cloud protect_cloud
Click here to display the Online help version of this document
Copyright ©2021 by ESET, spol. s r.o.
ESET PROTECT Cloud was developed by ESET, spol. s r.o.
For more information visit https://www.eset.com
All rights reserved. No part of this documentation may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning, or otherwise without permission in writing from the author.
ESET, spol. s r.o. reserves the right to change any of the described application software without prior notice.
Technical Support: https://support.eset.com
REV. 4/22/2021
1 About help
.....................................................................................................................................................
...............................................................................................................................................
2 Release notes
..............................................................................................................................................
3 Availability of service
............................................................................................................................
4 Introduction to ESET PROTECT Cloud
..........................................................................................
4.3 Supported Operating Systems
............................................................................................................
..........................................................................................................................................
4.5 Differences between on-premise and cloud management console
...............................................
5 Getting started with ESET PROTECT Cloud
...............................................................................
5.1 Create a new ESET PROTECT Cloud instance using ESET Business Account
...............................
5.2 Create a new ESET PROTECT Cloud user in ESET Business Account
.............................................
5.3 ESET PROTECT Cloud Web Console
.....................................................................................................
..........................................................................................................................................
..........................................................................................................................................
5.3.4 Filters and layout customization
..................................................................................................................
....................................................................................................................................................
............................................................................................................................................
5.3.7 Troubleshooting - Web Console
...................................................................................................................
5.4 Synchronize ESET PROTECT Cloud with Active Directory
...............................................................
5.5 How to manage Endpoint products from ESET PROTECT Cloud
.....................................................
5.6 ESET Push Notification Service
...........................................................................................................
6 VDI, cloning and hardware detection
........................................................................................... 49
6.1 Resolving cloning questions
................................................................................................................
........................................................................................................................
7 Apache HTTP Proxy
................................................................................................................................
7.1 Apache HTTP Proxy installation and cache
.......................................................................................
7.2 Apache HTTP Proxy installation - Linux
.............................................................................................
7.2.1 Squid HTTP Proxy installation on Ubuntu Server
..............................................................................................
8 ESET Management Agent Deployment
.......................................................................................
8.1 Add computers using RD Sensor
.........................................................................................................
..............................................................................................................................
............................................................................................................................
..................................................................................................................................
8.2.1 Create Agent (and ESET security product) installer
...........................................................................................
8.2.1.1 ESET PROTECT Live Installer behavior
........................................................................................................
8.2.2.2 Agent prerequisites - Linux
......................................................................................................................
............................................................................................................................
..............................................................................................................................
8.3.1.1 Deployment steps - SCCM
.......................................................................................................................
8.3.2 ESET Remote Deployment Tool
...................................................................................................................
8.3.2.1 ESET Remote Deployment Tool prerequisites
...............................................................................................
8.3.2.2 Select computers from Active Directory
......................................................................................................
8.3.2.4 Import a list of computers
.......................................................................................................................
8.3.2.5 Add computers manually
........................................................................................................................
8.3.2.6 ESET Remote Deployment Tool - troubleshooting
..........................................................................................
....................................................................................................................................
8.6 Troubleshooting - Agent connection
..................................................................................................
9 ESET PROTECT Cloud Main Menu
...................................................................................................
.............................................................................................................................................
............................................................................................................................................
...................................................................................................................................
9.2.2 Remove computer from management
.........................................................................................................
...............................................................................................................................................
....................................................................................................................................
.....................................................................................................................................
.....................................................................................................................................
9.2.3.3.1 Create a new Static Group
9.2.3.3.2 Export Static Groups
9.2.3.3.3 Import Static Groups
..................................................................................................................
.........................................................................................................................
.........................................................................................................................
.................................................................................................................................
9.2.3.4.1 Create a new Dynamic Group
..............................................................................................................
9.2.3.5 Move Static or Dynamic Group
...............................................................................................................
9.2.3.6 Assign Client Task to a Group
.................................................................................................................
9.2.3.7 Assign Policy to a Group
.......................................................................................................................
.............................................................................................................................................
................................................................................................................................
...................................................................................................................................
9.3.2.1 ESET security products compatible with exclusions
......................................................................................
...............................................................................................................................
..................................................................................................................................................
9.4.1 Create a new report template
...................................................................................................................
....................................................................................................................................
..................................................................................................................................
............................................................................................................................
..........................................................................................................................
...............................................................................................................................
......................................................................................................................................................
.........................................................................................................................................
.............................................................................................................................
9.5.1.1.1 Assign Client Task to a Group or Computer(s)
..........................................................................................
...............................................................................................................................
.......................................................................................................................................
.................................................................................................................................
9.5.1.5 End computer isolation from network
.......................................................................................................
9.5.1.6 Export Managed Products Configuration
....................................................................................................
9.5.1.7 Isolate computer from network
...............................................................................................................
9.5.1.9 Modules Update Rollback
......................................................................................................................
..............................................................................................................................
9.5.1.11 Operating System Update
....................................................................................................................
9.5.1.12 Quarantine Management
.....................................................................................................................
.............................................................................................................................
...........................................................................................................................
9.5.1.15 Rogue Detection Sensor Database Reset
.................................................................................................
..................................................................................................................................
9.5.1.17 Run SysInspector Script
......................................................................................................................
.....................................................................................................................................
...........................................................................................................................
.................................................................................................................................
9.5.1.20.1 Upgrade ESET software
....................................................................................................................
............................................................................................................................
.............................................................................................................................
9.5.1.22 Stop Managing (Uninstall ESET Management Agent)
...................................................................................
.................................................................................................................................
9.5.1.25 Upload Quarantined File
......................................................................................................................
........................................................................................................................................
9.5.2.1 Delete Not Connecting Computers
...........................................................................................................
.................................................................................................................................
.............................................................................................................................
.................................................................................................................................
9.5.3.1 Cron expression interval
.......................................................................................................................
9.5.4 Advanced Settings - Throttling
..................................................................................................................
.............................................................................................................................
.....................................................................................................................................
...............................................................................................................................
........................................................................................................................................
.......................................................................................................................................
...............................................................................................................................................
..................................................................................................................................................
.....................................................................................................................................
..................................................................................................................................................
....................................................................................................................................
9.7.4 How Policies are applied to clients
.............................................................................................................
.................................................................................................................................
...........................................................................................................................
.................................................................................................................................
9.7.4.3.1 Example scenario of merging policies
....................................................................................................
9.7.5 Configuration of a product from ESET PROTECT Cloud
.....................................................................................
9.7.6 Assign a Policy to a Group
.......................................................................................................................
9.7.7 Assign a Policy to a Client
........................................................................................................................
9.7.8 How to use Override mode
.......................................................................................................................
.........................................................................................................................................
..............................................................................................................................
9.8.1.2 Status update on ESET PROTECT Cloud
.....................................................................................................
.......................................................................................................................
..........................................................................................................................................
...................................................................................................................................
.....................................................................................................................................................
...................................................................................................................................
.........................................................................................................................................
.........................................................................................................................................
..................................................................................................................................
.................................................................................................................................
........................................................................................................................................
9.10.4.3 Create New User Group
.......................................................................................................................
9.10.5 Dynamic Group Templates
.....................................................................................................................
9.10.5.1 New Dynamic Group Template
..............................................................................................................
9.10.5.2 Rules for a Dynamic Group template
......................................................................................................
....................................................................................................................................
9.10.5.2.2 Rules and logical connectors
..............................................................................................................
9.10.5.2.3 Template rules evaluation
.................................................................................................................
9.10.5.3 Dynamic Group template - examples
......................................................................................................
9.10.5.3.1 Dynamic Group - a security product is installed
.......................................................................................
9.10.5.3.2 Dynamic Group - a specific software version is installed
............................................................................
9.10.5.3.3 Dynamic Group - a specific version of a software is not installed at all
..........................................................
9.10.5.3.4 Dynamic Group - a specific version of a software is not installed but other version exists
...................................
9.10.5.3.5 Dynamic Group - a computer is in specific subnet
....................................................................................
9.10.5.3.6 Dynamic Group - installed but not activated version of server security product
...............................................
9.10.5.4 How to automate ESET PROTECT Cloud
...................................................................................................
............................................................................................................................
.....................................................................................................................................
.............................................................................................................................................
9.10.7.1.1 User actions and user details
.............................................................................................................
9.10.7.1.2 Assign a Permission Set to a User
........................................................................................................
9.10.7.1.3 Two-Factor Authentication
.................................................................................................................
................................................................................................................................
9.10.7.2.1 Manage Permission Sets
...................................................................................................................
9.10.7.2.2 List of permissions
..........................................................................................................................
...........................................................................................................................................
............................................................................................................................................
9.10.9.1 Syslog security restrictions and limits
.....................................................................................................
...........................................................................................................................
..................................................................................................................................
9.10.10.2 Events exported to LEEF format
...........................................................................................................
9.10.10.3 Events exported to JSON format
..........................................................................................................
10 ESET PROTECT Cloud for Managed Service Providers
...................................................
10.1 Features of ESET PROTECT Cloud for MSP users
.........................................................................
10.2 Create a new ESET PROTECT Cloud user in ESET MSP Administrator
......................................
10.3 Deployment process for MSP
..........................................................................................................
10.3.1 Local deployment of Agent
.....................................................................................................................
10.3.2 Remote deployment of Agent
..................................................................................................................
......................................................................................................................................
...............................................................................................................
................................................................................................................
....................................................................................................................
...........................................................................................................................................
....................................................................................................................
......................................................................................................................
......................................................................................................................
11 Cloud Mobile Device Management
...........................................................................................
..............................................................................................................................
..........................................................................................................................
12 ESET PROTECT Cloud Migration scenarios
...........................................................................
12.1 Partial Migration from ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud
............................
13 Stop using ESET PROTECT Cloud
...............................................................................................
13.1 Last ESET PROTECT Cloud license expiration
...............................................................................
14 About ESET PROTECT Cloud
.........................................................................................................
15 ESET PROTECT Cloud Security
....................................................................................................
16 Terms of Use
.........................................................................................................................................
16.1 ESET Management Agent EULA
.......................................................................................................
16.2 Data Processing Agreement
............................................................................................................
16.3 Standard Contractual Clauses
.........................................................................................................
17 Privacy policy
........................................................................................................................................
18 Cloud Eligible Licenses
....................................................................................................................
19 Preview features
.................................................................................................................................
...............................................................................................................................
.............................................................................................................................
About help
The Administration guide was written to help you get familiar with ESET PROTECT Cloud and provides instructions to use it.
For consistency and to help prevent confusion, the terminology used throughout this guide is based on the ESET
PROTECT Cloud parameter names. We also use a set of symbols to highlight topics of particular interest or significance.
Note
Notes can provide valuable information, such as specific features or a link to a related topic.
Important
This requires your attention and it should not be skipped. Usually, it provides non-critical but significant information.
Warning
Critical information you should treat with increased caution. Warnings are placed specifically to deter you from committing potentially harmful mistakes. Please read and understand text placed in warning brackets, as it references highly sensitive system settings or something risky.
Example
Example scenario that describes a user case relevant for the topic where it is included. Examples are used to explain more complicated topics.
Convention
Bold type
Italic type
Meaning
Names of interface items such as boxes and option buttons.
Placeholders for information you provide. For example, file name or path means you type the actual path or a name of file.
Courier New Code samples or commands
Hyperlink Provides quick and easy access to cross-referenced topics or external web location. Hyperlinks are highlighted in blue and may be underlined.
%ProgramFiles% The Windows system directory which stores installed programs of Windows and others.
• Online Help is the primary source of help content. The latest version of Online Help will automatically be displayed when you have a working internet connection.
• Topics in this guide are divided into several chapters and sub-chapters. You can find relevant information by using the search field at the top.
• The ESET Knowledgebase contains answers to the most frequently asked questions, as well as recommended solutions for various issues. Regularly updated by ESET technical specialists, the
Knowledgebase is the most powerful tool for resolving various types of problems.
• The ESET Forum provides ESET users with an easy way to get help and to help others. You can post any problem or question related to your ESET products.
• You can post your rating and/or provide a feedback on a particular topic in help: Click the Was this
information helpful? link underneath the help page.
Icon legend
This is a collection of icons used throughout ESET PROTECT Cloud Web Console with their description. Some of the icons depict actions, item types or current status. Most icons are displayed in one of three colors to denote the accessibility of an element:
1
Default icon - available action
Blue icon - highlighted element when you hover with mouse pointer
Gray icon - action not available
Status icon Descriptions
Show Details - detailed information
about the client device.
Add New - add new devices.
New Task - add new task.
New Notification - add new notification.
New Static/Dynamic Groups - add new groups.
Edit - you can edit your created tasks, notifications, reports template, groups, policies, etc.
Duplicate - lets you create a new policy based on the existing policy you have selected, a new name is required for the duplicate.
Move - computers, policies, Static or Dynamic Groups.
Access Group - Move the item to a different Static Group.
Delete - removes the selected client, group, etc completely.
Rename multiple items - if you select multiple items you can rename them one by one in a list or use Regex search and replace multiple items at once.
Scan - using this option will run the On Demand Scan task on the client that reported the detection.
Update Modules - using this option will run the
task (triggers an update manually).
Audit Log - View the Audit Log
for the selected item.
Reboot - if you select a computer and press Reboot the device will be rebooted.
Restore - restore
quarantined file to its original location.
Shutdown - if you select a computer and click Reboot > Shutdown the device will be shut down.
Run Task - select a task and configure trigger and throttling
(optional) for this task. The task will be queued according to the task settings. This option immediately triggers an existing
that you select from a list of available tasks.
Last used tasks - shows last used tasks. You can click task to execute it again.
Assign User - assign user to a device. You can manage users in Computer Users .
can also be assigned directly to a client (multiple clients), not just a group.
Select this option to assign the policy to selected client(s).
Send Wake-Up Call - ESET PROTECT Cloud Server runs instant replication of the ESET Management
when the ESET Management Agent connects to the ESET PROTECT Cloud Server. For example when you want a
Client Task to be run immediately on client(s) or if you want a
to be applied right away.
Connect - generate and download a .rdp file that will let you connect to target device via Remote
Desktop Protocol.
Mute - if you select a computer and press Mute, the Agent on this client stops reporting to ESET
PROTECT Cloud; it will only aggregate the information. A muted icon will be displayed next to a computer name in the Muted column.
Once muting is disabled by clicking Un-mute, the muted computer will report again and communication between ESET PROTECT Cloud and the client is restored.
Disable - disable or remove a setting or selection.
Assign - assign a Policy to client or groups.
you want to import.
Export - select
Tags - Edit tags
Static Group
/
(assign, unassign, create, delete).
2
Status icon Descriptions
Dynamic Group
Not apply
Triggers - See the list of
for the selected Client Task.
Desktop
Server
File Server
Mail Server
Gateway Server
Collaboration Server
Agent
Rogue Detection Sensor
ESET Full Disk Encryption
Enable EDTD - activate and enable the ESET Dynamic Threat Defense.
Release notes
ESET PROTECT Cloud 2.2.0
• NEW: New concept–Option to preview certain features
• NEW: Preview feature–Support for iOS / iPadOS (without ABM enrollment)
• NEW: Preview feature–Computer preview
• ADDED: Upgrade outdated products in a computer group
• ADDED: Default filter in the Detection screen (unresolved detections first)
• ADDED: Ability to use a second license to activate ESET Dynamic Threat Defense in a software installation task when an eligible endpoint product is selected
• ADDED: User management for users with global "write" access
• ADDED: Expiration time for client task triggers (Triggers tab)
• ADDED: New report–Computer Hardware Overview
• ADDED: Enabled non-root administration (other than the instance creator) to manage the security of other managed accounts (depends on the upcoming EBA release planned for April 2020)
• IMPROVED: Pause a task for ESET Full Disk Encryption (capability to select an exact date and time)
• IMPROVED: The encryption status tile is now more interactive
• IMPROVED: Extended information in detection details
• IMPROVED: A recommendation message is displayed when the Administrator tries to run a client task on more than 1,000 clients (using a group is recommended)
• IMPROVED: Assigning a policy to more than 200 individual devices is permitted (using a group is recommended)
• IMPROVED: Various performance improvements
• FIXED: Licenses with over 10,000 seats were displayed as infinite
• FIXED: In some cases, the "Planned" flag In a client task remained active after a task was executed
3
• FIXED: The license usage number did not display the correct number when a license was overused
• FIXED: Subunits were not used by percentage usage enumeration for mail security products
• FIXED: The operating system name (Big Sur) for macOS 11.1 and 11.2 was missing
• FIXED: Various other bug fixes and improvements
ESET PROTECT Cloud 2.1.0
• ADDED: Ability to look up specific computer based on the last logged user parameter
• ADDED: Support for policy-based migration from on-premise console to cloud console
• FIXED: Issue with opening/reading PDF reports sent by email (base64-encoded)
• FIXED: Non-root user with write permission rights for ESET PROTECT Cloud in ESET Business Account cannot import or create dynamic group templates
• FIXED: Device filters on Dashboards display different values than in tables
• FIXED: In some cases, Detail in the "Audit Log" overlapping other lines
• FIXED: Product deactivation fails with timeout (in certain cases) if started by "Delete not connected computers" server task
• FIXED: User cannot delete objects in some cases even with correct access rights
• FIXED: Name of the file is garbled when Japanese characters are used
• FIXED: Various other bug fixes and minor improvements
ESET PROTECT Cloud 2.0.148.0
• CHANGED: ESET Cloud Administrator renamed to ESET PROTECT Cloud
• ADDED: Ability to manage and protect Android mobile devices
• ADDED: Ability to manage FileVault (macOS) native encryption when an eligible license is present
• ADDED: Increased device management limit (up to 10,000 - dependent on purchased license size)
• ADDED: One-click deployment of ESET Dynamic Threat Defense if an eligible license is present
• ADDED: Ability to manage dynamic groups
• ADDED: Ability to manage notifications
• ADDED: Ability to define specific permission sets for selected users
• ADDED: Active Directory synchronization (Computers only)
• ADDED: Syslog log exporting
• ADDED: New “Audit log” section provides detailed information about specific actions
• ADDED: Ability to mass deploy the management agent to macOS devices
• ADDED: Second-level menu for advanced options
• ADDED: Secure Browser management
4
5
• ADDED: Support for sites (ESET Business Account) licenses including new "License user" column
• ADDED: Renew a license in the “License Management” screen
• ADDED: Ability to drill-down from expiring license issues in “Dashboards” and “Reports” to obtain more information in the “License Management” screen
• ADDED: New “Manage license” context menu
• ADDED: EULA update notifications that support auto-upgrade (uPCU) of endpoint products in managed environments
• ADDED: New ESET Full Disk Encryption (EFDE) management actions directly from “Computer details”
• ADDED: New EFDE Dynamic groups and Reports
• ADDED: Detection details (LiveGrid, Observed in organization, Virus Total )
• ADDED: One-click access to client task triggers
• ADDED: Unsupported browser warning
• ADDED: New "Seats allocated to sites" present in dedicated license report
• ADDED: Multi-line command scripts for Run Command task
• ADDED: Option to create a Computer user group in the “Add computer user” wizard
• CHANGED: Management Agent - supported operating systems
• CHANGED: Retention policy defaults
• CHANGED: License unit/sub-units visualization changed to "used/total" for online licenses and "X offline" for offline licenses
• CHANGED: Access to behavior reports (when EDTD is purchased and enabled) are available (in the UI) only if an eligible license is present
• IMPROVED: Ability to define a retention policy for certain logs
• IMPROVED: Exclusions mechanism extended to firewall threats
• IMPROVED: Computer details now directly accessible by clicking the computer name
• IMPROVED: One-click Network isolation
• IMPROVED: Columns ordering
• IMPROVED: Pop-up with search option
• IMPROVED: Hierarchical Dynamic groups tree
• IMPROVED: Multi-select in pop-up (modal) windows
• IMPROVED: Ability to create one exclusion from multiple detentions with standard exclusion criteria(s)
• IMPROVED: Breadcrumbs for better navigation in Wizards
• IMPROVED: Various other performance and security improvements
• FIXED: “Delete task action” removes all client tasks, not just selected items in a task list for a specific group
• FIXED: Status filter not visible for server tasks (only in client tasks)
• FIXED: Failed to send a wake-up call from the client task details executions
• FIXED: Incorrect target group type displays when editing a client trigger
• FIXED: “Status update” type notifications fail to save if they contain the “$” character
• FIXED: Import of policies with large file sizes
• FIXED: Infinite units or subunits in tooltips for licenses in the License Management screen display incorrectly
• FIXED: License-related notifications (for example, expiration/overuse) trigger when a license is suspended
• FIXED: Policy does not block the selected Scan profile
• FIXED: Filters previously set are not saved
• FIXED: Various other bug fixes
ESET Cloud Administrator 1.2.118.0
• ADDED: Support for ESET Dynamic Thread Defense (Sold separately. Available for purchase in upcoming weeks)
• ADDED: Submitted files screen
• ADDED: Ability to pause ESET Full Disk Encryption available from EFDE client version 1.2 (EFDE - purchased separately)
• ADDED: Automatic resolution of firewall logs and filtered websites
• ADDED: Ukrainian language
• ADDED: New filtering options
• ADDED: Many other performance, usability, and security improvements
• IMPROVED: Discontinued the default limit for the number of displayed static groups
• IMPROVED: Performance improvements in the “groups” tree on the “Computers” and “Detections” screens
• IMPROVED: Selected screens redesign: Users, scheduled reports and edit updates in the navigation bar
• IMPROVED: Unified table design for task selection, computers selection, and other features
• IMPROVED: Second-level menu added under "Change assignments" in the policy screen
• FIXED: Delay of product version status shown in the main web console
• FIXED: System applications are not reported on macOS 10.15
• FIXED: Language detection on macOS Catalina
• FIXED: Table sorting behavior: Clicking column headers adds columns to multi-sorting until it has been clicked
3 times
• FIXED: Last scan time in “computer details” screen won’t impact the computer security status tile
• FIXED: User cannot resolve detections when the “Resolved” column is not shown in the “detections” table
• FIXED: The side panel does not remember the expanded/collapsed state after log-out and log-in
• FIXED: Some threats cannot be marked as resolved
• FIXED: After moving computers from a specific group, the view is changed to the group "ALL."
ESET Cloud Administrator - ESET Management Agent release- June
6
• ADDED: New version of ESET Management Agent
• ADDED: Updating ESET Management Agent to the latest version can be deployed centrally alongside the cloud service update
• ADDED: Agent compatibility with H1/2021 Windows version 10
ESET Cloud Administrator 1.2.82.0
• IMPROVED: Email domain validation when sending live installer link was discontinued
• IMPROVED: Checkbox "automatically reboot when needed" not checked by default when activating EFDE from encryption tile
• IMPROVED: Dozens of usability, security, performance and stability improvements
• FIXED: Clicking column headers adds columns to multi-sorting until it has been clicked 3 times
• FIXED: Last Scan Time should note trigger red security status
• FIXED: Not possible to resolve detections when "Resolution" column is not shown
• FIXED: The side panel doesn't remember expanded/collapsed state after log-out and log-in
• FIXED: Agents stop connecting to cloud service under some circumstances
• FIXED: Recipients not visible in notifications emails
• FIXED: Computer with outdated OS are not visible in appropriate dynamic group
• FIXED: Ability to create hash exclusion without a hash present
• FIXED: ESET Full Disk Encryption not included within the selective export task configuration
ESET Cloud Administrator 1.2
• NEW: ESET Full Disk Encryption
• NEW: Tagging - mark all relevant objects (e.g., computers) using user-defined tags
• NEW: Support for the newest generation of Linux products, starting with ESET File Security for Linux v7
• NEW: Centralized Exclusions and wizard
• ADDED: Option to automatically delete computers that are not connecting
• ADDED: Option to rename computers based on defined criteria
• ADDED: Computer isolation task
• ADDED: Unified table design with new navigation elements
• ADDED: Ability to export tables across all the main screens to different formats
• ADDED: New "empty screen states" for simpler object creation
• ADDED: Detections view is now aggregated by time and other criteria to simplify operations and to resolve them
• ADDED: Execute one click actions from the "task executions" screen
7
8
• ADDED: Create a combined installer including ESET Full Disk Encryption
• ADDED: Option to deactivate individual products
• ADDED: New dynamic groups related to newly introduced products
• ADDED: Search by group name in computer screens and search bar
• ADDED: Option to save dashboard layout as preset for other users
• ADDED: Generate defined reports filtered to a selected group
• ADDED: Indonesian language support
• ADDED: New ESET Management Agent version (Windows) supports the latest security products
• IMPROVED: Many UI Improvements & other usability changes
• IMPROVED: Context menu now applies for all selected rows
• IMPROVED: Filtering panel has many new options such as autocomplete
• IMPROVED: New column selector element for primary tables.
• IMPROVED: Layout of detections (previously "threats") screen with new detection details
• IMPROVED: Reports screen layout includes a one click report generation option
• IMPROVED: Task section was updated and triggers are now displayed in a separate view of "task details"
• IMPROVED: Layout of policies screen, with simpler orientation and navigation
• IMPROVED: Layout of notifications screen with notification details
• IMPROVED: Quick links menu
• IMPROVED: AV remover (part of management agent) supports auto update
• IMPROVED: Download speeds from the repositories were significantly improved
• IMPROVED: Management agent file size significantly reduced
• CHANGED: "Threats" section was renamed to "Detections"
• CHANGED: Management agent compatibility update related to macOS 10.7 and 10.8 support (see the documentation for more details)
• CHANGED: ESET Cloud Administrator ends support for Endpoint and Server Security versions 6.4 and earlier.
• FIXED: Various other bug fixes and internal performance improvements
ESET Cloud Administrator 1.1.360.0
• Added: Full support for endpoint version 7.1 products
• Fixed: Various bugs
ESET Cloud Administrator 1.1.359.0
• Improved: Internal performance improvements
ESET Cloud Administrator 1.1.358.0
• Improved: Overall performance improvements
• Changed: Updated copyright information
• Fixed: ESET Cloud Administrator (ECA) server does not receive all "Web protection" threats
• Fixed: "Web protection" threat details view in the webconsole displays an unexpected error
• Fixed: An uncaught exception occurs when working with ECA
• Fixed: Indonesian language support is missing in product installation filters
• Fixed: Server Device Status chart is missing
ESET Cloud Administrator 1.1.356.0
• FIXED: Issue with too many notifications send from one incident.
ESET Cloud Administrator 1.1.350.0
• New version of ESET Management Agent fixing various installation/upgrade/repair issues.
• Internal service performance improvements
• Fixed invalid installer CA certificate encoding in GPO installer script
ESET Cloud Administrator 1.1.349
• Various minor performance improvements
ESET Cloud Administrator 1.1.345
• Various minor bug fixes
• Wrong information is displayed under "Policy Product" column while creating the ECA Live installer
ESET Cloud Administrator 1.1.343.0
• One-click actions
• New one-click action - One click upgrade option – even from aggregated data.
• New One-click actions to resolve "resolvable" actions – activate, reboot, update OS, or various protection issues
• Hardware inventory
• Redesigned client details section
• New "incident overview" dashboard, with new types of graphical elements, and one-click navigation to threats
• Improved Automatic resolving of handled threats
• Option to generate live installer without security product selected
9
10
• New status overview section
• Live installer now support offline cache to speed up the deployment
• Overall UI improvements (polished UI, new vector icons, updated menus)
• Updated "overview" dashboard with one click navigation & Configurable RSS feed
• Redesigned quick links & help links
• New layout for wizard elements
• Ability to switch ECA do different language in EBA (support for NEW languages)
• Automatic detection of "machine cloning"
• Ability to send e-mail directly from ECA when sending installer
• Automatic log-outs
• New more streamlined way when adding computers or using introductory wizard
• Redesigned "filter bar" with the option to remove / reset / save filter presets + "category filter" moved to
"filters"
• New columns for number / highest severity of alerts, cloning questions, and hardware detection reliability status
• Enhanced filtering options by product name, version, number of alerts, policies, threats, & other options
• New "remove computer from management" wizard, showing clear steps how to correctly remove devices from
ECA
• Redesigned task wizard
• New task types - Diagnostic (enable diagnostic / log collector)
• Section "logs" now includes tabs to display "log collector" and new section for "diagnostic logs"
• Alerts - Alert (problem) details are reported from the supported security products
• New dynamic groups for desktops and servers
• Questions to resolve conflicts
• Possible to locate threats detected by the same scan
• Added current detection engine version and a hash value
• Possibility to filter by cause, threat type, scan, scanner and define more granular criteria for the time filter in threats
• Possibility to collapse and expand all reports in one click
• Software installation task executes a "pre-execution check", and reports "task failed" with further details
• New report template categories Hardware Inventory, Cloning Detection
• Restyled report creation wizard
• Extended options for filtering for specific values
• Redesigned installer generation flow
• Ability to configure LiveGrid and PUA settings when creating live installer
• Ability to configure Live Installer proxy settings during the installer creation
• Support for GPO (Group policy)
• New filter to "hide not-assigned policies"
• Policy details showing "assigned to" (combines computers / groups) and "applied on" (actually applied targets)
• New predefined policies for optimal usage of ESET Live Grid, and few tweaks to existing recommended templates for maximum protection
• Possibility to allow "local lists"
• Possible to edit multiple notifications at once
• New announcement channel to inform users about planned outages and other important events
• Improved migration from ERA6 (ESMC) managed environment when executing live installers
Availability of service
Availability
Our target is to provide 99.5% service availability. Our effort and well-defined processes drive this endeavor. In the event of an ESET PROTECT Cloud service outage, endpoints remain secure and unaffected.
Maintenance
The ESET PROTECT Cloud service is subject to routine maintenance procedures. All maintenance windows that exceed 15 minutes are announced to console administrators in advance. Outages during maintenance windows are not affecting our targeted availability. Maintenance will be performed during weekends and outside working hours
(US data center - during US night hours; EU data center - during EU night hours).
Introduction to ESET PROTECT Cloud
Welcome to ESET PROTECT Cloud. ESET PROTECT Cloud allows you to manage ESET products on workstations and servers in a networked environment with up to 10,000 devices from one central location. Using the ESET PROTECT
Cloud Web Console, you can deploy ESET solutions, manage tasks, enforce security policies, monitor system status and quickly respond to problems or threats on remote computers.
ESET PROTECT Cloud is made up of the following components:
ESET PROTECT Cloud as a service
ESET PROTECT Cloud Web Console
• The Web Console interprets the data stored in the ESET PROTECT Cloud database. It visualizes the vast amounts of data into clear dashboards and reports, and also enforces policies and carries out tasks on agents and other ESET applications.
ESET PROTECT Live Installer
• Is a small application consisting of ESET Management Agent and a business endpoint product in a streamlined and easy to use package.
• ESET Management Agent is a small application with no graphical user interface that executes the commands of ESET PROTECT Cloud on connected clients. It executes the tasks, collects logs from ESET applications, interprets and forces policies, and performs other valid tasks such as software deployment and general computer monitoring.
11
• Is an easily downloadable, pre-configured package, containing an agent and security product (downloaded during installation), in the form of a streamlined installer that will automatically connect to the proper cloud instance and activate itself with a valid license with minimal interaction required from the user. The installer will identify the correct platform and download the proper security product installer package.
• The agent is a lightweight application that facilitates all communication between the ESET security product on a client computer and ESET PROTECT Cloud .
ESET security products
• ESET security products protect client computers and servers from threats.
•
ESET PROTECT Cloud supports the following ESET security products .
ESET Business Account
• Central entry point for business customers, or an identity provider to ESET PROTECT Cloud.
• Serves as a single-sign on for business customers to view their licenses, activated services, perform user management, and more.
• An ESET business account is required to activate the ESET PROTECT Cloud instance.
ESET Remote Deployment Tool
• A tool that can remotely deploy ESET PROTECT Live Installer to the network.
• Has the capability to remotely map the network and sync with AD, or support the import of targets on which the product will be deployed .
12
New features in ESET PROTECT Cloud
Renaming of ESET Cloud Administrator
ESET Cloud Administrator was renamed "ESET PROTECT Cloud". Products and services are evolving to cover new markets and customer needs. We have decided to rename our solution to better accommodate the current and new capabilities that we have planned.
Remote Mobile Device Management for Android
Manage and protect Android mobile devices with ESET Endpoint Security for Android. Quickly deploy to one or multiple devices via email or QR code. Initial configuration and scalability offer significant advantages for operation in small environments while also suitable for large-site deployments.
ESET Full Disk Encryption for macOS
We are extending platform coverage and adding FileVault (native encryption for macOS) management to increase organizations’ data security. Learn more
Support of ESET Dynamic Threat Defense
An add-on paid service that provides another layer of security for ESET products such as Mail Security and
Endpoints by utilizing a cloud-based sandboxing technology to detect new, never-before-seen threat types. Future proof your company’s IT security with: Behavior-based Detection, Machine learning, Zero-day Threats Detection
and Cloud Sandboxing. Learn more
13
Manage up to 10,000 devices
Manage and protect up to 10,000 devices according to your license in ESET PROTECT Cloud.
Management Agent Auto-Update
Automation of updates will help with desired compatibility and the highest security. ESET will centrally manage and deploy the latest agent version to production. Smart design will ensure that all updates will be deployed in phases and distributed over a longer period.
Administrators can update the agent manually before the central automatic deployment starts.
Advanced functionality
Some of the new functionalities are focused on the needs of larger networks, allowing more customization. These are all incorporated into existing user interface.
Dynamic Groups management
Create customized dynamic groups for better organization of your devices.
Notifications management
Create customized email notifications to stay informed about the state of your network.
Customized Access Rights for Administrators
Extended functionality to customize access rights and define a permission set for administrators working with ESET
PROTECT Cloud. Decide what functionality or devices are accessible and what actions are allowed for each
Active Directory Scan (Computers)
Scan your active directory and add multiple computers at once to ESET PROTECT Cloud. Learn more
Audit Log
New functionality helps administrators identify and track activity in ESET PROTECT Cloud. Easily navigate to run
Syslog (Log export)
Collect and send security-related events from ESET PROTECT Cloud to a SIEM tool, where they can be analyzed by
Exclude Firewall Threats
Added the ability to exclude firewall threats from the list of detections.
Support for ESET Business Account Sites
You can now import the complete structure of your ESET Business Account, including the distribution of license seats among the sites .
Supported Web browsers, ESET security products and languages
The ESET PROTECT Cloud Web Console can be run in the following web browsers:
14
Web browser
Mozilla Firefox
Microsoft Edge
Google Chrome
Safari
Opera
Note
• For the best experience with the ESET PROTECT Cloud Web Console we recommend that you keep your web browsers updated.
• If you use Internet Explorer, ESET PROTECT Cloud Web Console will notify you that you are using an unsupported web browser.
Latest versions of ESET products manageable via ESET PROTECT
Cloud
Product
ESET Endpoint Security for Windows
ESET Endpoint Antivirus for Windows
Product version
6.5+
6.5+
ESET Endpoint Security for macOS
ESET Endpoint Antivirus for macOS
6.4+
6.4+
ESET File Security for Windows Server* 6.5+
ESET Mail Security for Microsoft Exchange Server* 6.5+
ESET Security for Microsoft SharePoint Server*
ESET Mail Security for IBM Domino Server*
ESET File Security for Linux
ESET Endpoint Antivirus for Linux
ESET Endpoint Security for Android
ESET Full Disk Encryption for Windows
ESET Full Disk Encryption for macOS
ESET Dynamic Threat Defense
6.5+
6.5+
7.x+
7.x+
2.10.x
Supported languages
Language Code
English (United States) en-US
Arabic (Egypt) ar-EG
Chinese Simplified
Chinese Traditional zh-CN zh-TW
Croatian (Croatia) hr-HR
Czech (Czech Republic) cs-CZ
French (France)
French (Canada) fr-FR fr-CA
German (Germany) de-DE
Greek (Greece) el-GR
Hungarian (Hungary)* hu-HU
Indonesian (Indonesia)* id-ID
Italian (Italy) it-IT
Japanese (Japan)
Korean (Korea) ja-JP ko-KR
Polish (Poland)
Portuguese (Brazil)
Russian (Russia)
Spanish (Chile) pl-PL pt-BR ru-RU es-CL
15
Spanish (Spain)
Slovak (Slovakia)
Turkish (Turkey)
Ukrainian (Ukraine) es-ES sk-SK tr-TR uk-UA
* Only the product is available in this language; Online Help is not available.
Supported Operating Systems
The following tables display supported operating systems for each ESET PROTECT Cloud component:
Windows
Operating System
Windows Server 2008 R2 x64 SP1 with KB4474419 or KB4490628 installed
Windows Server 2008 R2 CORE x64 with KB4474419 or KB4490628 installed ✔
Windows Server 2008 SP2 (x86 and x64) with KB4493730 and KB4039648 installed ✔
Agent RD Sensor
✔ ✔
✔
✔
Windows Storage Server 2008 R2 x64 with KB4474419 or KB4490628 installed
Windows Server 2012 x64
Windows Server 2012 CORE x64
✔
✔
✔
✔
✔
✔
Windows Server 2012 R2 x64
Windows Server 2012 R2 CORE x64
Windows Storage Server 2012 R2 x64
✔
✔
✔
✔
✔
✔
Windows Server 2016 x64
Windows Storage Server 2016 x64
Windows Server 2019 x64
✔
✔
✔
✔
✔ ✔
Operating System Agent RD Sensor
Windows 7 x86 SP1 with latest Windows updates (at least KB4474419 and KB4490628 ) ✔ ✔
Windows 7 x64 SP1 with latest Windows updates (at least KB4474419 and KB4490628 ) ✔
Windows 8 x86
Windows 8 x64
Windows 8.1 x86
Windows 8.1 x64
Windows 10 x86
Windows 10 x64 (all official releases)
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
Linux
16
17
Operating System Agent RD Sensor
Ubuntu 16.04.1 LTS x86 Desktop ✔ ✔
Ubuntu 16.04.1 LTS x86 Server ✔
Ubuntu 16.04.1 LTS x64 Desktop ✔
Ubuntu 16.04.1 LTS x64 Server ✔
✔
✔
✔
Ubuntu 18.04.1 LTS x64 Desktop ✔
Ubuntu 18.04.1 LTS x64 Server ✔
Ubuntu 20.04 LTS x64
RHEL Server 7 x86
RHEL Server 7 x64
RHEL Server 8 x64
✔
✔
✔
✔
✔
✔
✔
✔
✔
CentOS 7 x86
CentOS 7 x64
CentOS 8 x64
SLED 15 x86
SLED 15 x64
SLES 11 x86
SLES 11 x64
SLES 12 x86
SLES 12 x64
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
SLES 15 x86
SLES 15 x64
OpenSUSE Leap 15.2 x64
Debian 9 x86
Debian 9 x64
Debian 10 x64
Fedora 31 x64
Fedora 32 x64
✔
✔
✔
✔
✔
✔
✔
✔
✔
✔
Mac
Operating System macOS 10.12 Sierra
Agent
✔ macOS 10.13 High Sierra ✔ macOS 10.14 Mojave ✔ macOS 10.15 Catalina ✔ macOS 11.0 Big Sur ✔
Mobile
Operating System EESA EESA Device Owner
Android v5.x+ ✔
Android v6.x+
Android v7.x+
Android v8.x+
✔
✔ ✔
✔ ✔
Android v9.0
Android v10.0
Android v11
✔ ✔
✔ ✔
✔ ✔
Prerequisites
These prerequisites must be met for ESET PROTECT Cloud to work correctly:
These domains and ports must be allowed in your network firewall for ESET PROTECT Cloud to work correctly:
Domain eba.eset.com
identity.eset.com
protect.eset.com
eu02.protect.eset.com
us02.protect.eset.com
*.a.ecaserver.eset.com
edf.eset.com
repository.eset.com
Port Type / Port
Number
TCP/443
TCP/443
TCP/443
TCP/443
TCP/443
TCP/443
TCP/443
TCP/80
Description
ESET Business Account
ESET Identity Server
ESET PROTECT Cloud
ESET PROTECT Cloud Web Console Location: Europe
ESET PROTECT Cloud Web Console Location: USA
Connection between the Agent and ESET PROTECT Cloud
ESET PROTECT Live Installer
ESET PROTECT Live Installer. Repository required for deployment.
Connection for
Cloud MDM enrollment epns.eset.com
eu.mdm.eset.com (EUROPE) us.mdm.eset.com (USA) checkin.eu.eset.com (EUROPE) checkin.us.eset.com (USA)
TCP/8883
TCP/443
TCP/443 mdmcomm.eu.eset.com (EUROPE) mdmcomm.us.eset.com (USA)
TCP/443
Cloud MDM check-in
Cloud MDM communication
ESET PROTECT Cloud Remote Deployment Tool
Protocol Port Usage
TCP 139 Target port from the point of view of ESET PROTECT Cloud
Remote Deployment Tool
TCP 445 Target port from the point of view of ESET PROTECT Cloud
Remote Deployment Tool
Descriptions
Using the share ADMIN$
Direct access to shared resources using
TCP/IP during remote installation (an alternative to TCP 139)
Name resolution during remote install UDP
UDP
137 Target port from the point of view of ESET PROTECT Cloud
Remote Deployment Tool
138 Target port from the point of view of ESET PROTECT Cloud
Remote Deployment Tool
Differences between on-premise and cloud management console
Browse during remote install
ESET PROTECT Cloud includes all of the key features and capabilities you know from ESET PROTECT but has been adjusted to fit the needs of a cloud-based management.
The table below includes descriptions of the major differences between ESET PROTECT Cloud and ESET PROTECT.
General difference ESET PROTECT Cloud ESET PROTECT
18
Hosting
Manageable devices limitation
Supported client operating systems
Supported product versions
Runs in the ESET-maintained cloud environment..
10,000 client devices.
Windows, Linux , macOS and Android.
Business products version 6 and later.
Runs on your physical or virtualized environment.
Limitation depends on server hardware limitations.
Windows, Linux, macOS, Android, iOS.
• Business products version 4 and later.
• ESET Enterprise Inspector
Important
ESET PROTECT Cloud does not support ESET Enterprise Inspector. If you migrate from ESET PROTECT to ESET PROTECT Cloud, you will not be able to manage ESET Enterprise Inspector from ESET PROTECT Cloud.
Components
Virtualization
Active Directory
Mobile Device
Management
Certificates
Access rights
License management
How to add computers
• ESET Management Agent
• RD Sensor
• Deployment Tool
• CloudMDM
• ESET Management Agent
• RD Sensor
• Deployment Tool
• MDM
VAgentHost and ESET Virtualization Security are not available.
Active Directory synchronization is available
with the use of ESET Active Directory
VAgentHost and ESET Virtualization Security are available.
Active Directory synchronization is available.
Mobile device management is available by default via CloudMDM.
Mobile device management is available via
ESET PROTECT MDM
Certificate management is handled by ESET. User can create, edit or import/export
Certificates and Certification Authorities.
Access Rights Management was moved to
ESET Business Account but you can specify access to specific ESET PROTECT Cloud features for a user with custom permissions.
License management was fully moved to
ESET Business Account.
Advanced multi-tenant access rights security model that is manageable from the ESET
PROTECT interface.
Computers can be added via Active Directory synchronization, from an RD sensor report and using GPO and SCCM installer scripts.
License management is partially in ESET
PROTECT and partially in ESET Business
Account.
Computers can be added via Active Directory synchronization, from an RD sensor report, using GPO and SCCM installer scripts, manually by adding a new device with the addition of an Agent Deployment task, or by installing Agent locally.
Getting started with ESET PROTECT Cloud
ESET PROTECT Cloud is out-of-the-box solution for managing ESET security products in your small and medium business network. It represents a new approach, broadening the former ESET on-premise solution and introducing new, more flexible, cloud-based service, hosted and maintained by ESET.
This solution offers immediate use and forgoes the installation and setup steps required by on-premise solutions.
ESET PROTECT Cloud is built to be easy to deploy and easy to use. This new cloud hosted service comes with a contemporary web-based administration console (ESET PROTECT Cloud Web Console), that you can connect to from virtually any location and/or device with a proper internet connection.
The following sections detail ESET PROTECT Cloud Web Console features and how to use it. You can create installers and deploy ESET Management Agent and ESET security products on client computers. After ESET
Management Agent deployment, you can manage groups, create and assign policies and set up notifications and reports.
Getting started with ESET PROTECT Cloud
19
I am using ESET Business Account
a new ESET PROTECT Cloud instance.
2. Set up ESET PROTECT Cloud users in
ESET Business Account and add them to ESET PROTECT Cloud Web
Console.
the ESET PROTECT Cloud Web Console. See also Startup Wizard
and ESET PROTECT Cloud Web
4. Add client computers on your network to the ESET PROTECT Cloud structure.
Note
If you have an MSP account, you can synchronize your MSP account with the ESET PROTECT Cloud
Web Console.
from ESET PROTECT Cloud.
I am using ESET MSP Administrator
1. Create a new ESET PROTECT Cloud instance.
2. Set up ESET PROTECT Cloud users in ESET MSP Administrator and add them to ESET PROTECT Cloud Web
Console.
3. Open
the ESET PROTECT Cloud Web Console. See also Startup Wizard
and ESET PROTECT Cloud Web
4. Add client computers on your network to the ESET PROTECT Cloud structure.
from ESET PROTECT Cloud.
Create a new ESET PROTECT Cloud instance using ESET Business Account
Prerequisites
• A Superuser account in ESET Business Account .
• An eligible license for ESET PROTECT Cloud.
Important
• If your EBA and EMA2 accounts are registered to the same email address, the ESET PROTECT Cloud can be activated only from one account. The account (EBA or EMA2) you choose to create the ESET
PROTECT Cloud instance from will be the only one you can use to activate or delete the instance.
Create a new ESET PROTECT Cloud instance
1. Open the ESET Business Account and log in (or create a new account ).
2. Click Licenses > Enter License Key.
20
3. In the Add License pop-up window, enter your ESET PROTECT Cloud License key and click Add License.
21
4. You will receive a verification email. Click Verify license.
5. In the Dashboard, click Activate under ESET PROTECT Cloud.
Warning
Check the language setting of your ESET Business Account. Some ESET PROTECT Cloud main program window elements are defined the first time you set the language in your ESET Business
Account language settings, and cannot be changed later.
6. An Activate ESET PROTECT Cloud window will open. Read the Terms of Use and select the check box if you agree.
7. Select a data center location for your ESET PROTECT Cloud instance that is the closest to the location of your managed network and click Continue.
Warning
After selected, you will not able to change the data center location of your ESET PROTECT Cloud instance.
8. Your ESET PROTECT Cloud instance will be created. You can wait for a few minutes until it is created or you can log out and you will be notified by email when the ESET PROTECT Cloud instance is available.
9. Click Continue. Alternatively, click Dashboard, click Open in the ESET PROTECT Cloud tile to open a new
tab with ESET PROTECT Cloud Web Console
.
Create a new ESET PROTECT Cloud user in ESET Business Account
1. Log in to your ESET Business Account account.
2. Select User Management > New User.
22
3. Fill in the required fields (read more in the ESET Business Account Online Help ):
I.
General - Provide basic information about the user
II.
Access Rights: a) Company Access - Select user's level of company access: Write, Read, Access only to selected
sites.
b) User Management Access - Select the check box to allow user to manage other users in ESET
Business Account.
c) ESET PROTECT Cloud Access:
• Write - User has full access to ESET PROTECT Cloud.
• Read - User can only view the data in ESET PROTECT Cloud.
• Custom - You can define user access later in ESET PROTECT Cloud in Permission Sets.
• No access - User has no access to ESET PROTECT Cloud.
Important
To access ESET PROTECT Cloud, a user must have Write or Read access rights to at least one company with eligible (active) ESET PROTECT Cloud license.
III.
Preferences - Set user's language for ESET Business Account and ESET PROTECT Cloud and set the time zone.
IV.
Security - Adjust security settings for the user (password expiration, idle session timeout, two-factor verification).
Click Create to create the user.
23
4. The new user appears in the User Management with the Waiting for activation label.
24
5. The user will receive an activation email (to the email address you specified when creating the user). The user must click Activate your account.
6. The user needs to adjust the user settings and type the password twice (Create password and Confirm
password), select the check box I agree to the ESET Terms of Use and click Activate the account.
25
7. Log in to your ESET Business Account account. Use the account from step 1; do not use the newly created user account yet.
8. Open the ESET PROTECT Cloud Web Console. Click More > Users > select Mapped ESET Business
Accounts > click the Add New button.
9. Click Select under ESET Business Account identifier.
26
10. Select the user you created in the previous steps and click OK.
11. Select the user's Home group and click Continue.
12. In Permission Sets, you can see the permissions level that you assigned to the user in step 3. If you selected Custom ESET PROTECT Cloud Access in step 3, you need to assign a permission set to the user (an existing one or you can
). Click Finish.
27
13. Users that were granted the access to ESET PROTECT Cloud will see the option to open ESET PROTECT Cloud in their ESET Business Account.
ESET PROTECT Cloud Web Console
ESET PROTECT Cloud Web Console is the main interface used to communicate with ESET PROTECT Cloud Server.
You can think of it as a control panel, a central place where you can manage all of your ESET security solutions. It
is a web-based interface that can be accessed using a browser (see Supported Web browsers
) from any place and any device with internet access. When you log into the Web Console the first time, a
In the ESET PROTECT Cloud Web Console standard layout:
• The current user is always shown in the upper right, where the timeout for his/her session counts down. You can click Logout to log out at any time. When a session times out (because of user inactivity), a user must log in again. To change
, click your username in top right corner of ESET PROTECT Cloud Web
Console.
• The
is accessible on the left at all times except when using a wizard. Click the to expand the menu on the left side of the screen; you can collapse it by clicking Collapse.
• If you need help when working with ESET PROTECT Cloud, click the Help in the top right corner and click
<Current topic> - Help. The respective help window for the current page will be displayed.
• At the top of the ESET PROTECT Cloud Web Console, you can use the Quick Search tool. Click the icon to select a search target: o Computer Name, Description and IP Address - Type a Client name, Computer description,
IPv4/IPv6 Address, or Group name and press Enter. You will be redirected to the Computers section
where the results will be displayed.
o
o
User Name - You can search for imported AD users, results will be displayed in the Computer Users
section.
• Click the Quick Links button to view the menu:
Quick links
Set up Computers
• Startup Wizard (Live installer)
28
Manage Computers
• Create Client Task
• Download Migration Policy
Manage Licenses
• Go To Business Account
• Manage Access Rights
• Manage Licenses
• The icon always denotes a context menu.
• Click Refresh to reload/refresh displayed information.
• Buttons on the bottom of the page are unique for each section and function, and are described in detail in their respective chapters.
•
Click the ESET PROTECT Cloud logo to open the Dashboard screen.
recommended steps.
29
Screens with trees have specific controls. The tree itself is on the left with actions below. Click an item from the tree to display options for that item.
Tables allow you to manage units from rows individually, or in a group (when more rows are selected). Click a row to display options for units in that row. Data in tables can be
Objects in ESET PROTECT Cloud can be edited using wizards. All wizards share the following behaviors:
30
• Steps are vertically oriented from top to bottom.
• You can return to any step at any time.
• Required (mandatory) settings are always marked with a red exclamation mark next to the section and the respective settings.
• Invalid input data is marked when you move your cursor to a new field. The wizard step containing invalid input data is marked as well.
• Finish is not available until all input data is correct.
Login screen
We recommend that you log into ESET PROTECT Cloud via ESET Business Account. From ESET Business Account you can open ESET PROTECT Cloud directly. This is the recommended login method because this way you will be logged into ESET Business Account and ESET PROTECT Cloud simultaneously. While it is also possible to log in to
ESET PROTECT Cloud directly from the ESET PROTECT Cloud login, you may experience issues with certain functions that require you to be logged into ESET Business Account.
ESET Business Account login credentials (username and password) are used for both of the methods mentioned above.
Note
If you experience problems logging in or receive error messages while trying to log in, see
Console Troubleshooting for suggestions to resolve your issue.
The language of login screen and ESET PROTECT Cloud Web Console can be changed in ESET Business Account
User Settings > Language.
Note
Keep in mind that not all elements of the Web Console will change after the language change. Some of the elements are created during the initial configuration of your ESET PROTECT Cloud instance and cannot be changed.
31
Forgotten Password allows you to recover forgotten password to your account.
Session management and security measures:
Login IP address lockout
After 10 unsuccessful login attempts from the same IP address, further login attempts from this IP address are blocked for approximately 15 minutes. The IP address ban on login attempts does not affect existing sessions. This is indicated by the error message: Login failed: Login from your address was temporarily blocked.
Using the Startup Wizard
When you log into the Web Console for the first time, a Startup Wizard for ESET PROTECT Cloud will appear and you can use it to deploy ESET Management Agents to computers in your network.
You can create an ESET PROTECT Live Installer package containing ESET Management Agent and an ESET security product for Windows or MacOS. To deploy ESET Management Agent to Linux computers, use the
.
Follow the steps below to create an ESET PROTECT Live Installer package:
1. On the Welcome screen of the Startup Wizard click Continue.
32
33
2. Package Contents - Select if you want:
• Management Agent only installer
• Management Agent and Security Product
• License - Select a license from the list of available licenses appropriate for the security product installer you are creating. This license will be used to activate the ESET security product during installation.
• Product - Select an ESET security product that will be installed together with ESET Management Agent. By default, the latest product version is selected. To select an older version, click the gear icon next to product name and click Select previous version.
• Security product configuration (optional) - click Select Policy and select a policy that will be applied on the ESET security product during its installation.
• Language - Select the language version of the ESET security product installer.
• Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
• Protection settings - select the check box next to the setting to enable it for the installer: o The ESET LiveGrid® feedback system o Detection of Potentially Unwanted Applications - read more in our Knowledgebase article .
o Do not define Protection settings right now - select this check box if you do not want to define these protections setting for the installer and you want to set them via policy later.
• Deselect the check box Participate in product improvement program if you do not agree to send crash reports and telemetry data to ESET. If the check box is left selected, telemetry data and crash reports will be sent to ESET.
• Full Disk Encryption - Encryption option is visible only with active ESET Full Disk Encryption license.
34
3. You can configure Advanced settings or continue to the next step.
• Installer name - Fill in the name for the installer.
• Description (Optional) - Enter additional information to help you identify the installer.
• Click Select tags to assign tags .
• Parent group (optional) - Select the Parent group where the computer will be placed after installation.
You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.
• ESET AV Remover - Select the check box to uninstall or completely remove other antivirus programs on the target device.
• Optionally, you can select a Policy that will be applied on the ESET security product during its installation.
• Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port,
Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address
of the machine where the HTTP Proxy
is running. HTTP Proxy uses the port 3128 by default. You can set a different port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT
Cloud Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
4. Click Continue to move to the deployment options.
5. You can deploy your installer locally in two ways:
a) After you select Show Live Installer download link you can Copy the download link, distribute it to users and let them download and install the ESET PROTECT Live Installer package. You can also Download the ESET PROTECT Live Installer package and distribute it personally or upload it to a shared location for the users to access.
b) After you select Send Live Installer link via email you can use ESET PROTECT Cloud SMTP server to deliver an email message to a specified users containing the installer download link. You can specify the users by filling in the Email Address field (and optionally a name). To add multiple users at once, click Add
user (add address of the user from the Computer Users ), or Import CSV (
Import a custom list of addresses
from a CSV file structured with delimiters).
Important
The installer is not digitally signed, which might generate a web browser warning during installer download as well as generate operating system warning and prevent installation on systems where unsigned installers are blocked.
6. Run the installation package file on a client computer. It will install the ESET Management Agent and the
ESET security product on the device and connect the device to ESET PROTECT Cloud. For step-by-step instructions, see the setup wizard .
Note
You can run the installation package in a silent mode to hide the setup wizard window.
User settings
In this section, you can customize your user settings. Click User account at the top right corner of the ESET
PROTECT Cloud Web Console (to the left of the Logout button) to display all active users. You can be logged into
ESET PROTECT Cloud Web Console from different web browsers, computers or mobile devices at the same time.
You will see all your sessions here.
Note
User settings only apply to the user who is currently logged on. Each user can have their own preferred time settings for ESET PROTECT Cloud Web Console. User-specific time settings are applied to each user regardless of where they access ESET PROTECT Cloud Web Console.
Time Settings
All information is stored internally in ESET PROTECT Cloud using the UTC (Coordinated Universal Time) standard.
UTC time is automatically converted to the time zone used by ESET PROTECT Cloud Web Console (taking daylight saving into account). ESET PROTECT Cloud Web Console displays the local time of the system where ESET
PROTECT Cloud Web Console is running (not the internal UTC time). You can override this setting to set the time shown in ESET PROTECT Cloud Web Console manually.
If you want to override the default Use Browser Local Time setting, you can choose the Select manually option, then specify the console time zone manually and decide whether to use daylight saving time or not.
35
Important
In some cases, the option to use a different time zone will be made available. When configuring a trigger, ESET PROTECT Cloud Web Console time zone is used by default. Alternatively, you can select the check box Use Server Local Time to use local time zone on server instead of ESET PROTECT
Cloud Console time zone for the trigger.
Click Save Time Settings to confirm your changes.
Stored User State
, table column sizes, remembered filters, pinned side menu, etc.
Active sessions
Information about all active sessions of the current user contain:
• IP address of a client computer or a device from which a user is connected to ESET PROTECT Cloud Web
Console.
• Date and time when a user logged in.
• Selected language for ESET PROTECT Cloud Web Console.
36
The current session is labeled This session.
Filters and layout customization
The ESET PROTECT Cloud Web Console allows you to customize the layout of displayed items in the main sections
(e.g. Computers, Tasks, etc.) in several ways:
Add filter and filter presets
To add filtering criteria, click Add filter and select item(s) from the list. Enter the search string(s) into the filter field(s). Active filters are highlighted in blue.
Filters can be saved to your user profile so that you can use them again in the future. Under Presets, the following options are available:
Filter sets
Save filter set
Manage filter sets
Clear filter values
Remove filters
Remove unused filters
Your saved filters, click one to apply it. The applied filter is denoted with a check mark.
Select Include visible columns, sorting and paging to save these parameters to the preset.
Save your current filter configuration as a new preset. Once the preset is saved, you cannot edit the filter configuration in the preset.
Remove or rename existing presets. Click Save to apply the changes to presets.
Click to remove only the current values from the selected filters. Saved presets will remain unchanged.
Click to remove the selected filters. Saved presets will remain unchanged.
Remove filter fields with no value.
The Access Group filter button allows users to select a static group and filter viewed objects according to the group where they are contained.
You can use
for filtering the displayed items.
Side panel layout
Click the icon next to the section name and adjust the side panel layout using the context menu (available options may vary based on the current layout):
• Hide side panel
• Show side panel
• Groups
• Groups and Tags
• Tags
If Groups are visible, you can select also one of these options:
• Expand All
• Collapse All
Manage the main table
To reorder a column, hover the mouse over the icon next to the column name and drag-and-drop the column.
See also Edit columns below.
37
For sorting by a single column, click the column header to sort table rows based on data in the selected column.
• One click or two clicks result in ascending (A-Z, 0-9) or descending (Z-A, 9-0) sorting.
• After you apply the sorting, a small arrow before column header indicates the sorting behavior.
• See also multiple sorting below.
Click the gear icon to manage the main table:
Actions
• Edit columns - Use the wizard to adjust ( add, remove, can also use drag-and-drop to adjust the columns.
reorder) the displayed columns. You
• Auto-fit columns - Automatically adjust columns width.
Table Sorting
• Reset Sorting - Reset the column sorting.
• Multiple Sorting - You can sort table data by selecting multiple (up to 4) columns. For each of the columns, you can adjust its: o sorting priority - change column order by clicking the Move Up or Move Down button (the first column: primary sorting; the second column - secondary sorting; etc.). After you apply multiple sorting, index numbers appear before column headers to indicate the sorting priority.
o sorting behavior - select Ascending or Descending from the drop down menu.
38
Example
1 primary sorting - Computer Name column: ascending sorting applied.
2 secondary sorting - Status column: descending sorting applied as secondary sorting.
Reports
Tags
• Export table as - Export the table as a report in your desired format. You can choose from .pdf
or .csv
.
CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
• Save a report template - Create a new report template from the table.
ESET PROTECT Cloud allows marking all relevant objects (computers, detections, tasks, installers, policies, notifications, licenses, etc.) with user defined tags, which can be further used for enhanced filtering and search.
Tagging is integrated natively in all major screens of ESET PROTECT Cloud Web Console.
Tags are user defined key words (labels) that you can add to different objects to make them easier for grouping, filtering and finding. For example, you can assign a tag 'VIP' for your relevant assets and quickly identify all objects that are associated with them.
39
You can create and assign tags manually.
Tags pane
You can see the existing tags in the Tags section visible on the bottom left side of the ESET PROTECT Cloud Web
Console menu screen:
Permissions for tags management
In order to manage tags for an object, a
needs to have the sufficient access rights (assigned permission set
) to the object. Additional users can manage tags, i.e. another user can delete a tag that you have created.
Assign tags
You can assign tags to one or more objects.
To assign tags, select the check box(es) next to the object(s) and click Actions > Tags:
To assign already existing tags, click into the typing field a tag from the list and click Apply.
40
Create a new tag
To create a new tag, type in the tag name, select Create "tag_name" and then click Apply.
Filter objects by tags
Click a tag to apply a filter to the listed objects. The selected tags are blue.
Unassign tags
To assign tags, select the check box(es) next to the object(s) and click Actions > Tags. Remove the tag by clicking the X and click Apply.
Delete a tag
To delete a tag, hover the mouse over the tag in the Tags pane, click the icon and click OK to confirm that you want to delete the tag from all objects in the ESET PROTECT Cloud Web Console.
41
Import CSV
Importing of a list can be done using custom .csv file with a proper structure. This function is used at various menus across ESET PROTECT Cloud user interface. Depending on what shall be imported, columns are changed.
1. Click Import CSV.
2. Upload - click Choose File, browse for the .csv
file you would like to upload and then click Upload.
3. Delimiter - a delimiter is a character that is used to separate text strings. Select an appropriate delimiter
(Semicolon, Comma, Space, Tab, Dot, Vertical bar) to match what your .csv
file uses. If your .csv
file uses different character as delimiter, select the check box next to Other and enter the character. Data
preview shows the contents of your .csv
file which can help you identify the type of delimiter used to separate strings.
4. Column mapping - once the .csv
file has been uploaded and parsed, you can map each desired column in the imported .csv
file to a ESET PROTECT Cloud column displayed in the table. Use the drop-down lists to select which CSV column should be associated with a specific ESET PROTECT Cloud column. If your .csv
file does not have a header row, deselect First line of CSV contains headings.
5. See the Table preview to make sure the column mapping is set correctly and the import operation will work the way you want.
6. Once you have successfully mapped each of the columns and the table preview looks correct, click
Import to begin the operation.
42
Troubleshooting - Web Console
Because ESET PROTECT Cloud is hosted in the cloud, most of the errors that can occur during login can be solved by following these general troubleshooting steps: o Clear the browser cache and refresh the login page.
o
).
o If the problem is not resolved, contact ESET Support.
The table below will give you some insight into the most common Web Console login error massages and statuses, what they mean and some additional troubleshooting steps:
Error message
Login failed: Communication from your address was temporary blocked
Possible cause
Repeated authentication attempts with incorrect data were detected.
Your IP address is being blocked for 15 minutes. After 15 minutes try to log in using the correct credentials.
Login failed: Authentication error
Login failed: Authentication failed on server
Login failed: Connection has failed with state 'Not connected'
The server received a damaged or incomplete authentication token.
Make sure you are using the correct login credentials and that your connection to the login page is secure. If the problem persists, try clearing the cookies.
Check network connection and firewall settings to make sure ESET
PROTECT Cloud Web Console can be reached from your device.
Login failed: Communication error
Login failed: Connection timeout
43
Error message
Login failed: User has no access rights assigned
JavaScript is disabled. Please enable
JavaScript in your browser.
You do not see the login screen or the login screen appears to be constantly loading.
"An unexpected error has occurred" or
"An uncaught exception has occurred"
Possible cause
The user account under which you are trying to log in does not have any access rights assigned. Log in as an administrator and edit the user's account assigning appropriate permissions to this user. If you do not have access to the administrator account , contact your administrator with this request.
JavaScript is required for the login page to work correctly. Enable
JavaScript or update your web browser
.
Check network connection and firewall settings to make sure ESET
PROTECT Cloud Web Console can be reached from your device.
This error can occurs when you are accessing the ESET PROTECT Cloud
Web Console from a browser that is not supported by ESET PROTECT
Cloud Web Console, see supported web browsers .
Synchronize ESET PROTECT Cloud with Active Directory
Use the ESET Active Directory Scanner to synchronize Active Directory computers with the ESET PROTECT
Cloud Web Console.
Important
Active Directory Scanner cannot synchronize Active Directory users. This functionality will be added later.
Prerequisites
• Run the Active Directory Scanner as an Active Directory user on a computer connected to Active Directory.
• Supported operating systems (support for HTTP/2): Windows 10, Windows Server 2016 and later.
• Download and install .NET Core Runtime .
Using the Active Directory Scanner
1.
In the ESET PROTECT Cloud Web Console, create the Agent GPO deployment script .
2. Log in to a computer in your Active Directory with an Active Directory user account. Make sure it meets the prerequisites listed above.
3. Download the latest Active Directory Scanner to the computer.
4. Unzip the downloaded file.
5. Download the Agent GPO deployment script (created in step 1) and copy it to the ActiveDirectoryScanner folder (a folder containing all Active Directory Scanner files).
6. In the ESET PROTECT Cloud Web Console, go to Computers and select the Static Group where you want to synchronize the Active Directory structure.
7. Click the gear icon next to the selected Static Group, select Active Directory Scanner and copy the generated access token.
Important
• Each Static Group has its own token. The token identifies the Static Group where the Active
Directory will be synchronized.
• To invalidate the current token for security reasons, click Regenerate to create a new token. If the
Active Directory synchronization with ESET PROTECT Cloud is already running, the synchronization will stop after the change of security token. You must run the Active Directory Scanner with the new token to re-enable the Active Directory synchronization.
44
8. Run the Active Directory Scanner (replace token_string with the token you copied in the previous step).
ActiveDirectoryScanner.exe --token token_string
Note
By default, the latest Active Directory Scanner does not synchronize disabled Active Directory computers. To synchronize disabled Active Directory computers, use the --disabled-computers parameter:
ActiveDirectoryScanner.exe --token token_string --disabled-computers
9. When requested, type the Active Directory user password.
10. After the Active Directory Scanner completes the synchronization, your Active Directory structure
(organizational units with computers) will appear in Computers in the ESET PROTECT Cloud Web Console as
Static Groups with computers.
Note
The Active Directory Scanner creates an Active Directory Synchronization task in the Windows
Task Scheduler with a trigger repeat interval set to 1 hour. You can adjust the Active Directory synchronization interval in the Task Scheduler based on your preference. Any future changes to your
Active Directory structure will be reflected in the ESET PROTECT Cloud Web Console after the next synchronization.
Important
Active Directory synchronization limitations: o Active Directory Scanner synchronizes only Active Directory organizational units that contain computers with DNS names. Organizational units that do not contain any computers will not be synchronized.
o If the organizational unit name changes in Active Directory, a new Static Group with the new name will be created in the ESET PROTECT Cloud Web Console after the next synchronization. The Static
Group corresponding to the old organizational unit name will remain the ESET PROTECT Cloud Web
Console and it will be empty (computers will move to the new Static Group with the new name).
o If you delete an organizational unit in Active Directory, all computers in the unit will be removed from the corresponding Static Group in the ESET PROTECT Cloud Web Console.
o If you delete a synchronized Active Directory computer from the ESET PROTECT Cloud Web
Console, it will not re-appear after the next synchronization, even though it remains in the Active
Directory.
To see the Active Directory Scanner help, use one of these parameters: -? -h --help.
45
For troubleshooting purposes, view the logs located in C:\ProgramData\ESET\ActiveDirectoryScanner\Logs.
Workaround solutions
46
Alternatively, you can use one of the workaround solutions below:
• Export the list of computers from Active Directory and import it to ESET PROTECT Cloud
•
Deploy the ESET Management Agent to Active Directory computers using a Group Policy Object
Export the list of computers from Active Directory and import it to
ESET PROTECT Cloud
Important
This solution provides a one-time Active Directory synchronization only and does not synchronize any future Active Directory changes.
1. Export the list of computers from Active Directory. You can use various tools, depending on how you manage
Active Directory. For example, open the Active Directory Users and Computers and under your domain, rightclick Computers and select Export List.
2. Save the list of exported Active Directory computers as a .txt
file.
3. Modify the list of computers to make the formatting acceptable for ESET PROTECT Cloud import. Make sure that each line contains one computer and has the following format:
\GROUP\SUBGROUP\Computer name 4. Save the updated .txt
file with the list of computers.
5. Import the list of Active Directory computers to the ESET PROTECT Cloud Web Console. Click Computers > click the gear icon next to the All Static Group and select
Deploy the ESET Management Agent to Active Directory computers using a Group Policy Object
1.
Create the Agent GPO deployment script
.
2. Deploy the ESET Management Agent using a Group Policy Object (GPO) - start with the step 3 in our
Knowledgebase article .
3. After the successful ESET Management Agent deployment via GPO, the ESET Management Agent will be installed on Active Directory computers and computers will appear in the ESET PROTECT Cloud Web Console Computers screen.
Anytime you add a new computer to Active Directory in the future, it will appear in the ESET PROTECT Cloud Web
How to manage Endpoint products from ESET PROTECT Cloud
Before you can start managing ESET Business Solutions you need to perform initial configuration. We recommend that you use
, especially if you have skipped the
. Administrator can perform variety of tasks from the ESET PROTECT Cloud Web Console in order to install products and control client computers.
Installation of ESET Management Agent and Endpoint security products
ESET PROTECT Cloud requires that theESET Management Agent to be installed on each managed client computer.
The ESET Management Agent can be installed in combination with your Endpoint security product. Before installation, we recommend that you import your license into ESET Business Account so it can be used for your consequent installations. There are two methods to install your Endpoint product:
• Use the
Agent and ESET security product installer or
ESET Remote Deployment Tool to install your Endpoint
product and ESET Management Agent at the same time.
using a Client Task.
Managing the Endpoint security product from ESET PROTECT Cloud
All Endpoint security products can be managed from ESET PROTECT Cloud Web Console. Policies are used to apply
localities, change scanner settings detection sensitivity (available in Endpoint 7.2 and later), or change all other
ESET security settings. Policies can be merged
, as shown in our
. Policies set using ESET PROTECT Cloud cannot be overwritten by a user on a client machine. However, the administrator can use the
allow a user to make changes on a client temporarily. When you are finished making changes, you can
request the final configuration from the client and save it as a new policy.
can also be used to manage clients. Tasks are deployed from the Web Console and executed on the client by the ESET Management Agent. The most common Client Tasks for Windows Endpoints are:
(also updates the virus database)
•
• Run custom
• Request the computer and product
Reporting the computer status and getting information from clients to ESET PROTECT Cloud
Each client computer is connected to ESET PROTECT Cloud through ESET Management Agent. The Agent reports all requested information about the client machine and its software to the ESET PROTECT Cloud Server. All logs from Endpoints or other ESET security products are sent to the ESET PROTECT Cloud Server.
Information about installed ESET products and other basic information about a client's OS and status can be found in Computers. Select a client and click Show Details. In the Configuration section of this window, a user can look up older configurations or request current configuration. In the SysInspector section, a user can request logs
(from Windows computers only).
Web Console also allows you to access a list of all detections
from client devices. Detections from a single device can be viewed in Computers. Select a client and click Show Details > Detections and Quarantine .
You can generate custom
reports on-demand or using a scheduled task to view data about clients in your network.
. Examples of reports include aggregated information about computers, detections, quarantine and necessary updates.
48
Important
A user can only use report templates for which he has sufficient
templates are stored in the group All. A report can only include information about computers and events within that user's permission scope. Even if a report template is shared among more users, each user's report will only contain information about devices for which that user has permission. See
the list of permissions for more information on access rights.
ESET Push Notification Service
ESET Push Notification Service (EPNS) serves for receiving messages from the ESET PROTECT Cloud, if ESET
PROTECT Cloud has a notification for the client. The connection is running so that ESET PROTECT Cloud can send a
(push) notification to a client immediately. When the connection is broken, client tries to reconnect. The main reason for the permanent connection is to make clients available to receive messages.
A Web Console user can send Wake-Up calls via EPNS between the ESET PROTECT Cloud Server and ESET
Management Agents.
Connection details
To configure your local network to allow communication with EPNS, ESET Management Agents need to be able to connect to the EPNS server. If you cannot establish a connection with EPNS for your Agents, only Wake-Up calls are affected.
Connection details
Transport security SSL
Protocol
Port
MQTT (machine-to-machine connectivity protocol)
• primary: 8883
• fallback: 443 and the proxy port set by the ESET Management Agent policy
Port 8883 is preferred, as it is an MQTT port. The 443 is only a fallback port and it is shared with other services. Also, a firewall can abort the connection on port 443 because of inactivity or maximum opened connections limit for the HTTP Proxy server.
Host address epns.eset.com
Proxy compatibility If you use HTTP Proxy for forwarding communication, Wake-Up calls are also sent through
HTTP Proxy. Authentication is not supported. Make sure to configure HTTP Proxy in Agent policy on computers where you want to send the Wake-up calls. In case HTTP Proxy is not working, Wake-up calls are sent directly.
VDI, cloning and hardware detection
ESET PROTECT Cloud supports VDI environments, cloning of machines and non-persistent storage systems. This
feature is necessary to set up a flag for the master computer or resolve a question
which appears after cloning or a change of hardware.
• Until the question is resolved, the client machine is unable to replicate to the ESET PROTECT Cloud. Client only checks if the question is resolved.
• Disabling hardware detection is irreversible, use it with the highest caution and only on physical machines!
• When resolving multiple
, use the
Status Overview - Questions tile.
Which OSs and hypervisors are supported?
Warning
Before you start using VDI with ESET PROTECT Cloud, read more about supported and unsupported features of various VDI environments in our Knowledgebase article .
• Only
Windows operating systems are supported.
• ESET Virtual Agent Hosts are not supported.
• ESET Full Disk Encryption is not supported.
49
• Mobile devices managed via Cloud MDM are not supported.
• Linked clones in Virtual Box cannot be distinguished from one another.
• In very rare cases, detection can be switched off automatically by the ESET PROTECT Cloud. This happens
when ESET PROTECT Cloud is not able to reliably analyze the hardware .
• See the list of supported configurations: o Citrix PVS 7.0+ with physical machines o Citrix PVS 7.0+ with virtual machines in Citrix XenServer 7+ o Citrix PVS 7.0+ and Citrix XenDesktop with Citrix XenServer 7+ o Citrix Machine Creation Services o (without PVS) Citrix XenDesktop with Citrix XenServer 7+ o VMWare Horizon 7.x and 8.0 with VMWare ESXi (instant clones are not supported) o Microsoft SCCM (for re-imaging)
VDI environments
You can use Master machine with ESET Management Agent for a VDI pool. There is no VDI connector needed; all communication is handled via ESET Management Agent. ESET Management Agent must be installed on the Master machine before the VDI pool (machine catalog) is set up.
• If you want to create a VDI pool, flag the Master computer in
> Hardware before creating the pool. Select Mark as Master for Cloning (Match with existing computer).
• If the Master computer is removed from the ESET PROTECT Cloud, recovery of its identity (cloning) is forbidden. New machines from the pool would get a new identity each time (new machine entry is created in the Web Console).
• When a machine from the VDI pool connects for the first time, it has a mandatory 1 minute connection interval. After the first few replications the connection interval is inherited from the master.
• Never disable hardware detection when using the VDI pool.
• You can have the master machine running along with the cloned computers, so you can keep it updated.
Default group for VDI machines
New machines cloned from the Master goes to the Lost and found static group. This cannot be altered.
Cloning machines on hypervisor
Create new computer only this time.
50
Imaging of systems to physical machines
You can use a Master image with ESET Management Agent installed and deploy it on physical computers. There are two ways to accomplish this:
1. System creates a new machine in ESET PROTECT Cloud after each image deployment.
•
Resolve each new computer manually in Questions and select Create a new computer every time.
• Flag the Master machine before cloning. Select Mark as Master for Cloning (Create a new computer).
2. System creates a new machine in ESET PROTECT Cloud after the image is deployed on a new machine. If the image is re-deployed on a machine with previous history in ESET PROTECT Cloud (that already had ESET
Management Agent deployed), this machine is connected to its previous identity in ESET PROTECT Cloud.
•
Resolve each new computer manually in Questions and select Match with an existing computer every
time.
• Flag the master machine before cloning. Select Mark as Master for Cloning (Match with existing
computer).
Warning
If you have an image (or a template) of your master computer, make sure to keep it updated. Always update the image after upgrade or re-installation of any ESET components on the master machine.
51
Parallel replication
ESET PROTECT Cloud Server can recognize and resolve parallel replication of multiple machines to a single identity
identical Agent ID'). There are two ways to resolve this issue:
• Use the
available on the alert. Computers are divided, and their hardware detection is permanently turned off.
• In rare cases, even computers with switched-off hardware detection can conflict. In such cases the
Reset cloned agent task is the only option.
•
Run the Reset cloned agent task
on the machine. This keeps you from having to disable hardware detection.
Resolving cloning questions
Every time a machine connects to the ESET PROTECT Cloud, an entry is created based on two fingerprints:
• an ESET Management Agent UUID (universally unique identifier) - It changes after the ESET Management
Agent is re-installed on a machine (see Double Agent situation ).
•
- It changes if the machine is cloned or redeployed.
A question is displayed if the ESET PROTECT Cloud Server detects one of the following:
• a cloned device connecting
• a change of hardware in an existing device with ESET Management Agent installed
Important
detection is not supported on:
• Linux, macOS, Android, iOS
• systems managed via ESET Virtual Agent Hosts (ESET Virtualization Security)
• machines without ESET Management Agent
Click the question and select Resolve question to open a menu with the following options:
New computers are being cloned or imaged from this computer
52
Match with the existing computer every time
Create a new computer every time
Create a new computer this time only
Select this option when:
• You use the computer as a master and all its images should connect to the existing computer entry in ESET
PROTECT Cloud.
• You use the computer as a master to set up a VDI environment and the computer is in VDI pool and is expected to recover its identity based on a hardware fingerprint ID.
Select this option when you use this computer as a master image and you want ESET PROTECT Cloud to automatically recognize all clones of this computer as new computers. Do not use with VDI environments.
Computer is cloned only once. Select to create a new instance for the cloned device.
KB article
KB article
KB article
No computers are cloned from this computer, but its hardware has changed
Accept changed hardware every time
Disable the hardware detection permanently for this device. Use only if nonexistent hardware changes are reported.
Warning
This action is irreversible!
If you disable the hardware detection, both Agent and Server store this setting. Re-deployment of the Agent does not restore the disabled HW detection. Machines with disabled hardware detection are not suitable for the VDI scenarios in ESET PROTECT
Cloud.
Accept changed hardware only this time
Select to renew the hardware fingerprint of the device. Use this option after the hardware of the client computer is changed. Future hardware modifications will be reported again.
Click Resolve to submit the selected option.
Double Agent situation
If an ESET Management Agent is uninstalled (but computer is not removed from Web Console) on the client machine and installed again, there are two same computers in the Web Console. One is connecting to the Cloud
53
and the other one is not. This situation is not handled by the Questions dialog window. Such a situation is the
result of incorrect agent removal procedure . The only solution is to manually
remove the not connecting computer from the Web Console. The history and logs created before the re-installation will be lost afterward.
Using the Delete not connecting computers task
If you have a VDI pool of computers and you did not resolve the question (see above) correctly, the Web Console creates a new computer instance after reloading of the computer from the pool. Computer instances stack up in the Web Console and licenses can get overused. We do not recommend to solve it by setting up a
also be overused.
Overused licenses
When a client computer with installed ESET Management Agent and activated ESET security product gets cloned, each cloned machine can claim another license seat. This process can overuse your licenses. In VDI environments, use an offline license file for the activation of ESET products and contact ESET to modify your license.
Notifications for cloned computers
There are three prepared notifications user can use for cloning-related actions, change of hardware or user can create a new custom notification using cloning-related events. To set up a
Notifications menu in the Web Console.
• New Computer Enrolled – Notify if a computer is connected for the first time to the selected static group
(the group All is selected by default).
• Computer Identity Recovered – Notify if a computer was identified based on its hardware. The computer was cloned from a Master machine or other known source.
• Potential Computer Cloning Detected – Notify about a significant hardware modification or cloning if the source machine was not flagged as a Master before.
Hardware identification
ESET PROTECT Cloud is gathering hardware details about each managed device and tries to identify it. Every device connected to ESET PROTECT Cloud belongs to one of the following categories, displayed in the column
Hardware identification, in the Computers window.
• Hardware detection enabled – detection is enabled and working fine.
• Hardware detection disabled – detection was disabled by the user or automatically by ESET PROTECT
Cloud Server.
• No hardware information – no hardware information is available, either the client device is running unsupported OS or old version of ESET Management Agent.
• Hardware detection unreliable – the detection is reported by the user to be unreliable, and it is going to be disabled. This status can occur only during the single replication interval before the detection is disabled.
Apache HTTP Proxy
Apache HTTP Proxy is a proxy service that can be used to distribute updates to client computers.
Using Apache HTTP Proxy offers the following benefits:
• Downloads and caches: o detection engine updates o activation tasks - communication with activation servers and caching of license requests o ESET PROTECT Cloud repository data o product component updates
54
o and then distributes them to endpoint clients on your network.
• Decreases internet traffic on your network.
• Compared to the Mirror Tool, which downloads all available data on ESET update servers, Apache HTTP Proxy downloads only data requested by ESET PROTECT Cloud components or ESET endpoint products to reduce network load. If an endpoint client requests an update, Apache HTTP Proxy downloads it from ESET update servers, saves the update to its cache directory and serves it to the particular endpoint client. If another endpoint client requests the same update, Apache HTTP Proxy serves the download to the client directly from cache, so there is no additional download from ESET update servers.
Note
What are the differences between various Proxies?
Important
You can use a
proxy chain , to add another proxy service to a remote location. Note that ESET
PROTECT Cloud does not support proxy chaining when proxies require authentication. You can use your own transparent web proxy solution, however there may be additional configuration required beyond what is mentioned here.
Apache HTTP Proxy installation and cache
Note
You can choose to install
Squid as an alternative to Apache HTTP Proxy.
To install
Apache HTTP Proxy on Windows, follow these steps:
1. Visit the ESET PROTECT Cloud download section to download a standalone installer for this ESET PROTECT
Cloud component ( apachehttp.zip
).
2. Open ApacheHttp.zip and extract the files to C:\Program Files\Apache HTTP Proxy
Note
If you want to install Apache HTTP Proxy on a different hard drive, C:\Program Files\ must be replaced with the corresponding path in the instructions below and in the httpd.conf file located in the Apache
HTTP Proxy\bin directory. For example, if you extract the content of ApacheHttp.zip to D:\Apache
Http Proxy, then C:\Program Files\ must be replaced with D:\Apache Http Proxy.
3. Open an administrative command prompt and change directory to C:\Program Files\Apache HTTP Proxy\bin
4. Execute the following command: httpd.exe -k install -n ApacheHttpProxy
5. Using a text editor such as Notepad, open the httpd.conf file and add the following lines at the bottom of the file:
55
ServerRoot "C:\Program Files\Apache HTTP Proxy"
DocumentRoot "C:\Program Files\Apache HTTP Proxy\htdocs"
<Directory "C:\Program Files\Apache HTTP Proxy\htdocs">
Options Indexes FollowSymLinks
AllowOverride None
Require all granted
</Directory>
CacheRoot "C:\Program Files\Apache HTTP Proxy\cache"
Note
If you wish the cache directory to be located somewhere else, for example on another disk drive, such as D:\Apache HTTP Proxy\cache , then in the last line of the code above change
"C:\Program Files\Apache HTTP Proxy\cache" to "D:\Apache HTTP Proxy\cache" .
6. Start the ApacheHttpProxy service using the following command: sc start ApacheHttpProxy
7. You can verify that the Apache HTTP Proxy service is running in the services.msc
snap-in (look for
ApacheHttpProxy). By default, the service is configured to start automatically.
Follow the steps below to configure a username and password for Apache HTTP Proxy
(recommended):
1. Stop the ApacheHttpProxy service by opening an elevated command prompt and executing the following command: sc stop ApacheHttpProxy
2. Verify the presence of the following modules in C:\Program Files\Apache HTTP Proxy\conf\httpd.conf:
LoadModule authn_core_module modules\mod_authn_core.dll
LoadModule authn_file_module modules\mod_authn_file.dll
LoadModule authz_groupfile_module modules\mod_authz_groupfile.dll
LoadModule auth_basic_module modules\mod_auth_basic.dll
3. Add the following lines to C:\Program Files\Apache HTTP Proxy\conf\httpd.conf under <Proxy *> :
56
AuthType Basic
AuthName "Password Required"
AuthUserFile password.file
AuthGroupFile group.file
Require group usergroup
4. Use the htpasswd command to create a file named password.file
in the folder Apache HTTP Proxy\bin\
(you will be prompted for password): htpasswd.exe -c ..\password.file username
5. Manually create the file group.file
in the folder Apache HTTP Proxy\ with the following content: usergroup:username
6. Start the ApacheHttpProxy service by executing the following command in an elevated command prompt: sc start ApacheHttpProxy
7. Test the connection to HTTP Proxy by accessing the following URL in your browser: http://[IP address]:3128/index.html
Note
Once you have successfully completed installation of Apache HTTP Proxy, you have the option to allow ESET communication only (blocking all other traffic - default) or allow all traffic. Perform the necessary configuration changes as described here:
• Forwarding for ESET communication only
The following command will display a list of content which is currently cached:
"C:\Program Files\Apache HTTP Proxy\bin\htcacheclean.exe" -a -p "C:\ProgramData\Apache HTTP Proxy\cache"
Use the htcacheclean tool to clean up the disk cache. See the recommended command below (setting cache size to 20 GB and cached files limit to ~128000):
"C:\Program Files\Apache HTTP Proxy\bin\htcacheclean.exe" -n -t^
-p"C:\ProgramData\Apache HTTP Proxy\cache" -l20000M -L128000
To schedule cache clean up every hour run: schtasks /Create /F /RU "SYSTEM" /SC HOURLY /TN ESETApacheHttpProxyCleanTask^
/TR "\"C:\Program Files\Apache HTTP Proxy\bin\htcacheclean.exe\"^
-n -t -p \"C:\ProgramData\Apache HTTP Proxy\cache\" -l20000M -L128000"
If you choose to allow all traffic, the recommended commands are:
57
"C:\Program Files\Apache HTTP Proxy\bin\htcacheclean.exe" -n -t^
-p"C:\ProgramData\Apache HTTP Proxy\cache" -l20000M
schtasks /Create /F /RU "SYSTEM" /SC HOURLY /TN ESETApacheHttpProxyCleanTask^
/TR "\"C:\Program Files\Apache HTTP Proxy\bin\htcacheclean.exe\"^
-n -t -p \"C:\ProgramData\Apache HTTP Proxy\cache\" -l20000M"
Note
The ^ character right after end of line in the commands above is essential, if it is not included the command will not execute correctly.
For more information, visit our Knowledgebase article or the Apache Authentication and Authorization documentation .
Squid installation and HTTP Proxy cache
Squid is an alternative to Apache HTTP Proxy . To install Squid on Windows, follow these steps:
1. Download the Squid MSI installer and install Squid.
2. Click the Squid for Windows icon in the tray menu and select Stop Squid Service.
3. Navigate to the Squid installation folder, for example C:\Squid\bin, and run the following command from command line: squid.exe -z -F
This creates the swap directories for cache.
4. Click the Squid for Windows icon in the tray menu and select Open Squid Configuration.
5. Replace http_access deny all with http_access allow all .
6. Enable disk caching by adding this line: cache_dir aufs /cygdrive/c/Squid/var/cache 3000 16 256
Note
• You can change the location of the cache directory based on your preferences. In the example, the cache directory is located in C:\Squid\var\cache (note the path format in the command).
• You can change the total cache size (3000 MB in the example) and the number of first-level subdirectories (16 in the example) and second-level sub-directories (256 in the example) in the cache directory.
7. Save and close the Squid configuration file squid.cofn.
8. Click the Squid for Windows icon in the tray menu and select Start Squid Service.
9. You can verify that the Squid service is running in the services.msc
snap-in (look for Squid for
Windows).
Apache HTTP Proxy installation - Linux
Choose the installation steps for
according to the Linux distribution you use on your server.
Linux installation (distribution generic) for Apache HTTP Proxy
1. Install Apache HTTP Server (at least version 2.4.10).
2. Verify that the following modules are loaded: access_compat, auth_basic, authn_core, authn_file, authz_core, authz_groupfile, authz_host, proxy, proxy_http, proxy_connect, cache, cache_disk
58
3. Add the caching configuration:
CacheEnable disk http://
CacheDirLevels 4
CacheDirLength 2
CacheDefaultExpire 3600
CacheMaxFileSize 200000000
CacheMaxExpire 604800
CacheQuickHandler Off
CacheRoot /var/cache/apache2/mod_cache_disk
4. If the directory /var/cache/apache2/mod_cache_disk does not exist, create it and assign Apache privileges
(r,w,x).
5. Add Proxy configuration:
ProxyRequests On
ProxyVia On
<Proxy *>
Order deny,allow
Deny from all
Allow from all
</Proxy>
6. Enable the added caching proxy and configuration (if configuration is in the main Apache configuration file, you can skip this step).
7. If necessary, change listening to your desired port (port 3128 is set by default).
8. Optional basic authentication: o Add authentication configuration to the proxy directive:
AuthType Basic
AuthName "Password Required"
AuthUserFile /etc/apache2/password.file
AuthGroupFile /etc/apache2/group.file
Require group usergroup o Create a password file using htpasswd.exe -c o Manually create a file named group.file with usergroup:username
9. Restart the Apache HTTP Server.
Ubuntu Server 14.10 and other Debian-based Linux distributions installation of Apache HTTP Proxy
1. Install the latest version of Apache HTTP Server from apt repository: sudo apt-get install apache2
2. Execute the following command to load the required Apache modules: sudo a2enmod access_compat auth_basic authn_core authn_file authz_core\ authz_groupfile authz_host proxy proxy_http proxy_connect cache cache_disk
3. Edit the Apache caching configuration file: sudo vim /etc/apache2/conf-available/cache_disk.conf
59
and copy/paste the following configuration:
CacheEnable disk http://
CacheDirLevels 4
CacheDirLength 2
CacheDefaultExpire 3600
CacheMaxFileSize 200000000
CacheMaxExpire 604800
CacheQuickHandler Off
CacheRoot /var/cache/apache2/mod_cache_disk
4. This step should not be required, but if the caching directory is missing, run following commands: sudo mkdir /var/cache/apache2/mod_cache_disk sudo chown www-data /var/cache/apache2/mod_cache_disk sudo chgrp www-data /var/cache/apache2/mod_cache_disk
5. Edit the Apache proxy configuration file: sudo vim /etc/apache2/conf-available/proxy.conf
and copy/paste the following configuration:
ProxyRequests On
ProxyVia On
<Proxy *>
Order deny,allow
Deny from all
Allow from all
</Proxy>
6. Enable the configuration files you edited in earlier steps: sudo a2enconf cache_disk.conf proxy.conf
7. Switch the listening port of Apache HTTP Server to 3128. Edit the file /etc/apache2/ports.conf and replace
Listen 80 with Listen 3128 .
8. Optional basic authentication: sudo vim /etc/apache2/mods-enabled/proxy.conf
o Copy/paste authentication configuration before </Proxy> :
AuthType Basic
AuthName "Password Required"
AuthUserFile /etc/apache2/password.file
AuthGroupFile /etc/apache2/group.file
Require group usergroup o Install apache2utils and create a new password file (for example username: user , group: usergroup ): sudo apt-get install apache2-utils sudo htpasswd -c /etc/apache2/password.file user
60 o Create a file called group: sudo vim /etc/apache2/group.file
and copy/paste the following line: usergroup:user
9. Restart the Apache HTTP Server using the following command: sudo service apache2 restart
Forwarding for ESET communication only
To allow forwarding of ESET communication only, remove the following:
<Proxy *>
Order deny,allow
Deny from all
Allow from all
</Proxy>
And add the following:
<Proxy *>
Deny from all
</Proxy>
#*.eset.com:
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?([a-zA-Z0-9-]{0,63}\.)?[a-zA-Z0-9-]{0,63}\.[e,E][s,S][e,E][t,T]\.[c,C][o,O][m,M](:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#*.eset.eu:
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?([a-zA-Z0-9-]{0,63}\.)?[a-zA-Z0-9-]{0,63}\.[e,E][s,S][e,E][t,T]\.[e,E][u,U](:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#Antispam module (ESET Mail Security only):
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(ds1-uk-rules-1.mailshell.net|ds1-uk-rules-2.mailshell.net|ds1-uk-rules-3.mailshell.net|fh-uk11.mailshell.net)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#Services (activation)
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(edf-pcs.cloudapp.net|edf-pcs2.cloudapp.net|edfpcs.trafficmanager.net)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#ESET servers accessed directly via IP address:
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(91.228.165.|91.228.166.|91.228.167.|38.90.226.)([0-9]+)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
To allow forwarding of all communication, add the following:
<Proxy *>
Order deny,allow
Deny from all
Allow from all
</Proxy> and remove the following:
61
<Proxy *>
Deny from all
</Proxy>
#*.eset.com:
ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?([a-zA-Z0-9-]{0,63}\.)?[a-zA-Z0-9-]{0,63}\.[e,E][s,S][e,E][t,T]\.[c,C][o,O][m,M](:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#*.eset.eu:
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?([a-zA-Z0-9-]{0,63}\.)?[a-zA-Z0-9-]{0,63}\.[e,E][s,S][e,E][t,T]\.[e,E][u,U](:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#Antispam module (ESET Mail Security only):
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(ds1-uk-rules-1.mailshell.net|ds1-uk-rules-2.mailshell.net|ds1-uk-rules-3.mailshell.net|fh-uk11.mailshell.net)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#Services (activation)
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(edf-pcs.cloudapp.net|edf-pcs2.cloudapp.net|edfpcs.trafficmanager.net)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
#ESET servers accessed directly via IP address:
<ProxyMatch ^([h,H][t,T][t,T][p,P][s,S]?://)?([^@/]*@)?(91.228.165.|91.228.166.|91.228.167.|38.90.226.)([0-9]+)(:[0-9]+)?(/.*)?$>
Allow from all
</ProxyMatch>
Proxy chaining (all traffic)
ESET PROTECT Cloud does not support proxy chaining when proxies require authentication. You can use your own transparent web proxy solution, however there may be additional configuration required beyond what is mentioned here. Add the following to the proxy configuration (password is working only on child proxy):
ProxyRemote * http://IP_ADDRESS:3128
Squid HTTP Proxy installation on Ubuntu Server
You can use the Squid proxy instead of Apache on the Ubuntu Server. To install and configure Squid on the Ubuntu
Server (and similar Debian-based Linux distributions), follow the steps below:
1. Install the Squid3 package: sudo apt-get install squid3
2. Edit the Squid configuration file /etc/squid3/squid.conf and replace:
#cache_dir ufs /var/spool/squid3 100 16 256 with: cache_dir ufs /var/spool/squid3 3000 16 256 max-size=200000000
Note
• You can change the total cache size (3000 MB in the example) and the number of first-level subdirectories (16 in the example) and second-level sub-directories (256 in the example) in the cache directory.
• Parameter max-size defines the maximum cached file size in bytes.
3. Stop the squid3 service.
sudo service squid3 stop sudo squid3 –z
62
4. Edit the Squid configuration file again and add http_access allow all before http_access deny all to allow all clients to access the proxy.
5. Restart the squid3 service: sudo service squid3 restart
ESET Management Agent Deployment
This section describes all available methods you can use to deploy ESET Management Agent on the client computers in your network. It is very important because ESET security solutions running on client computers communicate with ESET PROTECT Cloud Server exclusively through the Agent.
ESET Management Agent deployment
ESET Management Agent deployment can be performed in a few different ways. You can deploy the Agent locally or remotely:
•
- Install ESET Management Agent and ESET security product locally on a client computer.
Note
We recommend that you only use local deployment if you have a small network (up to 50 computers). For larger networks, you can
Deploy ESET Management Agent using GPO or SCCM
.
•
- we recommend that you use this method to deploy ESET Management Agent on large number of client computers.
Add computers using RD Sensor
The easiest way to find an unmanaged computer in your network structure is to use RD Sensor. RD Sensor monitors the network in which it is deployed and when a new device without an Agent connects to the network it reports this information to the ESET PROTECT Cloud. The RD Sensor component cannot be deployed with ESET
PROTECT Live Installer. To deploy RD Sensor into your network, follow the
RD Sensor Installation steps .
In Reports, go to section Computers and click the Rogue computers report.
The Rogue computers report lists computers found by the RD Sensor. You can adjust the information reported by
63
RD Sensor with the RD Sensor policy .
To add computers found by RD Sensor to ESET PROTECT Cloud, download the report in .csv format and use this list in
in
option.
The results of the RD Sensor scan are written to a log file called detectedMachines.log
. It contains a list of discovered computers on your network. You can find the detectedMachines.log
file here:
• Windows
C:\ProgramData\ESET\Rogue Detection Sensor\Logs\detectedMachines.log
• Linux
/var/log/eset/RogueDetectionSensor/detectedMachines.log
ESET Rogue Detection Sensor policy settings
It is possible to change the behavior of ESET RD Sensor using a policy. This is mostly used to change the filtering of addresses. You can, for example, include certain addresses in the blacklist so they are not detected.
Click Policies and expand Custom Policies to edit an existing policy or create a new one.
Filters
IPv4 Filter
Enable IPv4 address filtering - By enabling filtering, only computers whose IP addresses are part of the
Whitelist in the IPv4 filter list will be detected, or only those that are not part of the Blacklist.
Filters - Specify whether the list will be a Whitelist or Blacklist.
IPv4 address list - Click Edit IPv4 list to add or remove addresses from the list.
MAC address prefix filter
64
Enable MAC address prefix filtering - By enabling filtering, only computers whose MAC address prefix
(xx:xx:xx) addresses are part of the MAC address list will be detected, or only those that are not part of the
Blacklist.
Filtering mode - Specify whether the list will be a Whitelist or Blacklist.
MAC address prefix list - Click Edit MAC prefix list to add or remove a prefix from the list.
Detection
Active detection - Enabling this option will allow the RD Sensor to search the local network for computers actively. This can improve search results but it can also trigger firewall warnings on some machines.
OS detection ports - RD Sensor uses a pre-configured list of ports to search the local network for computers. You can edit the port list.
Advanced Settings
Diagnostics - Enable or disable the submission of anonymous crash report statistics to ESET for the improvement of customer experience.
Assign
Specify the clients that will receive this policy. Click Assign to display all Static and Dynamic Groups and their members. Select the computer that you want to apply a policy on and click OK.
Summary
Review the settings for this policy and click Finish.
RD Sensor installation
To install the RD Sensor component on Windows, follow these steps:
1. Visit the ESET PROTECT Cloud download section to download a standalone installer for this ESET PROTECT
Cloud component ( rdsensor_x86.msi
or rdsensor_x64.msi
).
2.
Make sure all prerequisites are met.
3. Double-click the RD Sensor installer file to begin installation.
4. After accepting the EULA, click Next.
5. Deselect the check box next to Participate in product improvement program if you do not agree to send crash reports and telemetry data to ESET. If the check box is left selected, telemetry data and crash reports will be sent to ESET.
6. Select the location where RD Sensor will be installed and click Next > Install.
RD Sensor prerequisites
The following prerequisites must be met in order to install the RD Sensor component on Windows:
• WinPcap - use the latest WinPcap version (at least 4.1.0)
• Network should be properly configured (appropriate
ports open, incoming communication not being blocked
by a firewall, etc.)
• ESET PROTECT Cloud instance reachable
• ESET Management Agent must be installed on the local computer to fully support all program features
• Rogue Detection Sensor log file can be found here: C:\ProgramData\ESET\Rouge Detection Sensor\Logs\
Local deployment
This deployment method is intended for on-premises installations. Create or download an installation package and allow access to it via via a shared folder, flash drive or email.
65
Important
The installer package must be installed by an Administrator or a user with Administrator privileges.
Note
We recommend that you only use local deployment if you have a small network (up to 50 computers). For larger networks, you can
Deploy ESET Management Agent using GPO or SCCM
.
Navigate to the Installers section and select the desired installer package.
Local deployment can be performed in these ways:
•
Create Agent (and ESET security product) installer (Windows only)
•
Create Agent Installer (Linux)
•
Create Agent Installer (macOS)
Important
ESET Management Agent comes pre-configured for proper connection to ESET PROTECT Cloud, therefore only limited modifications to ESET Management Agent settings are available via ESET
Management Agent Policy.
Create Agent (and ESET security product) installer
The procedure of creating an All-in-one installer (including ESET Management Agent and an ESET security product)
package is similar to a Startup Wizard .
Important
The installer package is an .exe
file and is valid for Microsoft Windows operating systems only.
Follow the steps below to create an ESET PROTECT Live Installer package:
Basic
Deselect the check box Participate in product improvement program if you do not agree to send crash reports and telemetry data to ESET. If the check box is left selected, telemetry data and crash reports will be sent to ESET.
Package contents - Select the check box(es) from the following options:
• Management Agent - Include only the ESET Management Agent. Select this option if you want to install the ESET security product on the client computer later, or if the client computer already has an ESET security product installed.
• Security Product - Include the ESET security product with the ESET Management Agent. Select this option if the client computer does not have any ESET security product installed and you want to install it with the
ESET Management Agent.
• Full Disk Encryption - Encryption option is visible only with active ESET Full Disk Encryption license.
Security Product
• License - Select a license from the list of available licenses appropriate for the security product installer you are creating. This license will be used to activate the ESET security product during installation.
• Product - Select an ESET security product that will be installed together with ESET Management Agent. By default, the latest product version is selected. To select an older version, click the gear icon next to product name and click Select previous version.
• Language - Select the language version of the ESET security product installer.
66
• Optionally, you can select a Policy that will be applied on the ESET security product during its installation.
• Protection settings - select the check box next to the setting to enable it for the installer: o The ESET LiveGrid® feedback system o Detection of Potentially Unwanted Applications - read more in our Knowledgebase article .
o Do not define Protection settings right now - select this check box if you do not want to define these protections setting for the installer and you want to set them via policy later.
• Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
Advanced
In this section, you can customize the All-in-one installer package:
• Optionally, you can change the Name and enter a Description for the package installer.
• Click Select tags to assign tags .
• Parent group (optional) - Select the Parent group where the computer will be placed after installation.
You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.
• ESET AV Remover - Select the check box to uninstall or completely remove other antivirus programs on the target device.
• Initial installer configuration (Optional) - Use this option if you want to apply
ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of
the existing ones.
• Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port,
Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address of the machine where the
HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a
different port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Cloud
Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
• Click Finish. You can deploy your installer locally in two ways: a) After you select Show download link you can Copy the download link, distribute it to users and let them download and install the ESET PROTECT Live Installer package. You can also Download the ESET PROTECT
Live Installer package and distribute it personally or upload it to a shared location for the users to access.
b) After you select Send installer link to users you can use ESET PROTECT Cloud SMTP server to deliver an email message to a specified users containing the installer download link. You can specify the users by filling in the Email Address field (and optionally a name). To add multiple users at once, click Add user (add
address of the user from the Computer Users ), or Import CSV (
Import a custom list of addresses from a
CSV file structured with delimiters).
Important
The installer is not digitally signed, which might generate a web browser warning during installer download as well as generate operating system warning and prevent installation on systems where unsigned installers are blocked.
Run the installation package file on a client computer. It will install the ESET Management Agent and the ESET
67
security product on the device and connect the device to ESET PROTECT Cloud. For step-by-step instructions, see the setup wizard .
Note
• You can run the installation package in a silent mode to hide the setup wizard window.
• After creation, ESET PROTECT Live Installer will behave according to
.
ESET PROTECT Live Installer behavior
After the ESET PROTECT Live Installer is created, it is stored in ESET PROTECT Cloud and will behave as described in the table below.
Action
ESET PROTECT Live Installer is deleted from ESET PROTECT
Cloud
ESET PROTECT Live Installer is not present in repository anymore.
Policy that is part of ESET
PROTECT Live Installer is edited.
Policy that is part of ESET
PROTECT Live Installer is deleted.
Behavior of ESET PROTECT Live
Installer download link
Download link is disabled.
Download link is disabled. Selected
package is not in repository is displayed next to installer.
The change in Policy will not reflect in existing copies of ESET PROTECT Live
Installer and the download link will offer the installer with policies defined when it was initially created.
If you want the changes to reflect in the installer, you will need to create a new installer with this updated Policy.
The referenced policy is not
accessible warning will be displayed next to the installer and the download link will be disabled. Duplicate the installer and assign a new policy to it.
Behavior of downloaded ESET
PROTECT Live Installer
ESET PROTECT Live Installer copies downloaded before deletion will stop working.
ESET PROTECT Live Installer copies downloaded before edits will stop working.
The installer will function but it will install your ESET product with policies defined when it was initially created.
ESET PROTECT Live Installer copies downloaded before deletion will stop working.
Group that is part of ESET
PROTECT Live Installer is edited.
Group that is part of ESET
PROTECT Live Installer is deleted.
This change will not affect existing installers and the computer will be assigned to the updated/moved group once it connects to ESET PROTECT
Cloud.
The installer will behave as if there was no group assigned to the installer at all. It will be assigned to the default Lost&Found group.
ESET PROTECT Live Installer lifetime
ESET PROTECT Live Installer installers are valid for 6 months after being created. To refresh the download link of an existing installer, navigate to
Installers, select the existing installer and select Show Download Link.
Download a valid installer from the new download link.
Agent Installer - Linux
This wizard will help you create .sh
script for ESET Management Agent deployment on Linux computers.
Follow the steps below to create an Agent live installer script for Linux:
1. Fill in the Name and Description of the installer.
2. Click Select tags to assign tags .
3. Parent group (optional) - Select the Parent group where the computer will be placed after installation. You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.
68
4.
Initial installer configuration (Optional) - Use this option if you want to apply configuration policy
to
ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of available policies. If none of the pre-defined policies are suitable, you can create
or customize the existing ones.
5. Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
6. Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address of the machine where the
HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a different
port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Cloud
Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
7. Select Save & Download to save the configuration and download the installation script or Save and close to save the configuration for later.
Note
ESET Management Agent from version – Windows: 7.2.1266.0, Linux: 7.2.2233.0, macOS: 7.2.3261.0
– and later, supports auto-upgrade functionality.
ESET Management Agent auto-upgrade is triggered two weeks after the newer version of ESET
Management Agent is released into the repository if the upgrade was not initiated by the
Administrator. The auto-upgrade is designed to assure that the upgrade process is phased and distributed during a longer period to prevent an increased impact on the network and managed workstations.
Deployment Agent Linux
Installation of the ESET Management Agent component on Linux is performed using a command in the Terminal.
Make sure all
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Cloud
Server that requires authentication will not work.
Follow the steps below for Agent installation on Linux workstation.
1. Extract the .sh file from the .gz archive.
2. The ESET Management Agent installation .sh file must be set as an executable (run chmod +x on the file to set this).
3. Execute the .sh file.
4. When prompted, enter the local admin password. (or run the installer as sudo
./ecaagentinstaller.sh
).
5. The computer with installed Agent will appear in your ESET PROTECT Cloud Web Console.
Agent prerequisites - Linux
The following prerequisites must be met in order to install the ESET Management Agent component on Linux:
69
• The computer must be reachable from the network.
• The ESET Management Agent installation file must be set as an executable (run chmod +x on the file to set this)
• We recommend that you use the latest OpenSSL version (1.1.1). The minimum supported version of
OpenSSL is openssl-1.0.1e-30. There can be more versions of OpenSSL installed on one system in the same time. At least one supported version must be present on you system.
o You can use the command openssl version to show current default version.
o You can list all versions of OpenSSL present on your system. See the file names endings listed using the command sudo find / -iname *libcrypto.so* o Fedora Linux users should use compat-openssl10 package.
Note
For Linux CentOS it is recommended to install the policycoreutils-devel package. Run the command to install the package: yum install policycoreutils-devel
Agent Installer - macOS
This wizard will help you create .sh
script for ESET Management Agent deployment on macOS computers.
Follow the steps below to create an Agent live installer script for macOS:
1. Fill in the Name and Description of the installer.
2. Click Select tags to assign tags .
3. Parent group (optional) - Select the Parent group where the computer will be placed after installation. You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.
4.
Initial installer configuration (Optional) - Use this option if you want to apply configuration policy
to
ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of available policies. If none of the pre-defined policies are suitable, you can create
or customize the existing ones.
5. Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
6. Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address of the machine where the
HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a different
port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Cloud
Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
7. Select Save & Download to save the configuration and download the installation script or Save and close to save the configuration for later.
70
Note
ESET Management Agent from version – Windows: 7.2.1266.0, Linux: 7.2.2233.0, macOS: 7.2.3261.0
– and later, supports auto-upgrade functionality.
ESET Management Agent auto-upgrade is triggered two weeks after the newer version of ESET
Management Agent is released into the repository if the upgrade was not initiated by the
Administrator. The auto-upgrade is designed to assure that the upgrade process is phased and distributed during a longer period to prevent an increased impact on the network and managed workstations.
8. Run the installation package file on a client computer. It will install the ESET Management Agent and the
ESET security product on the device and connect the device to ESET PROTECT Cloud. For step-by-step instructions, see the setup wizard .
Remote deployment
Important
For remote deployments, verify all client computers have an internet connection.
Remote deployment can be performed in the following ways:
• Group Policy Object (GPO) and System Center Configuration Manager (SCCM)
- we recommend this method for mass deployment of the ESET Management Agent on client computers.
Should you experience problems when deploying the ESET Management Agent remotely, see
.
Agent deployment using GPO and SCCM
Center Configuration Manager (SCCM), Symantec Altiris or Puppet for remote deployment of Agent.
Important
For remote deployments, verify all client computers have an internet connection.
Follow the steps below to deploy the ESET Management Agent to clients using GPO or SCCM:
Navigate to Installers > Create Installer > GPO or SCCM script.
You can customize the ESET Management Agent installation package:
1. Enter the Name and Description (optional) of the installation package.
2. Click Select tags to assign tags .
3. Parent group (optional) - Select the Parent group where the computer will be placed after installation.
You can select an existing static group or create a new static group to which the device will be assigned after the installer is deployed.
4. Initial installer configuration (Optional) - Use this option if you want to apply
ESET Management Agent. Click Select under Agent configuration (optional) and choose from the list of
the existing ones.
5. Deselect the check box Participate in product improvement program if you do not agree to send crash reports and telemetry data to ESET. If the check box is left selected, telemetry data and crash reports will be sent to ESET.
6. Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port,
Username and Password) to download the installer via Proxy and set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud
71
Server. Read more about Proxy
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT Cloud
Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
7. Click Save & Download and download the Configuration script and Agent.
Click the appropriate link below to view step-by-step instructions for two popular ESET Management Agent deployment methods:
1. Deployment of ESET Management Agent using Group Policy Object (GPO) - This Knowledgebase article may not be available in your language.
2. Deployment of ESET Management Agent using System Center Configuration Manager (SCCM)
Deployment steps - SCCM
To deploy ESET Management Agent using SCCM
, continue with the following steps:
1. Put the ESET Management Agent installer .msi
files and install_config.ini file on a shared folder.
72
Important
Client computers will require read/execute access to this shared folder.
73
2. Open SCCM console and click Software Library. In Application Management right-click Applications and choose Create Application. Choose Windows Installer (*.msi file).
74
3. Specify all required information about the application and click Next.
75
4. Right-click the ESET Management Agent Application, click the Deployment Types tab, select the only deployment there and then click Edit.
76
5. Click the Requirements tab and then click Add. Select Operating system from the Condition dropdown menu, select One of from the Operator drop-down menu and then specify the operating systems you will install to by selecting the appropriate check box(es). Click OK when you are finished and then click OK to close any remaining windows and save your changes.
77
78
6. In the System Center Software Library, right-click your new application and select Distribute Content from the context menu. Follow the prompts in the Deploy Software Wizard to complete deployment of the application.
79
80
7. Right-click the application and choose Deploy. Follow the wizard and choose the collection and destination where you want to deploy the agent.
81
82
83
84
85
86
ESET Remote Deployment Tool
The ESET Remote Deployment Tool is a convenient way to distribute the installer package
created by ESET
PROTECT Cloud to deploy ESET Management Agent and ESET security products remotely on computers over a network.
The ESET Remote Deployment Tool is available for free on the ESET website as a standalone ESET PROTECT Cloud
Component. The deployment tool is meant mainly for deployment on small to medium networks and is executed under admin privileges.
Note
The ESET Remote Deployment Tool is dedicated to deploy ESET Management Agent to client
Microsoft Windows operating systems only.
Important
ESET Management Agent comes pre-configured for proper connection to ESET PROTECT Cloud, therefore only limited modifications to ESET Management Agent settings are available via ESET
Management Agent Policy.
To deploy the ESET Management Agent and ESET security product using this method, follow the steps below:
1. Download the ESET Remote Deployment Tool from ESET website.
87
2.
Make sure all prerequisites are met.
3. Run the ESET Remote Deployment Tool on client computer.
4. Select one of the following deployment options:
•
the Active Directory structure for subsequent import to ESET PROTECT Cloud.
•
Scan Network - You will need to provide IP ranges to scan computers in the network.
•
- You will need to provide list of hostnames or IP addresses.
•
Add computers manually - You will need to provide list of hostnames or IP addresses manually.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
ESET Remote Deployment Tool prerequisites
Important
For remote deployments, verify all client computers have an internet connection.
The following prerequisites must be met to use ESET Remote Deployment Tool on Windows:
• ESET PROTECT Cloud instance must be created and working.
• Appropriate ports must be opened. See ESET PROTECT Cloud Deployment Tool ports .
•
An ESET PROTECT Live Installer instance must be created and downloaded on to the local drive of the
device from which you are going to perform the remote deployment with Deployment Tool.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
Select computers from Active Directory
To continue ESET Management Agent and ESET security product deployment from the previous chapter :
1. Read and Accept the End User License Agreement and click Next.
2. Enter the Active Directory Server with IP address or hostname and Port you want to connect to.
3. Enter Username and Password to log into the Active Directory Server. If you select the check box next to
Use current user credentials, login credentials will be automatically completed.
4. Optionally, select the check box next to Export computer list for ESET PROTECT if you want to export the
Active Directory structure for subsequent import to ESET PROTECT Cloud.
Note
If a computer is in Active Directory, click Next and automatic login into the default Domain Controller will take place.
5. Select the check box next to the computers you want to add and click Next. Select the check box Include
subgroups to list all computers inside a selected group.
6. Selected computers for remote deployment will be displayed. Make sure all computers are added and then click Next.
88
Important
Make sure that all selected computers have the same platform (64-bit or 32-bit operating systems).
7. Click Browse and select the bundle installer package you created in ESET PROTECT or ESET PROTECT Cloud
Web Console. You can also select Use ESET offline install package (.dat file) created from the ESET
PROTECT Live Installer. If you do not have any additional security applications installed on your local computer, deselect the check box next to Use ESET AV Remover. ESET AV Remover can remove certain applications .
8. Enter login credentials for the target computers. If computers are members of a domain, enter domain
administrator credentials. If you log in with local administration credentials, it is necessary to disable remote UAC on the target computers . Optionally, you can select the check box next to Use current user
credentials and login credentials will be automatically completed.
9. Deployment method is used to execute programs on remote machines. Built-in method is a default setting which supports Windows error messages. PsExec is a third-party tool and it is an alternative to the built-in method. Select one of these options and click Next.
89
Important
If you have selected PsExec, the deployment will fail, because the tool is unable to accept the
PsExec EULA. For a successful deployment, open the command line and run the PsExec command manually.
10. When the installation is started, "Success" will be displayed. Click Finish to complete the deployment. If deployment fails, you can export a list of failed computers. Click Browse next the Export failed computers field, select a .txt
file to which you want to save the list and then click Export failed computer.
You can check the status log (C:\ProgramData\ESET\RemoteAdministrator\Agent\Logs\status.html) on the client machine to make sure ESET Management Agent is working properly.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
Scan the local network for computers
To continue ESET Management Agent and ESET security product deployment from the previous chapter :
1. Read and Accept the End User License Agreement and click Next.
2. Enter IP Ranges of the network in the form 10.100.100.10-10.100.100.250.
3. Select one of the following Scan methods:
• Ping scan - Looks for client computers with command ping .
Note
Some client computers in this network do not have to send a response to command ping because of firewall blocking the connection.
• Port scan - Uses port numbers to scan the network.
4. To find computers in the network, click Start scan.
5. Select the check box next to the computers you want to add and click Next.
6. Selected computers for remote deployment will be displayed. Make sure all computers are added and then click Next.
Important
Make sure that all selected computers have the same platform (64-bit or 32-bit operating systems).
7. Click Browse and select the bundle installer package you created in ESET PROTECT or ESET PROTECT Cloud
Web Console. You can also select Use ESET offline install package (.dat file) created from the ESET
PROTECT Live Installer. If you do not have any additional security applications installed on your local computer, deselect the check box next to Use ESET AV Remover. ESET AV Remover can remove certain applications .
8. Enter login credentials for the target computers. If computers are members of a domain, enter domain
administrator credentials. If you log in with local administration credentials, it is necessary to disable remote UAC on the target computers . Optionally, you can select the check box next to Use current user
credentials and login credentials will be automatically completed.
9. Deployment method is used to execute programs on remote machines. Built-in method is a default setting which supports Windows error messages. PsExec is a third-party tool and it is an alternative to the built-in method. Select one of these options and click Next.
90
Important
If you have selected PsExec, the deployment will fail, because the tool is unable to accept the
PsExec EULA. For a successful deployment, open the command line and run the PsExec command manually.
10. When the installation is started, "Success" will be displayed. Click Finish to complete the deployment. If deployment fails, you can export a list of failed computers. Click Browse next the Export failed computers field, select a .txt
file to which you want to save the list and then click Export failed computer.
You can check the status log (C:\ProgramData\ESET\RemoteAdministrator\Agent\Logs\status.html) on the client machine to make sure ESET Management Agent is working properly.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
Import a list of computers
To continue ESET Management Agent and ESET security product deployment from the previous chapter :
91
92
1. Read and Accept the End User License Agreement and click Next.
2. Select one of the following options:
• Text file (one computer per line): A file with hostnames or IP addresses. Each IP address or hostname must be on a separate line.
• Export from management console: A file with hostnames or IP addresses
.
3. Click Browse and select the file you would like to upload and then click Next.
4. Selected computers for remote deployment will be displayed. Make sure all computers are added and then click Next.
Important
Make sure that all selected computers have the same platform (64-bit or 32-bit operating systems).
5. Click Browse and select the bundle installer package you created in ESET PROTECT or ESET PROTECT Cloud
Web Console. You can also select Use ESET offline install package (.dat file) created from the ESET
PROTECT Live Installer. If you do not have any additional security applications installed on your local computer, deselect the check box next to Use ESET AV Remover. ESET AV Remover can remove certain applications .
6. Enter login credentials for the target computers. If computers are members of a domain, enter domain
administrator credentials. If you log in with local administration credentials, it is necessary to disable remote UAC on the target computers . Optionally, you can select the check box next to Use current user
credentials and login credentials will be automatically completed.
7. Deployment method is used to execute programs on remote machines. Built-in method is a default setting which supports Windows error messages. PsExec is a third-party tool and it is an alternative to the built-in method. Select one of these options and click Next.
Important
If you have selected PsExec, the deployment will fail, because the tool is unable to accept the
PsExec EULA. For a successful deployment, open the command line and run the PsExec command manually.
8. When the installation is started, "Success" will be displayed. Click Finish to complete the deployment. If deployment fails, you can export a list of failed computers. Click Browse next the Export failed computers field, select a .txt
file to which you want to save the list and then click Export failed computer.
You can check the status log (C:\ProgramData\ESET\RemoteAdministrator\Agent\Logs\status.html) on the client machine to make sure ESET Management Agent is working properly.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
Add computers manually
To continue ESET Management Agent and ESET security product deployment from the previous chapter :
1. Read and Accept the End User License Agreement and click Next.
2. Enter the hostnames or IP addresses manually and then click Next. Each IP address or hostname must be on a new line.
Important
Make sure that all selected computers have the same platform (64-bit or 32-bit operating systems).
3. Selected computers for remote deployment will be displayed. Make sure all computers are added and then click Next.
4. Click Browse and select the bundle installer package you created in ESET PROTECT or ESET PROTECT Cloud
Web Console. You can also select Use ESET offline install package (.dat file) created from the ESET
PROTECT Live Installer. If you do not have any additional security applications installed on your local computer, deselect the check box next to Use ESET AV Remover. ESET AV Remover can remove certain applications .
5. Enter login credentials for the target computers. If computers are members of a domain, enter domain
administrator credentials. If you log in with local administration credentials, it is necessary to disable remote UAC on the target computers . Optionally, you can select the check box next to Use current user
credentials and login credentials will be automatically completed.
6. Deployment method is used to execute programs on remote machines. Built-in method is a default setting which supports Windows error messages. PsExec is a third-party tool and it is an alternative to the built-in method. Select one of these options and click Next.
93
Important
If you have selected PsExec, the deployment will fail, because the tool is unable to accept the
PsExec EULA. For a successful deployment, open the command line and run the PsExec command manually.
7. When the installation is started, "Success" will be displayed. Click Finish to complete the deployment. If deployment fails, you can export a list of failed computers. Click Browse next the Export failed computers field, select a .txt
file to which you want to save the list and then click Export failed computer.
You can check the status log (C:\ProgramData\ESET\RemoteAdministrator\Agent\Logs\status.html) on the client machine to make sure ESET Management Agent is working properly.
Note
The deployment may fail due to a number of reasons. In case of any problems with deployment, read
.
ESET Remote Deployment Tool - troubleshooting
The ESET Remote Deployment Tool is available for free on the ESET website as a standalone ESET PROTECT Cloud
Component. The deployment tool is meant mainly for deployment on small to medium networks and is executed
94
under admin privileges.
Note
The ESET Remote Deployment Tool is dedicated to deploy ESET Management Agent to client
Microsoft Windows operating systems only.
The deployment may fail with several error messages and due to a number of reasons listed in the table below:
Error message
The network path was not
found (error code 0x35)
Possible causes
• Client is not reachable on the network, firewall blocks communication
• Inbound ports 135, 137, 138, 139 and 445 are not open in firewall on the client or Windows Firewall: Allow inbound file and printer sharing exception is not used
• Client's host name could not be resolved, use valid FQDN computer names
Access is denied (error code
0x5)
The user name or password is
incorrect (error code 0x52e)
The installation package is not supported by this
processor type (error code
1633)
The semaphore timeout period has expired
• When deploying from a server joined to a domain to a client joined to the domain, use credentials of a user that is member of Domain Admin group in format Domain\DomainAdmin
• When deploying from a server to a client that is not in the same domain, disable remote UAC filtering on target computer .
• When deploying from a server to a client that is not in the same domain, use credentials of a local user that is member of Administrators group in format
Admin. Target computer name will be automatically prepended to the login.
• No password set for administrator account
• Insufficient access rights
• ADMIN$ administrative share is not available
• IPC$ administrative share is not available
• Use simple file sharing is enabled
The installation package is not supported on this platform. Create and download the installation package with the correct platform (64-bit or 32-bit operating system) in ESET PROTECT Cloud Web Console.
Client cannot access the network share with deployment package because SMB
1.0 is disabled on the share.
Follow the appropriate troubleshooting steps according to the possible cause:
Possible cause
Client is not reachable on the network
Firewall blocks communication
Client's host name could not be resolved
No password set for administrator account
Troubleshooting steps
Ping the client from the ESET PROTECT Cloud Server; if you get a response, try to log on to the client machine remotely (for example, via remote desktop).
Check the firewall settings on both the server and the client, as well as any other firewall that exists between these two machines (if applicable).
After successful deployment, ports 2222 and 2223 are not open in firewall. Make sure that these ports are open on all firewalls between the two machines (client and server).
Possible solutions to DNS issues can include but are not limited to:
• Using the nslookup command of the IP address and hostname of the server and/or the clients having Agent deployment issues. The results should match the information from the machine. For instance, an nslookup of a hostname should resolve to the IP address that an ipconfig command shows on the host in question. The nslookup command will need to be run on the clients and the server.
• Manually examining DNS records for duplicates.
Set a proper password for the administrator account (do not use a blank password).
95
Possible cause
Insufficient access rights
ADMIN$ administrative share is not available
IPC$ administrative share is not available
Use simple file sharing is enabled
Troubleshooting steps
Try using the Domain Administrator's credentials when creating an Agent deployment task. If the client machine is in a Workgroup, use the local
Administrator account on that particular machine.
For Windows 7 and later, the Administrator user account must be activated in order to run the Agent deployment task. You can create a local user that is a member of
Administrators group or to enable built-in local Administrator account.
To activate the Administrator user account:
1. Open an administrative command prompt
2. Enter the following command: net user administrator /active:yes
The client machine must have the shared resource ADMIN$ activated. Make sure it is present among the other shares (Start > Control Panel > Administrative
Tools > Computer Management > Shared Folders > Shares).
Verify that the server can access IPC$ by issuing the following from a command prompt on the server: net use \\clientname\IPC$ where clientname is the name of the target computer.
If you are getting the Access denied error message and your environment is mixed (contains both a Domain and Workgroup), disable Use simple file sharing or Use Sharing Wizard on all machines that are having problems with Agent deployment. For example, in Windows 7 do the following:
• Click Start, type folder into the Search box, and then click Folder Options.
Click the View tab and in the Advanced settings box, scroll down the list and deselect the check box next to Use Sharing Wizard.
Agent protection
The ESET Management Agent is protected by a built-in self-defense mechanism. This feature provides the following: o Protection against modification of ESET Management Agent registry entries (HIPS) o Files that belong to ESET Management Agent cannot be modified, replaced, deleted or altered (HIPS) o ESET Management Agent process cannot be killed o The ESET Management Agent Service cannot be stopped, paused, disabled, uninstalled or otherwise compromised
Some of the protection is covered by the HIPS feature included in your ESET product.
Note
To ensure full protection of the ESET Management Agent, HIPS must be enabled on a client computer.
Password-protected setup
In addition to self-defense, you can password-protect access to the ESET Management Agent (available for
Windows only). When password-protection is configured, the ESET Management Agent cannot be uninstalled or repaired unless the correct password is provided. To set an ESET Management Agent password, you need to create the appropriate
policy for ESET Management Agent .
ESET Management Agent settings
You can configure specific settings for ESET Management Agent using a ESET Management Agent policy. There are no pre-defined policies for the ESET Management Agent. To create a ESET Management Agent policy, click
Policies > New Policy and in the Settings section select ESET Management Agent where you can adjust the following settings:
96
Advanced Settings
• HTTP Proxy - Use a
to facilitate internet traffic to clients on your network. Enable Use direct
connection if HTTP proxy is not available if you want to allow this fallback option.
• Operating System - Use the switches to report certain information or issues on the client computer.
• Product Improvement Program - Enable or disable transmission of crash reports and anonymous telemetry data to ESET.
• Logging - Set the log verbosity to determine the level of information that will be collected and logged, from Trace (informational) to Fatal (most important critical information). The latest ESET Management Agent
can be found on a client computer.
• Setup -
is a protection feature of ESET Management Agent (Windows only).
to enable ESET Management Agent Password protection. Once the policy is applied, ESET
Management Agent cannot be uninstalled or repaired unless a password is provided.
Important
If you forget this password, you will not be able to uninstall ESET Management Agent from the target machine.
Assign
Specify the clients that will receive this policy. Click Assign to display all Static and Dynamic Groups and their members. Select the computer that you want to apply a policy on and click OK.
Summary
Review the settings for this policy and click Finish.
Create a Policy to enable ESET Management Agent Password protection
Follow the steps below to create a new policy that will enforce a password to protect the ESET Management Agent.
When Password protected setup is used, ESET Management Agent cannot be uninstalled or repaired unless a password is provided. See
for more details.
Basic
Enter a Name for this policy. The Description field is optional.
Settings
Select ESET Management Agent from the drop-down list, expand Advanced settings, navigate to Setup and type the password into the Password protected setup field. This password will be required if someone is trying to uninstall or repair ESET Management Agent on a client computer.
Important
Make sure to record this password in a safe place, it is essential to enter the password to allow ESET
Management Agent uninstallation from the client computer. There is no other regular way of uninstalling ESET Management Agent without a correct password once Password protected setup policy is in place.
Assign
Specify the clients (individual computers or whole groups) that are the recipients of this policy.
97
Click Assign to display all Static and Dynamic Groups and their members. Select your desired clients and click OK.
Summary
Review the settings for this policy and click Finish. The policy gets applied on the targets after their next connection to ESET PROTECT Cloud Server (depending on the Agent connection interval).
98
Note
To apply the policy immediately, you can run the Send Wake-up Call action on targets in
Computers.
Troubleshooting - Agent connection
When a client computer does not appear to be connecting to your ESET PROTECT Cloud Server, we recommend that you perform ESET Management Agent troubleshooting locally on the client machine.
By default, the ESET Management Agent synchronizes with ESET PROTECT Cloud Server every 10 minutes.
Check the latest ESET Management Agent log file. You can find it here:
Windows C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs
Linux
/var/log/eset/RemoteAdministrator/Agent/
/var/log/eset/RemoteAdministrator/EraAgentInstaller.log
macOS
/Library/Application Support/com.eset.remoteadministrator.agent/Logs/
/Users/%user%/Library/Logs/EraAgentInstaller.log
• last-error.html – protocol (table) that displays the last error recorded while the ESET Management Agent is running.
• software-install.log – text protocol of the last remote installation task performed by the ESET
Management Agent.
• status.html – a table showing the current state of communication (synchronization) of ESET Management
Agent with ESET PROTECT Cloud Server. The log also contains HTTP Proxy configuration, a list of applied policies (including the applied exclusions), and a list Dynamic groups to which the device belongs.
• trace.log – a detailed report of all ESET Management Agent activity including any errors that have been recorded.
Note
To enable full logging, create a dummy file named traceAll without an extension in the same folder as a trace.log and then restart the ESET Management Agent service. This will enable full logging in the trace.log file.
The most common issues that can prevent the ESET Management Agent from connecting to the ESET PROTECT
Cloud Server is that DNS is not working properly, or ports are blocked by a firewall - check our
ESET PROTECT Cloud.
ESET PROTECT Cloud Main Menu
All clients are managed through the ESET PROTECT Cloud Web Console . You can access the ESET PROTECT
times except when using a wizard. Click the to expand the menu on the left side of the screen; you can collapse it by clicking Collapse.
The main menu on the left contains the main ESET PROTECT Cloud sections and the following items:
99
Dashboard
The dashboard is the default page displayed after you log into the ESET PROTECT Cloud Web Console for the first time. It displays pre-defined reports about your network. You can switch between dashboards using the tabs in the top menu bar. Each dashboard consists of several reports.
Dashboard manipulation
• Add - Click the symbol at the top of the dashboard header to add a new dashboard. Enter a name for the new dashboard and click Add dashboard to confirm. A new blank dashboard is created.
• Move - Click and drag the name of a dashboard to change its location relative to other dashboards.
• Customize - You can customize your dashboards by adding, modifying, resizing, moving and re-arranging reports.
• Set as default - Select the dashboard, click the gear icon next to Dashboard and select Set as
default.
Click the gear icon next to the selected dashboard title to get following options in the drop down menu:
Refresh page
Remove
Rename
Duplicate
Change Layout
Refresh the report templates in this dashboard.
Remove the dashboard.
Rename the dashboard.
Create a copy of the dashboard with the same parameters in user's home group.
Choose a new layout for this dashboard. The change will remove current templates from the dashboard.
Note
You cannot customize these default dashboards: Status Overview and Security Overview.
The following dashboards come pre-configured in ESET PROTECT Cloud:
100
Status Overview
The Status Overview dashboard is the default screen you see when you log into ESET PROTECT Cloud (unless you set another dashboard as the default one). It displays general information about your network.
• Device filters - Displays the number of managed devices based on last reported status. You can click each of the 4 tiles to open a filtered list of devices.
• Device status - Displays the number of managed devices based on the type security product installed in respective tabs. If no security product of that group is deployed, the tab will display an option to deploy the respective installer package.
• Connection status - Displays the list of last connections of managed devices.
• Product version status - Displays the ratio of up-to-date and outdated security product versions based on platform. By clicking the red graph that represents outdated applications, you can initiate an update by selecting Update installed ESET products. The ESET product in unknown status is installed, but its version is not recognized (for example, shortly after a new installation of ESET product).
• Management status - Displays the number of Managed & Protected (client devices with both ESET
Agent and a security product installed), Managed (client devices with only Agent), Unmanaged (client devices in your network that are known to ESET PROTECT Cloud but without Agent) and Rogue (client devices unknown to ESET PROTECT Cloud but detected by Rogue Detection Sensor).
• RSS feed - Displays an RSS feed from WeLiveSecurity and the ESET Knowledgebase Portal . When you click the gear icon in RSS feed, you can choose to Turn off feed autoplay, or turn off individual feed source, or Turn off RSS feed.
Security Overview
This dashboard provides overview of unresolved detections discovered in the last 7 days, including their severity, detection method, resolution status and top 10 computers/users with detections.
Computers
This dashboard gives you an overview of client machines, including their protection status, operating systems and update status.
Antivirus detections
Here you can see reports from the antivirus module of client security products, including active detections, detections in the last 7/30 days, and so on.
Firewall detections
Firewall events of the connected clients arranged according to their severity, time of reporting, etc.
ESET applications
This dashboard lets you view information about installed ESET applications.
Dynamic Threat Defense
If you are using the ESET Dynamic Threat Defense , you can find here an overview of useful ESET Dynamic Threat
Defense and ESET LiveGrid® reports.
Actions in a dashboard report
Re-size
Click to view a report in fullscreen mode.
Refresh
Refresh the report template.
Download
Change
Click Download to generate and download the report. You can choose from .pdf
or
.csv
. CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
Change the report template for another from the list of templates.
101
Edit report template Edit an existing report template. The same settings and options used for
creating a new report template apply.
Set Refresh Interval
Set up custom refresh interval for the template.
Schedule
Remove
- you can modify the schedule trigger ,
and report delivery. You can find all scheduled reports in the Scheduled reports tab.
Remove the report template from the dashboard.
Rename
This Cell
Rename the report template.
Choose a new layout for this dashboard. The change will remove current templates from the dashboard.
Permissions for Dashboard
A user must have the appropriate permission to work with Dashboards. Only report templates contained in a group where the user has
can be used in a Dashboard. If user has no rights assigned for Reports and
Dashboard, user will see no data in the Dashboard section. Administrator can see all data by default.
Important
• Read - User can list report templates and their categories. User can also generate reports based on report templates. User is able to read his dashboard.
• Use - User can modify his dashboard with available report templates.
• Write - Create / modify / remove templates and their categories.
All default templates are located in the All group.
Drill down
You can use the drill-down dashboard functionality to examine data in greater detail. It lets you interactively select specific items from a summary and view detailed data about them. Focus on the item of interest by "drilling down" from summary information in order to get more information about this particular item. There are usually multiple levels you can drill-down through.
There are several drill-down options:
• Show Detailed information - Computer name and description, Static Group name, etc. Displays original
(not aggregated) data for the clicked row.
• Show Only 'value' - Show only data with the selected level of severity: Information, Critical, Security risk,
Security notification, etc.
• Expand column 'value' - This will show aggregated information (usually for count or sum). For example, if there is just a number in the column and you click Expand column Computer, it will list all details about computers.
• Show In Computers page (all) - Redirects you to the Computers page (shows a result of 100 items only).
One-click actions
Reports with information about the discovered problems contain additional drill down options when you click the item in the table/chart:
• 'task to resolve the selected alert' - You can resolve the alert by selecting the suggested task that will run
ASAP.
If the alert cannot be resolved via a task, but it can be resolved by a policy setting, the following options are displayed:
o New Policy
• Search the Web - Triggers Google search for the selected alert. You can use this option if there is no suggested response (task or policy setting) to resolve the selected alert.
102
Note
The results you get using drill-down of other reports show the first 1,000 items only.
Click the Generate and Download button if you want to generate and download the report. You can choose from
or .csv
. CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
103
Computers
All client devices that have been added to ESET PROTECT Cloud are shown here and are divided into
. Each
device is assigned to a single static group
. Clicking a group from the list (on the left) will display the members
(clients) of this group in the right pane.
Unmanaged computers (clients on the network that do not have the ESET Management Agent or an ESET security product installed) usually appear in the Lost & found group. The status of a client that is shown in the
ESET PROTECT Cloud Web Console is independent from the settings of the ESET security products on the client.
That is why even if a certain status is not displayed on the client, it is still reported to the ESET PROTECT Cloud
Web Console. You can drag and drop clients to move them between groups.
Click button Add New and select:
• Computers - You can add computers to the selected static group.
• Mobile devices - You can
to the selected static group.
Click a device to open a new menu with actions available for that device. You can also select the check box next to a device and click the Actions button on the bottom bar. The Action menu will display different options depending on the type of device. Refer to the
for details about different icon types and statues. Click the number
of alerts in the Alerts column to see the list of alerts in the computer details section.
Last Connected displays the date and time of last connection of the managed device. The Last Connected information gets highlighted to indicate that the computer is not connecting: o Yellow (error) - computer is not connecting for 2-14 days.
o Red (warning) - computer is not connecting for more than 14 days.
Filtering the view
There are different ways to filter your view:
• Standard filter: To add filtering criteria, click Add filter and select item(s) from the list. Enter the search string(s) into the filter field(s). Active filters are highlighted in blue.
• You can filter by severity using the status icons: red - Errors, yellow - Warnings, green - OK and
gray - Unmanaged computers. The severity icon represents the current status of your ESET product on a particular client computer. You can use a combination of these icons by turning them on or off. For example, to see only the computers with warnings, leave only the yellow icon selected (the rest of the icons must be deselected). To see both, warnings and errors, leave only these two icons on.
• Click Add filter > Product Category and using the drop-down menu, you can select the types of devices to be displayed.
o All Devices - select this option from the drop-down menu to see all the client computers again, without limiting (filtering) displayed clients. You can use a combination of filtering options when narrowing down the view.
o ESET Protected - protected by an ESET product o ESET PROTECT Cloud - individual ESET PROTECT Cloud components such as Agent, RD Sensor, Server, etc.
o Other - Shared Local Cache, Virtual Appliance, Enterprise Inspector Agent, Enterprise Inspector Server.
• Show Subgroups check box - show subgroups of the currently selected group.
•
for more advanced filtering.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
104
•
Add filters and filter presets. You can use
for filtering the displayed items.
Note
If you are not able to find a particular computer in the list and know it is in your ESET PROTECT Cloud infrastructure, make sure that all filters are turned off.
Computer details
To find out details about a computer, select a client computer in a Static or Dynamic Group and click Show
Details or click the computer name.
The information window consists of the following parts:
Overview
There are the following tiles with an overview of the computer's situation.
Computer
• Click the edit icon to change the computer's name or description. You can select Allow Duplicate
Name if there is already another managed computer with the same name.
• Click Select tags to assign tags .
• FQDN - fully qualified domain name of the computer
• Parent Group - Change parent Static group of the computer.
• IP - the IP address of the machine.
• Applied Policies Count - Click the number to see the list of the applied policies.
• Member of Dynamic Groups - The list of Dynamic Groups in which the client computer was present during the latest replication.
Hardware
This tile contains a list of key hardware parameters, information about operating system and unique identifiers.
Click the tile to view the Details - Hardware tab.
Alerts
• Alerts - Link to list of problems with current computer.
• Unresolved Detections Count - Count of unresolved detections. Click the count to see the list of unresolved detections.
• Last Connected Time - Last Connected displays the date and time of last connection of the managed device. The Last Connected information gets highlighted to indicate that the computer is not connecting: o Yellow (error) - computer is not connecting for 2-14 days.
o Red (warning) - computer is not connecting for more than 14 days.
• Last Scan Time - Time information with last scan.
• Detection Engine - Version of detection engine on target device.
• Updated - The update status.
Products & Licenses
List of ESET components installed on the computer. Click the tile to view the Details - Product & Licenses tab.
105
Encryption
The encryption tile is visible only on workstations that are supported by ESET Full Disk Encryption .
ESET Dynamic Threat Defense
The tile provides basic information about the service. It can have two tile statuses:
• White - the default state. After the ESET Dynamic Threat Defense is activated and working, the tile is still in the white state.
• Yellow - if there is a problem with the ESET Dynamic Threat Defense service, the tile turns yellows and shows the information about the problem.
Available actions:
Users
• Enable - This option is available after you import the product license . Click it to set up the activation task and policy for the ESET Dynamic Threat Defense product on the current machine.
• Submitted files - shortcut to
• Learn more - shortcut to the product page.
• Logged users (computers only) - Domain and username of users logged on the device.
• Assigned users o Click Add user or Assign user to assign a user from
to this device.
o Click the trash icon to un-assign current user.
o Click the assigned user's username to display his account details.
Location (mobile devices only).
Click the Network Isolation button to run the network isolation client tasks on the computer:
•
•
Hardware button is used to set up the computer for cloning. It is required when computers are cloned or computers' hardware is changed.
• Mark as Master for Cloning > Match with existing computers - See the
• Mark as Master for Cloning > Create new computers - See the
Create a new computer every time
option. It is recommended to use this option before the VDI pool is created.
• Disable hardware detection - Disable detection of the hardware changes permanently. This action is irreversible!
• Unmark as Master for Cloning - Remove the master flag. After this is applied, each new cloning of the
.
106
Important
detection is not supported on:
• Linux, macOS, Android, iOS
• systems managed via ESET Virtual Agent Hosts (ESET Virtualization Security)
• machines without ESET Management Agent
Configuration
Configuration tab - Contains list of configurations of installed ESET products (ESET Management Agent, ESET endpoint, etc.). Available actions are:
• Click Request configuration to create a task for ESET Management Agent to collect all the managed product configurations. After the task is delivered to ESET Management Agent, it is executed immediately and the results are delivered to ESET PROTECT Cloud Server on the next connection. This will allow you to see the list of all managed product configurations.
• Open a configuration via context menu and convert it to a policy. Click a configuration to see it in the viewer.
• Once you open the configuration, you can convert it to a policy. Click Convert to Policy, current configuration will be transferred to the policy wizard and you can modify and save the configuration as a new policy.
• Download a configuration for diagnostics and support purposes. Click a selected configuration and click
Download for diagnostics in drop-down menu.
Applied Policies tab - List of policies applied to the device. If you have applied a policy for ESET product or ESET product feature that is not installed on the computer, the listed policy is grayed out.
Note
You can see the policies assigned to the selected device as well as policies applied to groups containing the device.
Click Manage Policies to manage, edit, assign or delete a policy. Policies are applied based on their order
(Policy Order column). To change policy application priority, select the check box next to a policy and click the
Apply Sooner or Apply Later button.
Applied Exclusions tab - List of exclusions
applied to the device.
Logs (computers only)
•
SysInspector - Click Request log (Windows only) to run the SysInspector log request task on selected
clients. After the task is completed, a new entry is added in the list of ESET SysInspector logs. Click a log in
•
entry is added in the list of logs. Click a log in the list to download it.
• Diagnostic logs - Click the Diagnostics > Turn on to start the Diagnostics mode on the current machine.
Diagnostics mode will make client send all logs to the ESET PROTECT Cloud Server. You can browse all logs within 24 hours. Logs are sorted into 5 categories: Spam Log, Firewall Log, HIPS Log, Device Control
Log, Web Control Log. Click Diagnostics > Resend All Logs to resend all logs from Agent in next replication. Click Diagnostics > Turn off to stop the Diagnostics mode.
107
Note
The file size limit for log delivery per device is 15 MB. Logs can be accessed from the Web Console at
Show Details > Logs section. If the logs gathered by the task are bigger than 15 MB, the task will fail. If this situation occurs, you can:
• Gather the logs locally on the device.
• Change the verbosity of the logs and retry the task: o For Windows targets, use the /Targets:EraAgLogs parameter to gather only ESET Management
Agent logs.
o For Linux/macOS targets, use the --no-productlogs parameter to exclude logs from the installed
ESET security product.
Task Executions
A list of executed tasks. You can filter the view to narrow down the results, view task details
, edit, duplicate, delete or run on/rerun the task.
Installed Applications
Displays a list of programs installed on a client with details such as version, size, security status, etc. You can turn on the reporting of non-ESET applications via Policy setting . Select a program and click Uninstall to remove it. You will be asked to enter Uninstallation parameters. These are optional command line parameters for the installer
(installation package). Uninstallation parameters are unique for each software installer. You can find more information in the documentation for the particular product.
If an update for the ESET product is available, you can update the ESET product by clicking Update ESET
Products button.
Note
ESET Management Agent from version – Windows: 7.2.1266.0, Linux: 7.2.2233.0, macOS: 7.2.3261.0
– and later, supports auto-upgrade functionality.
ESET Management Agent auto-upgrade is triggered two weeks after the newer version of ESET
Management Agent is released into the repository if the upgrade was not initiated by the
Administrator. The auto-upgrade is designed to assure that the upgrade process is phased and distributed during a longer period to prevent an increased impact on the network and managed workstations.
Alerts
Shows a list of alerts and their details: Problem, Status, Product, Occurred, Severity, etc. This list can be accessed
Questions (computers only)
The list of cloning-related question is on the Questions tab.
Read more about resolving questions for changed or
cloned computers.
108
Detections and Quarantine
• Detections - All
detection types are displayed, but you can filter them by Detection Category -
Antivirus, Firewall, HIPS, and Web protection.
•
Quarantine - A list of quarantined
detections with details such as Detection name, Detection type, Object name, Size, First occurred, Count, User reason, etc.
Details
• Basic - Information about the device: OS Name, Type, Version, Serial number, FQDN name, etc. Information whether the device is muted, managed, when it was last time updated and number of applied policies.
• Hardware - Information about the hardware of the computer, manufacturer and model and information about networking (IPv4, IPV6, subnet, network adapter...).
• Products and Licenses - Version of current detection engine, versions of installed ESET security products, used licenses.
Remove computer from management
To remove a device from management, click Computers, select a device and click Remove. A dialog box will display the steps needed to remove the selected computer from management.
109
Important
When proceeding to the next step, make sure that you have successfully competed the previous step. This is essential for correct device removal.
1. Reset Endpoint settings - Click Manage Policies and remove all applied policies to allow local device
management. See Policy Removal Rules in the Policies
section. If a password is set to access the Endpoint product setup, create a new policy to remove the password (select to set a password, but do not enter any password). For EFDE clients follow the decryption steps here .
2. Stop computer management - Run a
Stop Managing Task or uninstall the ESET Management Agent or
ESET security product locally on a computer. This suspends the connection between the computer and ESET
PROTECT Cloud.
3. Remove computer from database - After you ensure that the computer is no longer connecting to ESET
PROTECT Cloud, you can remove it from the list of managed devices.
• Select the check box I want to deactivate installed ESET products to remove the license from all ESET
products installed on the selected computer. See also deactivation of ESET business products
.
Groups
Groups can be understood as folders where computers and other objects are categorized.
110
For computers and devices, you can use pre-defined groups and group templates, or create new ones. Client computers can be added to groups. This helps you keep the computers structured and arranged to your liking. You can add computers to a Static Group.
Static Groups are managed manually, while Dynamic Groups are arranged automatically based on specific criteria in a template. Once the computers are in groups, you can assign policies, tasks or settings to these groups. The policy, task or setting is then applied to all the members of the group. There are two types of client groups:
Static Groups
be added/removed manually, not based on dynamic criteria. An object can only be present in one Static Group. A static group can be deleted only if there are no objects contained in it .
Dynamic Groups
are groups of devices (not other objects like tasks or policies) that have become members of the group by meeting specific criteria. If a client device does not fulfill that criteria, it will be removed from the group.
Computers that satisfy the criteria will be added to the group automatically (hence the name "dynamic").
Click the gear icon next to the group name to see the available
.
Computers that are members of the group are listed on the right pane.
Group Actions
Navigate to Computers and select the group you want to manage. Click the Group button or the gear icon next to the group name. A menu with the following options will be displayed:
Group Action Group Action Description
Show Details
Provides an overview of the selected group.
Audit Log
View the
for the selected item.
New Static
Group
New Dynamic
Group
The selected group becomes the default parent group, but you can change the parent group later when you
The selected group becomes the default parent group, but you can change the parent group later when you
New Notification Create a
.
Tasks
Select Client Tasks to be executed on devices in this group:
Scan - Run the On Demand Scan task on all clients in the
selected group.
Update Modules - Run the
task (triggers an update manually).
Run Task - Select one or more Client Tasks and run them on the selected device.
Reports
New Task - Create a new
Client Task . Select a task and
configure the
throttling (optional) for this task. The task will be
queued according to the task settings.
This option immediately triggers an existing
that you select from a list of available tasks. The trigger is not available for this task, because it will be executed immediately.
Last used tasks - List of last used Client Tasks for all
groups and computers.
Select and run a
from the selected group.
✔
✔ x
✔
✔
Applies to
Static
Groups
✔
✔
Dynamic
Groups
✔
✔ x
✔
✔
✔ x
111
Group Action Group Action Description
Manage Policies
Edit
Move
Delete
Apply sooner
Apply later
Import
assigned to the selected group.
Edit the selected Group. The same settings apply as when you create a new group (static or dynamic).
Select a group and move it as a subgroup of another group.
Remove the selected group.
Change the priority level of a Dynamic Group.
Export
Active Directory
Scanner
a list (usually a text file) of computers, as members of the selected group. If the computers already exist as members of this group, the conflict will be solved based on the selected action.
Export the members of the group (and subgroups, if selected)
in a list (.txt file). This list can be used for review or imported later.
Use the generated access token to authenticate ESET Active
to connect to the ESET PROTECT Cloud and synchronize the Active Directory to the selected Static Group.
✔
✔
Applies to
Static
Groups
✔
✔ x
✔
✔
✔
Group Details
When you select the group action Show Details, you can see an overview of the selected group:
Overview
✔
✔
Dynamic
Groups
✔
✔
✔ x x x
In Overview, you can edit group settings by clicking or Add description. You can view information about
see the
based on which computers are evaluated and assigned to the group.
Tasks
You can view and edit the
Client Tasks assigned to the group.
Policies
You can assign an existing policy to the group or create a new policy. You can view and edit the
assigned to the group.
Note
You can see only the policies assigned to the selected group. You cannot see the policies applied to individual computers in the group.
Policies are applied based on their order (Policy Order column). To change policy application priority, select the check box next to a policy and click the Apply Sooner or Apply Later button.
Alerts
The list of
from computers in the group. You can manage alerts via one-click actions
.
Exclusions
The list of
exclusions applied to the group.
112
Static Groups
Static Groups are used to:
• Organize devices and create hierarchy of groups and subgroups
• Organize objects
• Serve as Home Groups for users
device can belong only to one Static Group. The management of Static Groups is available via
There are two default Static Groups:
• All - This is a main group for all devices in the ESET PROTECT Cloud Server network. All objects created by the administrator are (by default) contained in this group. It is always displayed and cannot be renamed.
Access to this group gives users access to all subgroups; therefore it should be distributed carefully.
• Lost & Found - A child group of group All. Each new computer that connects to the ESET PROTECT Cloud
Server for the first time is automatically displayed in this group. The group can be renamed or copied, but it can't be deleted or moved.
Important
A static group can be deleted only if:
• The user has write permission for this group
• The group is empty
If there are still some objects in the static group, the delete operation will fail. There is an Access
Group filter button located in each menu (for example, Installers) with objects.
Click Select to choose a static group—only objects contained in this group will then be listed in the view. With this filtered view, the user can easily manipulate objects from one group.
Create a new Static Group
To create a new Static Group, click Computers, select the gear icon next to a static group and select New
Static Group.
113
Basic
Enter a Name and a Description for the new group. Optionally, you can change the Parent group. By default, the parent group is the group you selected when you started creating the New Static Group. If you want to change its parent group, click Change Parent Group and select a parent group from the tree. The parent of the New
Static Group must be a Static Group. It is not possible for a Static Group to be included in a Dynamic Group. Click
Finish to create the New Static Group.
114
Export Static Groups
Exporting a list of computers that are in the ESET PROTECT Cloud structure is simple. You can export the list and store it as a backup so that you can import the list back in the future, for example if you want to restore the group structure.
Note
Static groups need to contain at least one computer. Exporting empty groups is not possible.
1. Go to Computers and select a Static Group you want to export.
2. Click the gear icon and select Export.
3. If the selected Static Group contains subgroups with computers, you can select to export computers from subgroups as well.
115
4. The file will be saved in .txt format.
Note
Dynamic Groups cannot be exported because Dynamic Groups are only links to computers according to the criteria defined in Dynamic Group Templates.
Import Static Groups
files from Static Groups can be imported back into ESET PROTECT Cloud Web Console and included in your existing group structure.
1. Click Computers, select any Static Group.
2. Click the gear icon and select Import.
3. Click Choose File and navigate to the .txt file.
4. Select the group file and click Open. The file name is displayed in the text box.
5. Select one of the following options to resolve conflicts:
• Do not create or move any devices if same entries were found elsewhere.
If the static group exists and computers from the .txt file already exist in this group, those computers are skipped and are not imported. Information about this is displayed.
• Move existing devices if they do not already exist on imported paths. Keep only managed devices on same path when possible.
If the static group exists and computers from the .txt file already exist in this group, it is necessary to move computers to other Static Groups prior to the import, after the import, these computers will be moved back into original groups from where they had been moved.
• Duplicate existing devices if they do not already exist on imported paths.
If the static group exists and computers from the .txt file already exist in this group, duplicates of these computers are created in the same Static Group. The original computer is displayed with full information and the duplicate is displayed with its Computer name only.
6. Click Import to import the static group and computers.
Dynamic Groups
Dynamic Groups can be seen as filters based on computer status. One computer may apply for more than one filter and, therefore, be assigned to more than one Dynamic Group. This makes Dynamic Groups different from Static
Groups, because a single client cannot belong to more than one static group.
Dynamic Groups are groups of clients selected based on specific conditions. For a computer to become a member
of a specific Dynamic Group, it must meet the conditions defined in a
. Each template
116
consists of one or several Rules
. You can specify these rules when creating a new Template
. If a client computer does not fulfill the criteria, it will be removed from the group. If it fulfills the defined conditions, it will be added to the group.
Devices are evaluated for inclusion in Dynamic Groups each time they check in to ESET PROTECT Cloud. When a device meets the values specified in a Dynamic Group template, it is automatically assigned to this group.
Computers are filtered on the Agent side, so no extra information needs to be transferred to server. The Agent decides on its own which Dynamic Groups a client belongs to, and only notifies the server about this decision.
Note
If the client device is not connected (for example, it is turned off), its membership in dynamic groups is not updated. After the device is connected again, its membership in dynamic groups will be updated.
There are ten pre-defined Dynamic Groups available after you have created ESET PROTECT Cloud. You can also create custom Dynamic Groups. There are 2 ways to do this:
•
Create a template first and then create a Dynamic Group
.
• Create a
when creating a new Dynamic Group.
You can use Dynamic Groups in other parts of ESET PROTECT Cloud. You can assign policies
to them (policies are
for all computers in the group.
A dynamic group can be inside (under) a static group or dynamic groups. However, static group cannot be inside a dynamic group. All dynamic groups under a certain static group only filter devices of that static group. If a dynamic group is inside another dynamic group, it filters the results of the superior dynamic group. Once the group is
created, it can be moved freely across the tree
.
The management of Dynamic Groups is available via group actions
.
Create a new Dynamic Group
Follow the steps below to create a New Dynamic Group.
1. Click Computers, select the gear icon next to any group and select New Dynamic Group. A New
Dynamic Group Wizard will appear.
117
2. Enter a name and description for the new template.
3. You can change the parent group by clicking Change Parent Group.
118
4.
Click Template. Every Dynamic Group is created from a Template that defines how the group filters
client computers. Unlimited number of Dynamic Groups can be created from one template.
Note
A template is a static object stored in a Static group. Users must have appropriate
access templates. A user needs access permissions to be able to work with Dynamic Group templates. All pre-defined templates are located in the static group All and are by default available only to the Administrator. Other users need to be
assigned additional permissions . As a result, users
may be unable to see or use default templates. The templates can be moved to a group where the users have permissions.
To duplicate a template, the user must be assigned Use permissions (for Dynamic Group templates) for the group where the source template is located, and Write permissions for the user's home group (where the duplicate will be stored). See the object duplication example .
•
, click Choose existing and select the appropriate template from the list.
• If you have not created any templates and none of the pre-defined templates in the list suit you, click New and follow the steps to create a
For more use cases how to create new Dynamic Group based on a Dynamic Group template with rules, see
5. Click Summary. The new group will appear under the parent Group.
Move Static or Dynamic Group
A Dynamic Group can be a member of any other group including Static Groups. A Static Group cannot be moved into a Dynamic Group. Also, it is not possible to move pre-defined Static Groups (for example, the Lost & found
Static Group) to any other group. Other groups can be moved freely.
Click the gear icon next to the group name and select Move. A pop-up window will be displayed showing the group's tree structure. Select the target group (static or dynamic) into which you want to move the selected group.
The target group will become a parent group. You can also move groups by dragging and dropping a group into the target group of your choice.
119
Note
The Dynamic Group in a new position starts to filter computers (based on the template) without any relation to its previous location.
There are 3 methods to move a group:
• Drag and drop - click and hold the group you want to move and release it above the new parent group.
• Click the gear icon > Move > select a new parent group from the list and click OK.
120
• Click the gear icon > Edit > select Change parent group. Select a new parent group from the list and click OK.
Assign Client Task to a Group
Click Computers, select Static or Dynamic Group and click the gear icon > Tasks > New Task. A New
Client Task wizard window will open.
121
Assign Policy to a Group
After a policy is created, you can assign it to a Static or Dynamic Group. There are two ways to assign a policy:
Method I.
Under Policies, select a policy and click Actions > Show Details > Assigned To > Assign Group(s). Select a
Static or Dynamic Group from the list (you can select more groups) and click OK.
Method II.
1. Click Computers, click the gear icon next to the group name and select Manage Policies.
122
2. In the Policy application order window click Add Policy.
3. Select the check box next to the policies that you want to assign to this group and click OK.
4. Click Close.
To see what policies are assigned to a particular group, select that group and click the Policies tab to view a list of policies assigned to the group.
To see what groups are assigned to a particular policy, select the policy and click Show Details > Applied on.
Note
For more information about policies, see the
Detections
The Detections section gives you an overview of detections found on managed devices.
Group structure is displayed on the left. You can browse groups and view detections found on members of a given group. To view all detections found on clients assigned to groups for your account, select the All group and
Detection status
There are two types of detections based on their status:
• Active detections - Active detections are detections that have not been cleaned yet. To clean the detection, run an In-Depth Scan with cleaning enabled on the folder that contains the detection. The scan task must finish successfully to clean the detection and have no more detections. If a user does not resolve an active detection within 24 hours from its discovery, it loses the Active status but it stays unresolved.
• Resolved detections - These are detections that have been marked by a user as
, however they have not yet been scanned using In-Depth Scan. Devices with detections marked as resolved will still be displayed in the filtered results list until scanning is performed.
123
A Detection handled status indicates whether an ESET security product took action against a detection
(depending on detection type and cleaning level settings ):
• Yes - The ESET security product took action against the detection (delete, clean, or quarantine).
• No - The ESET security product did not take action against the detection.
You can use Detection handled as a filter in Reports, Notifications, and Dynamic Group Templates.
Note
Not all detections found on client devices are moved to quarantine. Detections that are not quarantined include:
• Detections that cannot be deleted.
• Detections that are suspicious based on their behavior, but are not identified as malware, for example, PUAs .
Aggregation of detections
Detections are aggregated by time and other criteria to simplify their resolution. Detections older than 24 hours are aggregated automatically every midnight. You can identify aggregated detections by the X/Y (resolved items/total items) value in the Resolved column. You can see the list of aggregated detections in the
Occurrences tab in detection details.
Detections in archives
If one or more detections are found in an archive, the archive and each detection inside the archive are reported in
Detections.
Warning
Excluding an archive file that contains a detection does not exclude the detection. You must exclude the individual detections inside the archive.
The excluded detections will not be detected anymore, even if they occur in another archive or are unarchived.
Filtering detections
By default, all detection types from the last seven days are shown, including detections that have been successfully cleaned. You can filter the detections by several criteria: Computer Muted and Occurred are enabled by default.
Note
Some filters are enabled by default. If detections are indicated on the Detections button in the main menu, but you cannot see them in the list of detections, check to see which filters are enabled.
For a more specific view, you can add other filters, such as:
• Detection Category - Antivirus, Firewall, HIPS, and Web protection.
• Detection Type
• IP Address of the client that reported the detection
• Scanner - Select the scanner type that reported the detection. For example, the Anti-Ransomware
scanner shows the detections reported by the
.
124
• Action - Select the action performed on the detection. ESET security products report the following actions to ESET PROTECT Cloud: o cleaned - The detection was cleaned.
o deleted / cleaned by deleting - The detection was deleted.
o was a part of a deleted object - An archive that contained the detection was deleted.
o blocked / connection terminated - The access to the detected object was blocked.
o retained - No action was performed due to various reasons, for example:
➢ In the interactive alert , the user manually selected not to perform any action.
➢ In the ESET security product detection engine settings , the Protection level for the detection category is set lower than the Reporting level.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Manage Detections
To manage detections, click the item and select one of the available actions, or select the check box next to one or more items and use the buttons in the lower part of the
•
Scan computers - Run the On-Demand Scan Task on the device that reported the selected detection.
• Show Details - See Detection details: o Overview - The Overview section contains the basic information about the detection. From this section, you can manage the detection with various actions (available actions depend on detection category), or go to
to see details about the computer where the detection occurred.
o
Occurrences - The Occurrences section is active only when the detection is aggregated and provides
the list of individual occurrences of the detection. You can mark all occurrences of the same detection as resolved/unresolved.
125
• Computers - A list of actions you can perform on the computer where the detection was found. This list is
the same as the one in the Computers
section.
•
Audit Log - View the Audit Log for the selected item.
•
Occurrences - The Occurrences section is active only when the detection is aggregated
and provides the list of individual occurrences of the detection. You can mark all occurrences of the same detection as resolved/unresolved.
• Computers - A list of actions you can perform on the computer where the detection was found. This list is
the same as the one in the Computers
section.
•
Audit Log - View the Audit Log for the selected item.
• Mark As Resolved / Mark As Not Resolved - You can mark detections as resolved/not resolved here or in computer details .
• Run Task - Run an existing task and create a trigger to complete the task.
• Scan Path (available only for Antivirus detections - files with known paths) - Create the
Scan Task with pre-defined paths and targets.
• Create Exclusion (available only for Antivirus detections and Firewall IDS rules) - Create
Create Exclusion
You can exclude selected item(s) in Detections from being detected in the future. Click a detection and select
Create Exclusion. You can exclude only Antivirus detections and Firewall detections - IDS rules . You can
create an exclusion and apply it to more computers/group(s). The More > Exclusions
section contains all created exclusions, increases their visibility and simplifies their management.
Warning
Use exclusions with caution - they may result in an infected computer.
In ESET PROTECT Cloud, there are two Antivirus exclusion categories:
1. Performance exclusions - Exclusions of files and folders defined by a path. You can create them via a
Policy. Also see performance exclusions format and examples .
2. Detection exclusions - Exclusions of files defined by detection name, detection name and its path, or by object hash (SHA-1). Also see examples of detection exclusions by detection name .
126
Warning
• In ESET PROTECT Cloud, you cannot create detection exclusions via a Policy.
• If your policies previously contained detection exclusions, you can migrate exclusions from a Policy to the
Exclusions list .
• By default, detection exclusions replace the local existing exclusions list on the managed computers. To keep the existing local exclusions list, you need to apply the Allow appending detection exclusions to locally defined
list Policy setting before applying detection exclusions:
Settings
You can exclude one or more detections based on the selected Exclusion criteria.
Antivirus detections
• Path & Detection - Exclude each file by its detection name and path, including file name (e.g.
file:///C:/Users/user/AppData/Local/Temp/34e1824e/ggdsfdgfd.pdf.exe).
• Exact files - Exclude each file by its SHA-1 hash.
• Detection - Exclude each file by its detection name.
Detections in archives
If one or more detections are found in an archive, the archive and each detection inside the archive are reported in
Detections.
Warning
Excluding an archive file that contains a detection does not exclude the detection. You must exclude the individual detections inside the archive.
The excluded detections will not be detected anymore, even if they occur in another archive or are unarchived.
Firewall detections - IDS rules
• Detection & context (recommended) - Exclude the firewall detection using a combination of the following criteria: by detection, application and IP address.
• IP address - Exclude firewall detections by a remote IP address. Use this option if the network
127
communication with a particular computer causes false positives.
• Detection - Exclude the detection and ignore the false positive triggered from multiple remote computers.
• Application - Exclude application from network detections. Allow the network communication for an application that causes IDS false positives.
The recommended option is pre-selected based on the detection type.
Select the Resolve matching alerts check box to automatically resolve the alerts covered by the exclusion.
Optionally, you can add a Comment.
Target
Warning
You can assign exclusions (for Antivirus detections and Firewall IDS rules) only to computers with a
compatible ESET security product
installed. Exclusions will not be applied to incompatible
ESET security products and will be ignored on them.
An exclusion is by default applied to a user's home group.
To change assignments, click Add Computers or Add Groups and select the target(s) where the exclusion will be applied, or select an existing assignment(s) and click Remove Targets.
Preview
Allows you to see the overview of created exclusions. Make sure all exclusion settings are correct based on your preferences.
Important
After you create the exclusion, you cannot edit it. You can only
change assignment or delete exclusion .
Click Finish to create the exclusion.
You can see all the created exclusions in More >
. To verify if a computer or a group has any applied exclusions, navigate to computer details > Configuration >
or group details >
ESET security products compatible with exclusions
Warning
Exclusions will not be applied to incompatible ESET security products and will be ignored on them.
Antivirus detection exclusions
All manageable ESET security products are compatible with Antivirus detection exclusions, except for the following:
• ESET Dynamic Threat Defense
• ESET Virtualization Security
• ESET Endpoint for MacOS version 6.8.1 and older.
Firewall IDS exclusions
The following ESET security products are compatible with Firewall IDS exclusions:
128
• ESET Endpoint Antivirus for Windows version 8.0 and later
• ESET Endpoint Security for Windows version 8.0 and later
Ransomware Shield
ESET business products (version 7 and later) include Ransomware Shield. This new security feature is a part of
HIPS and protects computers from ransomware. When ransomware is detected on a client computer, you can view the detection details in the ESET PROTECT Cloud Web Console under Detections. To filter only ransomware detections, click Add Filter > Scanner > Anti-Ransomware scanner. For more information about Ransomware
Shield, see the ESET Glossary .
You can remotely configure Ransomware Shield from the ESET PROTECT Cloud Web Console using the Policy settings for your ESET business product:
• Enable Ransomware Shield - ESET business product automatically blocks all the suspicious applications that behave like ransomware.
• Enable Audit Mode - When you enable the Audit Mode, potential detections identified by the Ransomware
Shield are not blocked and are reported in the ESET PROTECT Cloud Web Console. The administrator can decide to block the potential reported detection or exclude it by selecting
. This Policy setting is available only via ESET PROTECT Cloud Web Console.
Important
By default, Ransomware Shield blocks all applications with potential ransomware behavior, including legitimate applications. We recommend that you Enable Audit Mode for a short period on a new managed computer, so that you can exclude legitimate applications that are detected as ransomware based on their behavior (false positives). We do not recommend that you use the Audit
Mode permanently, because ransomware on the managed computers is not automatically blocked when Audit Mode is enabled.
Reports
Reports allow you to access and filter data from the database in a convenient way. The reports window consist of two tabs:
• Categories & Templates - this is the default tab for the Reports section. It includes an overview of report categories and templates. You can create new reports and categories or perform other report related actions here.
•
here.
129
Reports are generated from templates which are categorized by report type. A report can be generated
Now next to the desired report template. You can use pre-defined report templates from the list of Categories &
Templates, or you can create a new report template with custom settings. Click New report template
to open a report template wizard and specify custom settings for the new report. You can also create a new report category
(New Category) or import previously exported report templates (Import Report Templates).
There is a Search bar on the top of the page. You can search the category and template names, not descriptions.
You can use
for filtering the displayed items.
The Access Group filter button allows users to select a static group and filter viewed objects according to the group where they are contained.
Using the report templates
Choose a report template and click the gear icon on the report template tile. The following options are available:
Generate Now
Download
Schedule
Edit
Audit Log
Duplicate
The report will be generated and you can review the output data.
Click Download to generate and download the report. You can choose from .pdf
or
.csv
. CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
- you can modify the schedule trigger ,
and report delivery. You can find all scheduled reports in the Scheduled reports tab.
Edit an existing report template. The same settings and options used for
creating a new report template apply.
View the
Audit Log for the selected item.
Create a new report based on the selected report (a new name is required for the duplicate).
130
Delete
Export
Using the report categories
Remove the selected report template completely.
The report template will be exported to a .dat
file.
Select the report category and click gear icon at the right corner of the category. The following options are available:
New Category
Enter a Name to create a new report template category.
New Report Template Create a new custom report template.
Delete
Remove the selected report template category completely.
Edit
Rename existing report template category.
Audit Log
View the
Audit Log for the selected item.
Export
Access Group >
Move
The report template category and all included templates will be exported to a .dat
file. You can later import the category with all templates by clicking Import Report
Templates. This is useful, for example, when you want to migrate your custom report templates to another ESET PROTECT Cloud Server.
Move the report template Category to a different static group. This will make it accessible for the local admin of target group. Local admin has full access rights in his group.
Important
The Import Report Templates / Export feature is designed for importing and exporting report templates only, not an actual generated report with data.
Permissions for Reports
Reports are static objects which reside in a structure of objects in the ESET PROTECT Cloud database. Each new report template is stored in the home group of the user who created it. To be able to access a report you need
Computer statuses overview report, there will be only data from computers where you have Read permission.
Important
• Read - User can list report templates and their categories. User can also generate reports based on report templates. User is able to read his dashboard.
• Use - User can modify his dashboard with available report templates.
• Write - Create / modify / remove templates and their categories.
All default templates are located in the All group.
Create a new report template
and click New Report Template.
131
Basic
Edit the Basic information about the Template. Enter a Name, Description and Category. You can only choose from pre-defined Categories. If you want to create a new category, use the New Category option (described in the
). Click Select tags to assign tags .
Chart
132
In the Chart section, select the Report type. Either a Table, where the information is sorted in rows and columns, or a Chart that represents data using an X and Y axis.
Note
The selected chart type will be displayed in the Preview section. This way, you can see what the report will look like in real-time.
Selecting a Chart gives you multiple options:
• Bar Chart - A chart with rectangular bars proportional to the values they represent.
• Dots Chart - In this chart, dots are used to display quantitative values (similar to a bar chart).
• Pie Chart - A pie chart is a circular chart divided into proportional sectors, representing values.
• Doughnut Chart - Similar to a pie chart, but the doughnut chart can contain multiple types of data.
• Line Chart - Displays information as a series of data points connected by straight line segments.
• Simple Line Chart - Displays information as a line based on values without visible data points.
• Stacked Line Chart - This chart type is used when you want to analyze data with different units of measure.
• Stacked Bar Chart - Similar to a simple bar chart, but there are multiple data types with different units of measure stacked in the bars.
Optionally, you can enter a title for the X and Y axis of the chart to make it easier to read the chart and recognize trends.
Data
In the Data section, select the information you want to display: a.
Table Columns: Information for the table is added automatically based on the selected report type.
You can customize the Name, Label and Format (see below).
b.
Chart Axes: Select the data for the X and the Y axis. Clicking the Add Axis opens a window with options. The choices available for the Y axis always depend on the information selected for the X axis
133
Format and vice versa, because the chart displays their relation and the data must be compatible. Select the desired information and click OK.
Click the symbol in the Data section to see extended formatting options. You can change the Format in which the data is displayed. You can adjust formatting for Table Columns and Chart Axes. Not all options are available for each data type.
Format Column Choose a column according to which the current column will be formatted. For example, when formatting Name column, choose Severity column to add severity icons next to the names.
Minimal Value Set the minimal limit for the displayed values.
Maximal Value Set the maximum limit for the displayed values.
Color Choose the color scheme for the column. Color is adjusted according to the value of the column picked in the Format Column.
Icons
Add icons to the formatted column according to the value of the Format Column.
Click one of arrows to change the order of the columns.
Sorting
If the data selected in the Data section contains a sortable symbol, sorting is available. Click Add Sorting to define the relationship between the selected data. Select the starting information (sorting value) and sorting method, either Ascending or Descending. This will define the outcome displayed in the chart. Click Up or Down to change the order of the sorting elements. Click the trash icon to remove the element from the selection.
Filter
Define the filtering method. Click Add Filter and select the filtering element from the list and its value. This defines what information will be displayed in the chart. Click the trash icon to remove the element from the selection.
Summary
In the Summary, review the selected options and information. Click Finish to create a new report template.
Generate report
There are several ways to generate a report instantly from a report template:
• Click Reports and select the Categories & Templates tab. Select a report template from which you want to generate a report. Click the gear icon and then click edit if you want to make changes to the template.
o You can click the report tile to generate and view the report in the ESET PROTECT Cloud Web Console.
When the report is generated, you can click Generate and download to save the report in your desired format. You can choose from .pdf
or .csv
. CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
• Navigate to
> New >
Server Task to create a new Generate Report task.
o The task is now created and displayed in the Task types list. Select this task and click Run Now on the bottom of the page. The task will be executed immediately.
o Configure the settings (as described in the
Generate Report task) and click Finish.
Note
When you click an item displayed in a report shown in the ESET PROTECT Cloud Web Console, a
menu appears with additional options.
134
Schedule a report
There are several ways to schedule a report generation:
• Navigate to
> New >
Server Task to create a new Generate Report task.
• Navigate to Reports, select a report template from which you want to generate a report, click the gear
.
•
Click Schedule in the context menu of a report template in a dashboard
.
• Navigate to Reports > Scheduled Reports tab > click Schedule.
Note
When scheduling a report, you have multiple options, as described in the Generate Report
task:
• Choose multiple report templates for one report.
• Set report delivery in an email.
• Optionally set the trigger and throttling parameters.
Note
The maximum email size allowed by ESET PROTECT Cloud infrastructure is 30 MB.
(either one time, or repeatedly) and based on the
throttling settings (optional).
Scheduled Reports tab
You can review your scheduled reports in Reports > Scheduled Reports. Other actions available in this tab are shown below:
Schedule
Show Details
Audit Log
Tags
Run now
Edit
Duplicate
Delete
Access Group >
Move
Create a new schedule for an existing report.
View detailed information about the selected schedule.
View the
Audit Log for the selected item.
Edit tags (assign, unassign, create, delete).
Execute the scheduled report now.
Edit the schedule of the report. You can add or de-select report templates, modify schedule settings, or edit the throttling and delivery settings of the report.
Create a duplicate schedule in your home group.
Delete the schedule. The report template will stay.
Move the schedule to a different access group.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Outdated applications
Use the Outdated applications report to see which ESET PROTECT Cloud components are not up-to-date.
There are two methods to run this report:
135
•
Add a New Dashboard or modify one of existing dashboard panes.
• Navigate to Reports > Computers category > Outdated applications tile > click Generate now.
If you have found outdated application you can:
• Use the Client Task
to upgrade ESET Management Agent.
• Use the Client Task
to upgrade your security product.
SysInspector log viewer
Using SysInspector log viewer, you can view logs from SysInspector after it is run on a client computer. You can
also open SysInspector logs directly from a SysInspector Log Request task
after it has been successfully executed.
Log files can be downloaded and viewed in SysInspector on your local machine.
Note
SysInspector logs can only be requested from Windows-based clients.
How to view the SysInspector log
From a dashboard
1. Add a
or edit an existing dashboard report.
2. Select the report template Automation > SysInspector snapshot history in last 30 days.
3. Open the report, select a computer and then select Open SysInspector Log View form the drop down menu.
From a report
1.
> Automation category.
2. Select the SysInspector snapshot history in last 30 days template from the list and click
Generate now.
3. Open the report, select a computer and then select Open SysInspector Log View form the drop down menu.
From the Computers menu
1.
2. Select a computer in a Static or Dynamic Group and click Show Details.
3. Navigate to Logs section > SysInspector tab, click a list entry and select Open SysInspector Log
Viewer.
136
Hardware Inventory
ESET PROTECT Cloud has the ability to retrieve hardware inventory details from connected devices such as details about a device's RAM, storage, and processor.
Click Computers > click a connected device and select Show Details.
Click Details and select the Hardware tab.
137
You can filter connected devices based on their hardware parameters. You can select from the following hardware inventory categories: Chassis, Device information, Display, Display adapter, Input device, Mass storage, Network adapter, Printer, Processor, RAM and Sound device.
Hardware inventory reports
You can find pre-defined hardware inventory reports in Reports > Hardware inventory. You can create custom hardware inventory reports. When creating a
, under Data select a sub-category from one of the HW inventory filters. When you add the first table column or X-axis, only compatible data will be eligible for selection.
Dynamic Groups based on hardware inventory
creating a
, select rule(s) from hardware inventory categories. For example, you
can create a dynamic group with devices filtered by their RAM capacity to get an overview of devices with a certain amount of RAM.
Hardware inventory on Linux
The tool lshw must be installed on the client/server Linux machine for the ESET Management Agent to report hardware correctly.
Use the following command (as root or with sudo ) to install the lshw tool:
Debian based distributions (Ubuntu) apt-get install -y lshw
Red Hat based distributions (CentOS, Fedora, RHEL) yum install -y lshw
Hardware inventory on macOS
The hardware inventory feature is available on all manageable macOS versions.
138
Audit log report
The Audit log report contains all actions and changes performed by users on the ESET PROTECT Cloud Server.
To run this report, click Reports > Audit and License Management category > Audit log.
Note
You can view and filter an audit log directly in the Web Console under More > Audit Log
.
Important
To view the Audit log, the Web Console user must have a permission set with the
Tasks
You can use Tasks to manage ESET PROTECT Cloud Server, client computers and their ESET products. Tasks can automate routine jobs. There is a set of pre-defined tasks that cover the most common scenarios, or you can create a custom task with specific settings. Use tasks to request an action from client computers. To run a task successfully, it is required to have sufficient access rights for the task and for the objects (devices) that task uses.
See the list of permissions for more information on access rights.
There are two main task categories: Client Tasks
and
.
•
to groups or individual computers. Once created, a task is executed using a
Management Agent on a client connects to the ESET PROTECT Cloud Server. For this reason, it may take some time for task execution results to be communicated to the ESET PROTECT Cloud Server. You can manage your
ESET Management Agent connection interval to reduce task execution times.
• Server tasks are executed by ESET PROTECT Cloud Server on itself or other devices. Server tasks cannot be
assigned to any specific client or client group. Each Server Task can have one Trigger
configured. If the task needs to be run with various events, there has to be separate server task for each trigger.
You can create a new task in two ways:
• Click New > Client Task or Server Task .
• Select the desired task type on the left and click New > Client Task or Server Task .
The following pre-defined tasks are available for your convenience (each task category contains task types):
All Tasks
139
Client Tasks
ESET security product
End computer isolation from network
Export Managed Products Configuration
SysInspector Log Request (Windows only)
ESET PROTECT Cloud
Rogue Detection Sensor Database Reset
Stop Managing (Uninstall ESET Management Agent)
Operating System
Stop Managing (Uninstall ESET Management Agent)
Mobile
Export Managed Products Configuration
Stop Managing (Uninstall ESET Management Agent)
Server Tasks
Delete Not Connecting Computers
- deletes clients that no longer connect to ESET PROTECT Cloud from Web
Console.
- used to generate reports as they are needed.
Rename Computers - this task will periodically rename computers in groups using FQDN format.
Client Tasks
to groups or individual computers. Once created, a task is executed using a
. A
Client Task can have more triggers configured. Client Tasks are distributed to clients when the ESET Management
Agent on a client connects to the ESET PROTECT Cloud Server. For this reason, it may take some time for task execution results to be communicated to the ESET PROTECT Cloud Server. You can manage your ESET
Management Agent connection interval to reduce task execution times.
In Tasks you can see the
,
details for each created task.
140
Create a new Client Task
1. To create a new Client Task, click Tasks > New > Client Task or select the desired task type and click New > Client Task.
2. In the Basic section, enter basic information about the task, such as a Name and Description
(optional). Click Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific task type before creating a new task, Task is pre-selected based on your previous choice. Task (see
the list of all Tasks ) defines the settings and the behavior for the task.
3. Configure the task settings in the Settings section.
4. Verify all the settings for this task in the Summary section and then click Finish.
5. Click Create Trigger to create a
for the Client Task or click close and create the trigger later.
Client Task Triggers
A Trigger must be assigned to a
Client Task for it to be executed. To create a Trigger, click Tasks > click the Client
Task to a Group or Computer(s) .
To define a Trigger, select the Target computers or groups on which a Client Task should be executed. With your target(s) selected, set the trigger conditions to execute the task at a particular time or event. Additionally, you
can use Advanced settings - Throttling to further fine-tune the Trigger, if required.
Basic
Enter basic information about the Trigger in the Description field and then click Target.
Target
The Target window allows you to specify the clients (individual computers or groups) that are the recipients of this task.
• Click Add Computers to display all Static and Dynamic Groups and their members and select devices.
141
• Click Add Groups to display all Static and Dynamic Groups and their members and select groups.
After selection, click OK and proceed to the Trigger section.
Trigger
Trigger determines what event triggers the task.
• As Soon As Possible - Executes the task as soon as the client connects to ESET PROTECT Cloud Server and receives the task. If the task cannot be performed until the Expiration date, the task will be removed from the queue - the task will not be deleted, but it will not be executed.
• Scheduled - Executes the task at a selected time.
• Event Log Trigger - Executes the task based on events specified here. This trigger is invoked when a certain event occurs in logs. Define the log type, logical operator and filtering criteria that will trigger the task.
• Joined Dynamic Group Trigger - This trigger executes the task when a client joins the Dynamic Group selected in the target option. If a Static Group or individual client(s) have been selected, this option will not be available.
•
CRON Expression - You can also set your trigger interval using a CRON Expression.
Note
For more information about triggers, proceed to the
chapter.
Advanced settings - Throttling
Throttling is used to restrict a task from being executed if a task is triggered by a frequently occurring event, for example the Event Log Trigger or the Joined Dynamic Group Trigger (see above). For more information, see the
Advanced Settings - Throttling
chapter.
Click Finish when you have defined the recipients of this task and the triggers that execute the task.
142
Assign Client Task to a Group or Computer(s)
Read here how to assign Client Task to a Group .
There are two ways to assign a task to computer(s).
1. Dashboard > Computers > Computers with problems > select a computer and click Computer > select New Task
143
2. Computer > select computer(s) using check box(es) > select New Task
A New Client task wizard window will open.
Anti-Theft Actions
The Anti-Theft feature protects a mobile device from unauthorized access.
If a mobile device (enrolled and managed by ESET PROTECT Cloud) is lost or stolen, some actions are triggered automatically while other actions can be performed using a Client Task.
If an unauthorized person replaces a trusted SIM card with an untrusted SIM, the device will automatically be
locked by ESET Endpoint Security for Android and an alert SMS will be sent to user-defined phone number(s). This message will include the following information:
• the mobile device number of the SIM card currently in use
• the IMSI (International Mobile Subscriber Identity) number
• the mobile device's IMEI (International Mobile Equipment Identity) number
The unauthorized user will not be aware that this message has been sent because it will automatically be deleted from the device's messaging threads. You can also request the GPS coordinates of the lost mobile device or remotely erase all data stored on the device using a Client Task.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
144
Settings
Action
Find
Lock
Unlock
Siren
Wipe
Enhanced
Factory Reset
Find (Turn on lost mode)
Turn off lost mode
Behavior on mobile
OS
Description
The device will reply with a text message containing its GPS coordinates. If a more precise location is available after 10 minutes, the device will re-send the message.
Received information is displayed under device details .
Not supported.
The device will be locked. The device can be unlocked using the Administrator password or the unlock command.
The device will be locked. The device can be unlocked using the iOS passcode or the unlock command.
The device will be unlocked so it can be used again. The SIM card currently in the device will be saved as a Trusted SIM.
The device will be unlocked so it can be used again. This task also removes all stored fingerprints and passcodes and disables Apple Pay, iPhone Unlock and iTunes & App
Store.
The device will be locked and it will play a very loud sound for 5 minutes (or until unlocked).
Not supported.
All accessible data on the device will be erased (files will be overwritten). ESET
Endpoint Security will remain on the device. This can take up to several hours.
All accessible data on the device will be erased (files will be overwritten). This can take up to several hours.
All accessible data on the device will be erased (file headers will be destroyed) and the device will be reset to its default factory settings. This can take several minutes.
This action is not available from the Computers > Mobile context menu.
Not supported.
Supported on iOS ABM only. The device will switch to the "lost mode", lock down and can only be unlocked by executing the Turn off lost mode task from the ESET
PROTECT Cloud . You can customize the message that will be displayed on the lost device screen..
Supported on iOS ABM only.
145
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Diagnostics
Use the Diagnostics task to request a diagnostic action from an ESET security product on a client computer.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
146
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Diagnostic action
• Run Log Collector - Collects specific data (such as configuration and logs) from a selected machine in order to facilitate the collection of information from the customer's machine during a support case resolution.
o Log Collector parameters - You can specify Log Collector parameters on Windows , MacOS or Linux . To collect all available data, leave Log Collector parameters field blank. If you specify Log Collector parameters, select only computers running the applicable operating system as Targets for the task.
Note
The file size limit for log delivery per device is 15 MB. Logs can be accessed from the Web Console at
Show Details > Logs section. If the logs gathered by the task are bigger than 15 MB, the task will fail. If this situation occurs, you can:
• Gather the logs locally on the device.
• Change the verbosity of the logs and retry the task: o For Windows targets, use the /Targets:EraAgLogs parameter to gather only ESET Management
Agent logs.
o For Linux/macOS targets, use the --no-productlogs parameter to exclude logs from the installed
ESET security product.
• Set Diagnostic mode - Diagnostic mode consists of following categories: Spam log, Firewall log, HIPS
log, Device control log and Web control log. The main purpose of Diagnostic mode is to collect logs with all severity levels when troubleshooting is needed.
o Turn on - Turn on logging of all ESET applications.
o Turn off - You can turn off logging manually or logging will be automatically turned off after a computer restart.
The following prerequisites are needed for successful creation of Diagnostic logs:
• Diagnostic mode logs can be collected from client computers running Windows and macOS operating systems.
• Client computer must have ESET security product installed and activated.
Note
ESET Management Agent only sends logs collected by an ESET product installed on a client computer. Log category and verbosity depends on product type and configuration. Configure each product (via
Policies ) to collect specific logs.
Diagnostic logs older than 24 hours are removed every day during the midnight cleanup. This protects ESET
PROTECT Cloud database from overload.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
147
In Tasks you can see the
,
details for each created task.
You can view the created logs in computer details: Logs >
Display Message
The Display Message task enables you send a message to any managed device (client computer, tablet, mobile, etc.). The message will be displayed on the screen to inform the user.
• Windows - The message is displayed as a notification.
Important
In Windows, the Display Message Client Task uses the command msg.exe which is present only in
Windows Professional/Enterprise editions. As a result, you cannot use this task to display a message on a client computer running Windows Home edition.
• macOS and Linux - The message is displayed only in a terminal.
Note
To see the message in macOS or Linux, you first need to open the terminal.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
You can enter a Title and type in your Message.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
148
In Tasks you can see the
,
details for each created task.
End computer isolation from network
The End computer isolation from network task ends the computer isolation from the network and allows
connections of the isolated computer again. Use this Task only when the security issue has been resolved.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Note
Settings are not available for this task.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Export Managed Products Configuration
The Export Managed Products Configuration task is used to export the settings of individual ESET PROTECT
Cloud components or ESET security products installed on the client(s).
149
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Export managed products configuration settings.
• Product - Select an ESET PROTECT Cloud component or a client ESET security product for which you want to export the configuration.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
When the task completes, you can find the exported configuration in the Configuration tab under
computer details of target computers.
Isolate computer from network
The Isolate computer from network task isolates the selected computers from the network and all connections, except those needed for correct operation of ESET products, will be blocked. The allowed connections include the following:
• computer obtains an IP address
• communication of ekrn.exe, ESET Management Agent, ESET Enterprise Inspector Agent
• login to a domain
150
Warning
• Network isolation is compatible only with ESET security products (Endpoint Antivirus/Security and server security products) version 7.2 and later.
• Network isolation will likely interrupt the normal operation of the computers and you should use it in emergency cases only (e.g. if a severe security issue is identified on a managed computer). You can end the isolation with
.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Note
Settings are not available for this task.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Modules Update
The Modules Update task forces the update of all modules of the security product installed on a target device.
This is a general task for all security products on all systems. You can find the list of all modules of the target security product in the About section of the security product.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
151
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• Clear Update Cache - This option deletes the temporary update files in the cache on the client, and can often be used to repair module update errors.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Modules Update Rollback
In cases where a module update causes issues, or you do not want to apply the update to all clients (for example, for testing or when using pre-release updates), you can use the Modules Update Rollback task. When you apply this task, the modules will be reset to the previous version.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Expand this section to customize modules update rollback settings.
Action
• Enable Updates - Updates are enabled and the client will receive the next module update.
• Rollback and Disable Updates for Next - Updates are disabled for the specific time period in the
Disable interval drop-down menu (24, 36, 48 hours, or until revoked).
152
Important
Be careful when using the Until revoked option, as this presents a security risk.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
On-Demand Scan
The On-Demand Scan task lets you manually run a scan on the client computer (separate from a regular scheduled scan).
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Shutdown computer after scan - If you select this check box, the computer will shut down after scanning is finished.
Scan profile
You can select the profile you want from the drop-down menu:
• In-Depth Scan - This is a pre-defined profile on the client, it is configured to be the most thorough scan profile and checks the whole system but also requires the most time and resources.
• Smart Scan - Smart scan allows you to quickly launch a computer scan and clean infected files with no need for user intervention. The advantage of Smart scan is that it is easy to operate and does not require detailed scanning configuration. Smart scan checks all files on local drives and automatically cleans or deletes detected infiltrations. The cleaning level is automatically set to the default value.
• Scan From Context Menu - Scans a client using a pre-defined scan profile, you can customize the scan targets.
153
• Custom Profile - Custom scan lets you specify scanning parameters such as scan targets and scanning methods. The advantage of a Custom scan is the ability to configure the parameters in detail. Configurations can be saved to user-defined scan profiles, which make it easy to repeat the scan using the same parameters.
A profile must be created prior to running the task with the custom profile option. Once you select a custom profile from the drop-down menu, type the exact name of the profile into the Custom profile field.
Cleaning
By default, Scan With Cleaning is selected. This setting enables automatic cleaning of the found infected objects.
If this is not possible, they will be quarantined.
Scan Targets
The option Scan All Targets is also selected by default. Using this setting, all targets specified in the scan profile are scanned. If you deselect this option, you need to manually specify scan targets in the Add Target field. Type the scan target into the text field and click Add. The target will be displayed in the Scan targets field below. A scan target can be a file, location or you can run a pre-defined scan using any of the following strings as a Scan
target:
Scan target
${DriveRemovable}
Scanned locations
All removable drives and devices.
${DriveRemovableBoot} Boot sectors of all removable drives.
${DriveFixed} Hard drives (HDD, SSD).
${DriveFixedBoot}
${DriveRemote}
${DriveAll}
${DriveAllBoot}
${DriveSystem}
${Share}
${Boot}
Boot sectors of hard drives.
Network drives.
All available drives.
Boot sectors and UEFI of all drives. Read more about the UEFI scanner in the
System drives.
Shared drives (only for server products).
Main boot sector.
glossary .
${Memory}
${Registry}
${Wmi}
Operating memory.
System Registry (only for ESET Endpoint 8 and later).
WMI database (only for ESET Endpoint 8 and later).
Example
Below are some examples of how to use On-Demand Scan target parameters:
▪ File: C:\Users\Data.dat
▪ Folder C:\MyFolder
▪ Unix path or file /usr/data
▪ Windows UNC location \\server1\scan_folder
▪ Pre-defined string ${Memory}
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
154
In Tasks you can see the
,
details for each created task.
Operating System Update
The Operating System Update task is used to update the operating system of the client computer. This task can trigger the operating system update on Windows, macOS and Linux operating systems.
macOS - Task installs all updates using command:
/usr/sbin/softwareupdate --install --all
Linux - Task installs all updates. It is checking various package managers, so it covers most distributions.
Windows - The task installs OS updates. It does not install the feature updates, which upgrade your Windows to a newer version.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• Automatically accept EULA (Windows only) - Select this check box if you want to accept the EULA automatically. No text will be displayed to the user. If you do not enable accepting EULA, the task skips updates requiring EULA acceptance.
• Install optional updates (Windows only) - Updates that are marked as optional will also be installed.
• Allow reboot (Windows and macOS) - Force the client computer to reboot once the updates are installed.
Note
• If the Allow reboot option is not selected, updates that require a reboot will not be installed.
• Settings do not influence the task if the target device is running an unsupported OS type.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
155
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Quarantine Management
The Quarantine Management task is used to manage objects in the ESET PROTECT Cloud Server quarantine infected or suspicious objects found during the scan.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Quarantine management settings
Action - Select the action to be taken with the object in Quarantine.
• Restore Object(s) - Restores the object to its original location, but it will be scanned and if the reasons for the Quarantine persist, the object will be quarantined again.
• Restore Object(s) and Exclude in Future - Restores the object to its original location and it will not be quarantined again.
• Delete Object(s) - Deletes the object permanently.
Filter type - Filter the objects in the Quarantine based on the criteria defined below.
Filter settings:
• Hash items - Add hash items into the field. Only known objects can be entered, for example, an object that has already been quarantined.
• Occurred > Occurred from, Occurred to - Define the time range when the object has been quarantined.
• Size > Minimal/Maximal size (bytes) - Define the size range of the quarantined object (in bytes).
• Detection name - Select a detection from the quarantined items list.
• Object name - Select an object from the quarantined items list.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
156
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Product Activation
Use the Product Activation task to activate an ESET security product on a client computer or a mobile device.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Product activation settings - Select a license for the client from the list. This license will be applied to products already installed on the client. If you do not see any licenses listed, go to More > License Management and add a license .
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
157
Reset Cloned Agent
You can distribute the ESET Management Agent in your network via a pre-defined image, as described in this
Knowledgebase article . Cloned Agents have the same SID, which can cause problems (multiple Agents with the same SID). To resolve this, use the Reset Cloned Agent task to reset the SID and assign Agents a unique identity.
ESET Management Agent identifies cloned client machines running on Windows automatically, without Reset
was disabled) need the task to divide cloned machines.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Warning
Run this task with care. After the current ESET Management Agent is reset, all tasks running on it will be abandoned.
Note
Settings are not available for this task.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Rogue Detection Sensor Database Reset
The Rogue Detection Sensor Database Reset task is used to reset the RD Sensor search cache. The task deletes the cache and the search results will be stored again. This task does not remove detected computers. This task is useful when detected computers are still in the cache and are not reported to the server.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and
158
select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Note
Settings are not available for this task.
When creating a trigger for this task, target a computer where the RD Sensor is installed.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Run Command
The Run Command task can be used to execute specific command line instructions on the client. The administrator can specify the command line input to run.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Important
Commands are executed without access to a desktop environment. As a result, the execution of commands with requirements to the application's GUI may fail.
You can use ecmd commands with the Run Command task. For more information, visit the following
Knowledgebase article .
Operating
System
Windows
Command will run as user
Local System
Default working directory Accessible network locations
C:\Windows\Temp Only locations in the current domain and available to user
Local System
(
Command will be run in
Command prompt cmd.exe
)
159
Linux or macOS root /tmp Only if location is mounted and available to root user
Console
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• Command line to run - Enter a command line you want to run on the client(s).
• Working directory - Enter a directory where the command line above will be executed.
Important
You can enter a multi-line command.
Maximum command length restrictions:
• Web Console can process up to 32,768 characters. If you copy-paste a longer command, it would silently cut off the end.
• Linux and Mac are able to process the full length of the command. Windows has restriction for maximum 8,191 characters (read more here ).
Example
• To run a local script located on a client at C:\Users\user\script.bat
follow these steps:
1. Create a new Client Task and select Run Command.
2. In the Settings section enter:
Command line to run: call script.bat
Working Directory: C:\Users\user
3. Click Finish, create a trigger and choose target clients.
• To run a multi-line command to restart a Windows service remotely (replace service_name with the service name, for example wuauserv for the Windows Update service): net stop service_name net start service_name
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
160
Run SysInspector Script
The Run SysInspector Script task is used to remove unwanted objects from the system. A SysInspector Script needs to be exported from ESET SysInspector prior to using this task. After you export the script, you can mark objects you want to remove and run the script with the modified data - the marked objects will be deleted.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Note
Once the task is finished, you can review the results in a report.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• SysInspector Script - Click Browse to navigate to the service script. The service script needs to be created prior to running this task.
• Action - You can either Upload to, or Download a script from the ESET PROTECT Cloud Console.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Server Scan
You can use the Server Scan task to scan clients with the installed ESET Server solution. The type of scan run depends on the ESET solution installed:
Product
ESET File Security for
Microsoft Windows Server
Scan
Hyper-V scan
Description
This type of scan allows you to scan the disks of a
Microsoft Hyper-V Server , which is a virtual machine
(VM), without installing ESET Management Agent on the
VM.
161
Product
ESET Security for Microsoft
SharePoint Server
ESET Mail Security for
Microsoft Exchange Server
ESET Mail Security for IBM
Domino
Scan
SharePoint database scan, Hyper-V scan
On-demand mailbox database scan, Hyper-V scan
On-demand database scan, Hyper-V scan
Description
This functionality lets ESET PROTECT Cloud use the appropriate scan target when running the Server Scan
Client task on a server with ESET Security for Microsoft
SharePoint.
This functionality lets ESET PROTECT Cloud use the appropriate scan target. When ESET PROTECT Cloud runs a Server Scan Client Task, it will collect the list of targets and you will be asked to select scan targets for
On-demand mailbox database scan on that particular server.
This functionality lets ESET PROTECT Cloud use the appropriate scan target when running the Server Scan
Client task on a server with ESET Mail Security for IBM
Domino.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
• Click Select under Scanned Server and select a computer with version 6 or later server security products installed. You will be prompted to select specific drives, folders or files to scan on that computer.
• Select a
for this task, you can set throttling if you prefer. By default the task is run ASAP.
Scan Targets
ESET PROTECT Cloud offers you a list of available targets on the selected server. To use this list, Generate target
list must be enabled in the policy for your server product under Tools > ERA/ESMC Scan Targets:
• Generate target list - Enable this setting to allow ESET PROTECT Cloud to generate target lists.
• Update period [minutes] - Generating the target list for the first time will take about half of this period.
Select targets for scanning from the list. For more information, see ESET PROTECT Cloud scan targets .
Summary
All configured options are displayed here. Review the settings and click Finish.
In Tasks you can see the
,
details for each created task.
Shutdown computer
You can use the Shutdown computer task to shutdown or reboot client computers.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
162
Settings
• Reboot computer(s) - select this check box if you want to reboot the client computer after task completion.
If you want to shutdown computer(s), deselect this option.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Software Install
The Software Install task is used to install or upgrade
software on your client computers. It is primarily intended to install ESET products, but you can use it to install any software you like.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
To prevent installation failure, ESET PROTECT Cloud performs the following checks before installing or upgrading
ESET products:
• if the repository is accessible
• if there is enough (1 GB) free space on the client machine (not available for Linux)
Note
• Both ESET PROTECT Cloud Server and ESET Management Agent require access to the internet to access the repository and perform installations. If you do not have internet access, you must install the client software locally because remote installation will fail.
• When performing a Software Install task on computers in a domain with ESET Management Agent running, the user must have read permission for the folder where the installers are stored. Follow the steps below to grant these permissions if necessary.
1. Add an Active Directory computer account on the computer executing the task (for example
NewComputer$).
2. Grant Read permissions to NewComputer$ by right-clicking the folder where installers are located and selecting Properties > Sharing > Share from the context menu. Note that the "$" symbol needs to be present at the end of the computer name string.
Installation from a shared location is only possible if the client machine is in a domain.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
163
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• Click <Choose ESET License> and select the appropriate license for the installed product from the list of available licenses. This will only work for products installed from the repository, not products installed from a custom URL.
• Click <Choose package> to select an installer package from the repository or specify a package URL.
A list of available packages where you can select the ESET product you want to install (for example, ESET
Endpoint Security) will be displayed. Select your desired installer package and click OK. If you want to specify a
URL where the installation package is located, type or copy and paste the URL (for example
file://\\pc22\install\ees_nt64_ENU.msi) into the text field (do not use a URL that requires authentication).
http://server_address/ees_nt64_ENU.msi - If you are installing from a public web server or from your own HTTP server.
file://\\pc22\install\ees_nt64_ENU.msi - If you are installing from network path.
file://C:\installs\ees_nt64_ENU.msi - If you are installing from local path.
Select the check box I accept the terms of the application End User License Agreement and acknowledge
the Privacy Policy.
If you need to, you can specify command-line installation parameters, otherwise leave this field empty.
• Command-line installation parameters are intended for use only with the reduced, basic, and none user interface settings.
• See documentation for the msiexec version used for the appropriate command line switches.
• For ESET security product command-line installation, read the respective Online Help: o ESET Endpoint products o ESET Server products
Select the check box next to Automatically reboot when needed to force an automatic reboot of the client computer after installation. Alternatively, you can leave this option deselected and manually restart the client computer(s).
Installation of third-party software
You can use the Software Install task to install non-ESET (third-party) software.
Operating system Supported installation file types
Windows .msi
Linux macOS
Android iOS
.deb, .rpm, .sh
.pkg, .dmg (containing
.pkg file)
.apk
.ipa
Support for installation parameters
The Software Install task always performs silent installation of the
.msi packages.
You cannot specify msiexec parameters. You can specify only parameters used by the installation package itself (unique for each software installation package).
You can use parameters only with .sh files (.deb and .rpm do not support parameters).
Installation parameters are not supported.
164
Example
You want to install software on Linux using the file install_script.sh that has two parameters: -a is the first parameter, -b is the second parameter.
Installation in terminal (as root user in folder where install_script.sh is located):
./install_script.sh -a parameter_1 -b parameter_2 Installation using the Software
Install task:
• Enter the file path in Install by direct package URL, for example: file:///home/user/Desktop/install_script.sh
• Enter the Installation parameters: -a parameter_1 -b parameter_2 .
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
List of problems when installation fails
• Installation package not found.
• Required newer version of the Windows Installer Service.
• Another version or conflicting product is already installed.
• Another installation is already in progress. Complete that installation before proceeding with this install.
• Installation or uninstallation finished successfully but computer restart is required.
• Task failed - there was an error, you need to look at the
Agent trace log and check the return code of the
installer.
Upgrade ESET software
The Software Install task can be used to upgrade ESET security products. Run the task using the latest installer package to install the latest version over your existing solution.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
165
Settings
ESET license - Do not select a license when upgrading an active product. Only select a license when installing or upgrading products that are not active, or if you want to change the license currently in use to a different license.
Package to install - Select the latest version available from the repository to upgrade.
Select the check box I accept the terms of the application End User License Agreement and acknowledge
the Privacy Policy.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Important
• Do not use a Software Install task to upgrade ESET Management Agents. Use the
instead.
• You can run immediate ESET security product update from Dashboard using one-click actions .
• See upgrade instructions for ESET Security for Microsoft SharePoint to complete this upgrade.
Safetica software
What is Safetica
Safetica is a third-party software company and a member of the ESET Technology Alliance. Safetica provides an IT security solution for Data Loss Prevention and is complementary to ESET security solutions. Primary Safetica software features include:
• Data loss prevention - monitoring of all hard drives, USB drives, network file transfers, emails and printers as well as application file access
• Reporting and activity blocking - for file operations, websites, emails, instant messaging, application usage and searched keywords
How Safetica works
Safetica deploys an Agent (Safetica Endpoint Client) to your desired endpoints and maintains a regular connection with them through the server (Safetica Management Service). This server builds a database of workstation activity and distributes new data protection policies and regulations to each workstation.
Safetica integration in ESET PROTECT Cloud
166
ESET Management Agent detects and reports Safetica software as ESET software in Show Details > Installed
Applications . ESET PROTECT Cloud Web Console will update Safetica Agent if there is a new version available.
Safetica Agent can be updated directly from ESET PROTECT Cloud Web Console from the ESET software repository
using the Software Install task
.
You can also install Safetica Agent with Client Task - Run Command :
msiexec /i safetica_agent.msi STSERVER=Server_name
Where "Server_name" is the Hostname / IP address of the server where Safetica Management Service is installed.
You can use the /silent parameter at the end of the command to run the installation remotely and in a "silent" mode. e.g. msiexec /i safetica_agent.msi STSERVER=Server_name /silent
For the installation mentioned above the .msi package must be already present on the device. To run the installation where the .msi package is on a shared location, specify the location in the command as follows: msiexec /i Z:\sharedLocation\safetica_agent.msi STSERVER=Server_name
Software Uninstall
The Software Uninstall task is used to uninstall an ESET product from client computers when they are no longer wanted/needed.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Software Uninstallation Settings
Uninstall - Application from list
• Package name - Select an ESET PROTECT Cloud component, a client security product or a third-party application. All packages that can be uninstalled from the selected client(s) are displayed in this list.
Important
Once you uninstall the ESET Management Agent from the client computer, the device is no longer managed by ESET PROTECT Cloud:
• ESET security product may retain some settings after the ESET Management Agent has been uninstalled.
• If the Agent is password protected, you will not be able to uninstall it. We recommend that you reset some settings that you do not want to keep (for example, password protection) to default settings using a policy before the device is removed from management.
• All tasks running on the Agent will be abandoned. The Running, Finished or Failed execution status of this task may not be displayed accurately in ESET PROTECT Cloud Web Console depending on replication.
• After the Agent is uninstalled, you can manage your security product via the integrated EGUI or eShell .
• Package version - You can either remove a specific version (sometimes, a specific version can cause problems) of the package, or uninstall all versions of a package.
• Uninstallation parameters - You can specify parameters for uninstallation.
167
• Select the check box next to Automatically reboot when needed to force an automatic reboot of the client computer after installation. Alternatively, you can leave this option deselected and manually restart the client computer(s).
Uninstall - Third-party antivirus software (Built with OPSWAT)
For a list of compatible AV Software, see our Knowledgebase article . This removal is different from the Add or
Remove Programs uninstallation. It uses alternative methods to remove third-party antivirus software thoroughly including any residual registry entries or other traces.
Follow the step-by-step instructions in this article Remove third-party antivirus software from client computers using ESET PROTECT Cloud to send a task to remove third-party antivirus software from client computers.
If you want to allow uninstallation of password-protected applications, see our Knowledgebase article .
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Note
ESET security product uninstallation task may fail with a password-related error, for example:
Product: ESET Endpoint Security -- Error 5004. Enter a valid password to continue uninstallation . This is due to enabled password protection setting in ESET security
to the client computer(s) to remove password protection. You can then uninstall ESET security product via Software Uninstall task.
Stop Managing (Uninstall ESET Management Agent)
This task will uninstall ESET Management Agent from selected target devices. If a desktop is selected, the task will remove the ESET Management Agent.
168
Important
Once you uninstall the ESET Management Agent from the client computer, the device is no longer managed by ESET PROTECT Cloud:
• ESET security product may retain some settings after the ESET Management Agent has been uninstalled.
• If the Agent is password protected, you will not be able to uninstall it. We recommend that you reset some settings that you do not want to keep (for example, password protection) to default settings using a policy before the device is removed from management.
• All tasks running on the Agent will be abandoned. The Running, Finished or Failed execution status of this task may not be displayed accurately in ESET PROTECT Cloud Web Console depending on replication.
• After the Agent is uninstalled, you can manage your security product via the integrated EGUI or eShell .
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Note
Settings are not available for this task.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
SysInspector Log Request (Windows only)
The SysInspector Log Request task is used to request the SysInspector log from a client security product, that has this function.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
169
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
• Store log on client - Select this if you want to store the SysInspector log on the client as well as on the ESET
PROTECT Cloud Server. For example, when a client has ESET Endpoint Security installed, the log is usually stored under C:\Program Data\ESET\ESET Security\SysInspector.
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Upgrade Agent
You can use the Upgrade Agent task to upgrade ESET Management Agent to the latest version.
Note
ESET Management Agent from version – Windows: 7.2.1266.0, Linux: 7.2.2233.0, macOS: 7.2.3261.0
– and later, supports auto-upgrade functionality.
ESET Management Agent auto-upgrade is triggered two weeks after the newer version of ESET
Management Agent is released into the repository if the upgrade was not initiated by the
Administrator. The auto-upgrade is designed to assure that the upgrade process is phased and distributed during a longer period to prevent an increased impact on the network and managed workstations.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
To prevent installation failure, ESET PROTECT Cloud performs the following checks before installing or upgrading
ESET products:
• if the repository is accessible
• if there is enough (1 GB) free space on the client machine (not available for Linux)
170
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
Select the check box I accept the terms of the application End User License Agreement and acknowledge
the Privacy Policy.
Select the check box next to Automatically reboot when needed to force an automatic reboot of the client computer after installation. Alternatively, you can leave this option deselected and manually restart the client computer(s).
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Upload Quarantined File
The Upload Quarantined File task is used to manage files quarantined on clients. You can upload quarantined file from quarantine to a specific location for advanced investigation.
To create the task, click Tasks > New > Client Task or click the desired client device in Computers and select New Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
Settings
•
Quarantined object - Select a specific object from the quarantine .
• Object password - Enter a password to encrypt the object for security reasons. Please note that password will be displayed in the corresponding report.
171
• Upload Path - Enter a path to a location where you want to upload the object. Use the following syntax: smb://server/share
• Upload Username/Password - In case the location requires authentication (network share, etc.), enter the credentials to access this path. If the user is in a domain, use the format DOMAIN\username .
Summary
Review the summary of configured settings and click Finish. The Client Task is now created and a pop-up window will open:
• We recommend that you click
to specify when this Client Task should be executed and on what Targets.
• If you click Close, you can create a
later: click the Client Task instance and select Run on from the drop-down menu.
In Tasks you can see the
,
details for each created task.
Note
In the Trigger, make sure to select the target where the file is quarantined.
After the quarantined file is uploaded to the selected Upload Path location:
• The file is stored in a password-protected .zip
archive. The password is the .zip
file name (hash of the quarantined file).
• The quarantined file is without a file extension. To restore the file, add the original file extension to it.
Server Tasks
Server tasks are executed by ESET PROTECT Cloud Server on itself or other devices. Server tasks cannot be assigned to any specific client or client group. Each Server Task can have one
Trigger configured. If the task needs
to be run with various events, there has to be separate server task for each trigger.
Server tasks and permissions
The task and trigger both need an executing user. This is the user who modifies the task (and trigger). This user must have sufficient permissions for the chosen action. During execution, the task always takes the executing user from the trigger. If the task is run using the Run task immediately after finish setting, the executing user is the user logged into the ESET PROTECT Cloud Web Console. A user has permissions (Read, Use, Write) for the selected server task instance if it has those permissions selected in its permission set (More > Permission
172
Example
John, whose home group is John’s Group, wants to remove Server Task 1: Generate Report. The task was originally created by Larry, therefore the task is automatically contained in Larry's home group, Larry's Group. The following conditions must be met for John to remove the task:
• John must be assigned a permission set with write permissions for Server Tasks & Triggers -
Generate Reports.
• The permission set must contain Larry’s Group under Static Groups.
Permissions needed for certain server task actions
• To create a new server task, the user needs write permission for the selected task type and proper access rights for the referenced objects (computers, licenses, groups).
• To modify a server task, the user needs write permission for the selected server task instance and proper access rights for the referenced objects (computers, licenses, groups).
• To remove a server task, the user needs write permission for the selected server task instance.
• To run a server task, the user needs use permission for the selected server task instance.
Create a new server task
1. To create a new Server Task, click Tasks > New > Server Task or select the desired task type on the left and click New > Server Task.
2. In the Basic section, enter basic information about the task, such as a Name and Description
(optional). Click Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific task type before creating a new task, Task is pre-selected based on your previous choice. Task (see
the list of all Tasks ) defines the settings and the behavior for the task.
You can also select from the following task trigger settings:
• Run task immediately after finish - Select this option to have the task run automatically after you click
Finish.
•
Configure trigger - Select this option to enable the Trigger section, where you can configure trigger
settings.
To set the trigger later, leave the check boxes deselected.
3. Configure the task settings in the Settings section.
4. Set the trigger in the Trigger section, if it is available.
5. Verify all the settings for this task in the Summary section and then click Finish.
Note
It is recommended for users who are regularly using Server tasks to create their own tasks rather than sharing them with other users. Each time the task is run it uses the permissions of the executing user. This can confuse some users.
Delete Not Connecting Computers
The Delete not connecting computers task lets you remove computers according to specified criteria. For example, if the ESET Management Agent on a client computer has not connected for 30 days, it can be removed from ESET PROTECT Cloud Web Console.
The Last Connected information gets highlighted to indicate that the computer is not connecting: o Yellow (error) - computer is not connecting for 2-14 days.
o Red (warning) - computer is not connecting for more than 14 days.
To create a new Server Task, click Tasks > New > Server Task or select the desired task type on the left and
173
click New > Server Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
You can also select from the following task trigger settings:
• Run task immediately after finish - Select this option to have the task run automatically after you click
Finish.
•
Configure trigger - Select this option to enable the Trigger section, where you can configure trigger
settings.
To set the trigger later, leave the check boxes deselected.
Settings
Group name - select a Static Group or create new a Static Group for renamed computers.
Number of days the computer has not been connected - type number of days after which computers will be removed.
Deactivate License - select this check box to deactivate licenses on removed computers.
Remove unmanaged computers - select this check box to remove also unmanaged computers.
Trigger
The
up to one trigger. Each trigger can run only one Server Task. If Configure trigger is not selected in the Basic section, a trigger is not created. A task can be created without trigger. Such a task can be run afterward manually or a trigger can be added later.
Advanced Settings - Throttling
By setting
Throttling , you can set advanced rules for the created trigger. Setting throttling is optional.
Summary
All configured options are displayed here. Review the settings and click Finish.
In Tasks you can see the
,
details for each created task.
Generate Report
To create a new Server Task, click Tasks > New > Server Task or select the desired task type on the left and click New > Server Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
174
) defines the settings and the behavior for the task.
You can also select from the following task trigger settings:
• Run task immediately after finish - Select this option to have the task run automatically after you click
Finish.
•
Configure trigger - Select this option to enable the Trigger section, where you can configure trigger
settings.
To set the trigger later, leave the check boxes deselected.
Settings
Report templates - Click Add Report Template to choose a report template from the list. User creating the task will be able to see and choose only from Report Templates which are available in his group. You can choose multiple report templates for one report.
• Send to - Enter the email address(-es) of recipients for report emails. Separate multiple addresses with a comma (,). It is also possible to add CC and BCC fields; these work exactly as they do for mail clients.
• The ESET PROTECT Cloud pre-fills the subject and body of the email based on the selected report template.
You can select the check box under Customize message to customize the Subject and Message: o Subject - Subject of the report message. Enter a distinctive subject, so that incoming messages can be sorted. This is an optional setting, but we recommend that you do not leave it empty.
o Message - Define the body of the report message.
• Send mail if report is empty - use this option if you want the report to be sent even though there is no data in it.
Click Show print options to display the following settings:
• Output format - Select the appropriate file format. You can choose from .pdf
or .csv
. CSV is suitable only for table data and uses ; (semicolon) as a delimiter.
Note
Selecting CSV results in the date and time values in your report to be stored in the UTC format.
When you select PDF, the report will use the local server time.
• Output language - Select the language for the message. The default language is based on the language selected for the ESET PROTECT Cloud Web Console.
• Page size/Resolution/Paper orientation/Color format/Margin units/Margins - Select the appropriate options based on your print preferences. These options are relevant if you want to print the report and only apply to the PDF format, not the CSV format.
Trigger
The
up to one trigger. Each trigger can run only one Server Task. If Configure trigger is not selected in the Basic section, a trigger is not created. A task can be created without trigger. Such a task can be run afterward manually or a trigger can be added later.
Advanced Settings - Throttling
By setting
Throttling , you can set advanced rules for the created trigger. Setting throttling is optional.
Summary
All configured options are displayed here. Review the settings and click Finish.
In Tasks you can see the
,
details for each created task.
175
Rename computers
You can use the Rename Computers task to rename computers to FQDN format in ESET PROTECT Cloud. You can use existing server task that came default with your ESET PROTECT Cloud installation. If a client device name is different from the one reported in the device details, running this task can restore the proper name.
This task automatically renames synchronized computers located in the Lost & found group every hour.
To create a new Server Task, click Tasks > New > Server Task or select the desired task type on the left and click New > Server Task.
Basic
In the Basic section, enter basic information about the task, such as a Name and Description (optional). Click
Select tags to assign tags .
In the Task drop-down menu, select the task type you want to create and configure. If you have selected a specific
) defines the settings and the behavior for the task.
You can also select from the following task trigger settings:
• Run task immediately after finish - Select this option to have the task run automatically after you click
Finish.
•
Configure trigger - Select this option to enable the Trigger section, where you can configure trigger
settings.
To set the trigger later, leave the check boxes deselected.
Settings
Group name - Select a Static or Dynamic Group or create a New Static or Dynamic Group for the renamed computers.
Rename based on:
• Computer name - Each computer is identified on the local network by its unique computer name
• Computer FQDN (Fully Qualified Domain Name) - This starts with hostname and continues with domain names all the way up to top-level domain name.
Resolution of name conflicts will be performed for computers already present in ESET PROTECT Cloud (computer name must be unique) and those added via synchronization. Checks only apply to the names of computers outside the subtree being synchronized.
Trigger
The
up to one trigger. Each trigger can run only one Server Task. If Configure trigger is not selected in the Basic section, a trigger is not created. A task can be created without trigger. Such a task can be run afterward manually or a trigger can be added later.
Advanced Settings - Throttling
By setting
Throttling , you can set advanced rules for the created trigger. Setting throttling is optional.
Summary
All configured options are displayed here. Review the settings and click Finish.
In Tasks you can see the
,
details for each created task.
176
Task trigger types
Triggers are essentially sensors that react to certain events in a pre-defined way. They are used to execute the task they are assigned to. They can be activated by the scheduler (time events) or when a certain system event occurs.
Important
It is not possible to reuse a trigger. Each task must be triggered with a separate trigger. Each trigger can run only one task.
The trigger does not run newly assigned tasks immediately (except the ASAP trigger) — the task is run as soon as the trigger is fired. Trigger sensitivity to events can be reduced further using
.
Trigger types:
• As soon as possible - Available only for Client Tasks. The task will run as soon as you click Finish. The
Expiration date value specifies the date after which the task will no longer be executed.
Scheduled
Scheduled Trigger will run the task based on date and time settings. Tasks can be scheduled to run once, on a recurring basis, or on
• Schedule Once - This trigger is invoked once on the scheduled date and time. It can be delayed by random interval.
• Daily - This trigger is invoked every selected day. You can set the start and end of the interval. For example, you can run a task for ten consecutive weekends.
• Weekly - This trigger is invoked on a selected day of the week. For example, run a task every Monday and
Friday between July 1 and August 31.
• Monthly - This trigger is invoked on selected days in the selected week of a month, for the selected period of time. The Repeat on value sets the weekday in the month (for example, the second Monday) on which the task should run.
• Yearly - This trigger is invoked every year (or more years, if so configured) on the specified start date.
Note
Random delay interval setting is available for Scheduled type triggers. It defines the range of maximum delay for task execution. Randomizing can prevent overloading the server.
Example
If John set the task to trigger Weekly on Monday and Start on 2017 Feb 10 8:00:00, with Random
delay interval set to 1 hour and end by set to 2017 Apr 6 00:00:00, the task would run with a randomized one-hour delay between 8:00 and 9:00 every Monday until the specified end date.
Note
• Select the check box Invoke ASAP if Event Missed to run the task immediately if it did not run at the defined time.
• When configuring a trigger, ESET PROTECT Cloud Web Console time zone is used by default.
Alternatively, you can select the check box Use Server Local Time to use local time zone on server instead of ESET PROTECT Cloud Console time zone for the trigger.
Dynamic Group
Dynamic Group triggers are available only for Server Tasks:
177
• Dynamic Group Members Changed - This trigger is invoked when the contents of a Dynamic Group change. For example, if clients join or leave a specific Dynamic Group.
• Dynamic Group Size Changed According to Threshold - This trigger is invoked when the number of clients in a Dynamic Group becomes higher or lower than the specified threshold. For example, if more than
100 computers are in a given group.
• Dynamic Group Size Changed Over the Time Period - This trigger is invoked when the number of clients in a Dynamic Group changes over a defined time period. For example, if the number of computers in a given group increases by 10% in an hour.
• Dynamic Group Size Changed According to Compared Group - This trigger is invoked when the number of clients in an observed Dynamic Group change according to a compared group (static or dynamic).
For example, if more than 10% of all computers are infected (the group All compared to the group Infected).
Other
•
• Joined Dynamic Group Trigger - Available only for Client Tasks. This trigger is invoked every time a device joins the dynamic group.
Note
Joined Dynamic Group Trigger is available only if a dynamic group is selected in the Target section. The trigger will run the task only on devices that join the dynamic group after the trigger is created. For all the devices already in the dynamic group, you will have to execute the task manually.
• Event Log Trigger - This trigger is invoked when a certain event occurs in logs. For example, if there is a detection in the Scan log. This type of trigger provides a set of special settings in the Throttling settings .
• CRON Expression -This trigger is invoked at a certain time and date.
Cron expression interval
A CRON expression is used to configure specific instances of a trigger. Mostly for scheduled repetitive triggering. It is a string consisting of 6 or 7 fields that represent individual values of the schedule. These fields are separated by space and contain any of the allowed values in various combinations.
CRON expression can be as simple as this: * * * * ? * or more complex, like this: 0/5 14,18,3-39,52 * ?
JAN,MAR,SEP MON-FRI 2012-2020
List of values you can use in the CRON expression:
Name
Seconds
Minutes
Hours
Day of the month Yes
Month Yes
Day of the week Yes
Year Yes
Required Value
Yes 0-59
Yes
Yes
0-59
0-23
1-31
Allowed Special Characters
, - * / R
, - * / R
, - * / R
, - * / ? L W
1-12 or JAN-DEC , - */
0-6 or SUN-SAT , - / ? L #
1970-2099 , - * /
CRON expression syntax is following:
178
┌────────── Seconds
(0 - 59)│
┌────────── Minutes
(0 - 59)│ │
┌────────── Hours (0
- 23)│ │ │
┌────────── Day of the month (1 - 31)│
│ │ │ ┌──────────
Month (1 - 12 or JAN-
DEC)│ │ │ │ │
┌────────── Day of the week (0 - 6 or
SUN-SAT)(for example,
0 is the same as
SUN)│ │ │ │ │ │
┌────────── Year│ │
│ │ │ │
│* * * * * ? *
• The 0 0 0 means midnight (seconds, minutes, hours).
• Use ? when a value cannot be defined because it was defined in other field (day of the month or day of the week).
• The * means every (seconds, minutes, hours, day of the month, month, day of the week, year).
• The SUN means on Sunday.
Note
The names of months and days of the week are not case sensitive. For example, MON is equal to mon, or JAN is equal to jan.
Special characters:
Comma (,)
Commas are used to separate items of a list. For example, using "MON,WED,FRI" in the 6th field (day of the week) means Mondays, Wednesdays and Fridays.
Hyphen (-)
Defines ranges. For example, 2012-2020 indicates every year between 2012 and 2020, inclusive.
Wildcard (*)
Used to select all possible values within a field. For example, * in the minute field means every minute. The wildcard cannot be used in day of the week field.
Question mark (?)
When choosing a specific day, you can specify either day of the month or day of the week. You cannot specify both. If you specify day of the month, you must use ? for day of the week and vice versa. For example, if you want the trigger to fire on a particular day of the month (say, the 10th), but don’t care what day of the week that happens to be, put 10 in the day of the month field and ? in the day of the week field.
Hash (#)
Used to specify "the nth" day of the month. For example, the value of 4#3 in the day of the week field means the third Thursday of the month (day 4 = Thursday and #3 = the 3rd Thursday in the month). If you specify #5 and there isn't 5th of the given day of the week in the month, then the trigger will not fire that month.
179
Slash (/)
Describes increments of a range. For example 3-59/15 in the 2nd field (minutes) indicate the third minute of the hour and every 15 minutes thereafter.
Last (L)
When used in the day of the week field, it allows you to specify constructs such as the last Friday (5L) of a given month. In the day of the month field, it specifies the last day of the month. For example, day 31 for January, day 28 for February on non-leap years.
Weekday (W)
The W character is allowed for the day of the month field. This character is used to specify the weekday (Monday-
Friday) nearest the given day. As an example, if you specify 15W as the value for the day of the month field, the meaning is the nearest weekday to the 15th of the month. So, if the 15th is a Saturday, the trigger fires on Friday the 14th. If the 15th is a Sunday, the trigger fires on Monday the 16th. However, if you specify 1W as the value for day of the month, and the 1st is a Saturday, the trigger fires on Monday the 3rd, as it does not jump over the boundary of a month's days.
Note
The L and W characters can also be combined in the day of the month field to result in LW, which translates to last weekday of the month.
Random (R)
The R is a special ERA CRON expression character that allows you to specify randomized time moments. For example, R 0 0 * * ? * trigger fires every day at 00:00 but at a random second (0-59).
Important
We recommend you to use randomized time moments to prevent all ESET Management Agents from connecting at the same time to your ESET PROTECT Cloud Server.
Real examples that illustrate some variations of the CRON expression:
CRON expression
0 0 12 * * ? *
R 0 0 * * ? *
R R R 15W * ? *
Meaning
Fire at 12 pm (noon) every day.
Fire at 00:00 but at random second (0-59) every day.
Fire at 15th every month at random time (seconds, minutes, hours). If the 15th is a
Saturday, the trigger fires on Friday the 14th. If the 15th is a Sunday, the trigger fires on
Monday the 16th.
0 15 10 * * ? 2016
0 * 14 * * ? *
0 0/5 14 * * ? *
0 0/5 14,18 * * ? *
0 0-5 14 * * ? *
0 10,44 14 ? 3 WED *
0 15 10 ? * MON-FRI *
0 15 10 15 * ? *
Fire at 10:15 am every day during the year 2016.
Fire every minute starting at 2 pm and ending at 2:59 pm, every day.
Fire every 5 minutes starting at 2 pm and ending at 2:55 pm, every day.
Fire every 5 minutes starting at 2 pm and ending at 2:55 pm, and fire every 5 minutes starting at 6pm and ending at 6:55 pm, every day.
Fire every minute starting at 2 pm and ending at 2:05 pm, every day.
Fire at 2:10 pm and at 2:44 pm every Wednesday in March.
Fire at 10:15 am every weekday (Monday, Tuesday, Wednesday, Thursday and Friday).
Fire at 10:15 am on the 15th day of every month.
0 15 10 ? * 5L * Fire at 10:15 am on the last Friday of every month.
0 15 10 ? * 5L 2016-2020 Fire at 10:15 am on every last Friday of every month from the year 2016 to 2020, inclusive.
0 15 10 ? * 5#3 *
0 0 * * * ? *
Fire at 10:15 am on the 3rd Friday of every month.
Fire every hour, every day.
180
Advanced Settings - Throttling
Throttling is used to restrict a task from being executed. Usually throttling is used when a task is triggered by a frequently occurring event. Under certain circumstances, throttling may prevent a trigger from being fired. Each time the trigger is triggered, it is evaluated according to the schema below. Only those triggers which meet the specified conditions would then make the task execute. If no throttling conditions are set, all trigger events would run the task.
Time based criteria
Condition 1
Trigger
Condition 2
Throttling
Statistical criteria
Condition 1
Task execution
Condition 2
There are three types of conditions for Throttling:
1. Time Based Criteria
2. Statistical Criteria
3. Event Log Criteria
For a task to be executed:
• It has to pass all types of conditions
• Conditions must be set; if a condition is empty, it is omitted
• All time-based conditions must pass as they are evaluated with the AND operator
• All statistical conditions evaluated with the AND operator must pass; at least one statistical condition with the OR operator must pass
• Statistical and time conditions set together must pass as they are evaluated with the AND operator—only then is the task executed
If any of the defined conditions are met, stacked information for all observers is reset (the count starts over from
0). This holds for time-based as well as statistical conditions. This information is also reset if the Agent or ESET
PROTECT Cloud Server is restarted. All modifications made to a trigger reset its status. We recommend that you
181
only use one statistical condition and multiple time-based conditions. Multiple statistical conditions can cause unnecessary complications, and can alter trigger results.
Preset
There are three presets available. When you select a preset, your current throttling settings are cleared and replaced by the preset values. These values can be further modified and used, however it is not possible to create a new preset.
Time-based criteria
Time period (T2) - Allow triggering once during the specified time period. If for example, this is set to ten seconds and during this time ten invocations occur, only the first would trigger the event.
Schedule (T1) - Allows triggering only within the defined time range. Click Add period and pop up window is displayed. Set a Range Duration in selected time units. Select one option from the Recurrence list and fill in fields, which change according to selected recurrence. You can define the recurrence also in a form of
. Click OK to save the range. You can add multiple time ranges to the list—they will be sorted chronologically.
All of the configured conditions must be fulfilled in order to trigger the task.
Statistical criteria
Condition - Statistical conditions can be combined using either:
• Send notification when all statistical criteria are met - AND logical operator is used for evaluation
• Send notification when at least one statistical criteria is met - OR logical operator is used for evaluation
Number of occurrences (S1) - Allows only every x-th trigger hit. For example, if you enter ten, only each tenth triggering will be counted.
Number of occurrences within a time period
Number of occurrences (S2) - Allows only triggering within the defined time period. This will define the minimum frequency of events to trigger the task. For example, you can use this setting to allow the execution of the task if the event is detected 10x in an hour. Firing of the trigger causes a counter reset.
Time period - Define the time period for the option described above.
A third statistical condition is available only for certain trigger types. See Trigger > Trigger type > Event Log
Trigger.
Event log criteria
These criteria are evaluated by ESET PROTECT Cloud as third statistical criteria (S3). The Statistical criteria
application operator (AND / OR) is applied to evaluate all three statistical conditions together. We recommend that you use event log criteria in combination with the Generate Report task. All three fields are required for the criteria to work. The buffer of symbols is reset if the trigger is fired and there is a symbol already in buffer.
Condition - This defines which events or sets of events will trigger the condition. The available options are:
• Received in a Row - The specified number of events must occur in succession. These events must be unique.
• Received Since Last Trigger Execution - The condition is triggered when the selected number of unique events is reached in the time since the task was last triggered.
182
Number of occurrences - Enter the number of unique events with selected symbols to run the task.
Symbol - According to Log type, which is set in the Trigger menu, you can choose a symbol in the log which you can then search for. Click Select to display the menu. You can remove the selected symbol by clicking Remove.
Note
When in use with a Server Task, all client computers are considered. It is unlikely to receive higher number of distinctive symbols in a row. Use the Received in a Row setting only for reasonable cases. A missing value (N/A) is considered as "not unique" and therefore the buffer is reset in this point.
Additional properties
As stated above, not every event will cause a trigger to fire. Actions taken for non-firing events can be:
• If there is more than one event skipped, group the last N events into one (store data of suppressed ticks)
[N <= 100]
• For N == 0, only the last event is processed (N means history length, where the last event is always processed)
• All non-firing events are merged (merging the last tick with N historical ticks)
If the trigger fires too often or you want to be notified less often, consider the following suggestions:
• If the user wants to react only if there are more events, not a single one, see statistical condition S1
• If the trigger should fire only when a cluster of events occur, follow statistical condition S2
• When events with unwanted values are supposed to be ignored, refer to statistical condition S3
• When events from outside relevant hours (for example, working hours) should be ignored, see time-based condition T1
• To set a minimum time between trigger firings, use time-based condition T2
Note
The conditions can also be combined to form more complex throttling scenarios. See the
for more details.
Throttling Examples
Throttling examples explain how the throttling conditions (T1, T2, S1, S2, S3) are combined and evaluated.
Note
"Tick" means impulse from the trigger. "T" stands for time-based criteria, "S" stands for statistical criteria. "S3" stands for event log criteria.
S1: Criterion for occurrences (allow every third tick)
Time 00 01 02 03 04 05 06 Trigger is modified 07 08 09 10 11 12 13 14 15
Ticks x x x x x x x x x x x x x
S1 1 1 1 1
S2: Criterion for occurrences within time (allow if three ticks occur within four seconds)
Time 00 01 02 03 04 05 06 Trigger is modified 07 08 09 10 11 12 13
183
Time 00 01 02 03 04 05 06 Trigger is modified 07 08 09 10 11 12 13
Ticks x x x x x x x x x x
S2 1 1
S3: Criterion for unique symbol values (allow if three unique values are in a row)
Time 00 01 02 03 04 05 06 Trigger is modified 07 08 09 10 11 12 13
Value A B B C D G H
S3 1
J K n/a L M N N
1
S3: Criterion for unique symbol values (allow if three unique values are since the last tick)
Time 00 01 02 03 04 05 06 07 Trigger is modified 08 09 10 11 12 13 14
Value A B B C D G H I J K n/a L M N N
S3 1 1 1
T1: Allow a tick in certain time ranges (allow every day starting at 8:10, duration 60 seconds)
Time 8:09:50 8:09:59 8:10:00 8:10:01 Trigger is modified 8:10:59 8:11:00 8:11:01
Ticks x x x x x x x
T1 1 1 1
This criterion has no state; therefore trigger modifications have no effect on the results.
T2: Allow a single tick in a time interval (allow at most once every five seconds)
Time 00 01 02 03 04 05 06 Trigger is modified 07 08 09 10 11 12 13
Ticks x x x x x
T2 1 1 x x x x x
1 1
S1+S2 combination
• S1: every fifth tick
• S2: three ticks within four seconds
Time 00 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16
Ticks x x x x x x x x x x x
S1
S2
1
1 1 1
Result 1 1 1
The result is enumerated as: S1 (logical or) S2
S1+T1 combination
• S1: Allow every third tick
• T1: Allow every day starting at 8:08, duration 60 seconds
Time 8:07:50 8:07:51 8:07:52 8:07:53 8:08:10 8:08:11 8:08:19 8:08:54 8:08:55 8:09:01
Ticks x x x x x x x x x x
S1
T1
Result
1
1
1
1
1
1 1
1
1
1
The result is enumerated as: S1 (logical and) T1
S2+T1 combination
184
• S2: three ticks within ten seconds
• T1: Allow every day starting at 8:08, for a duration of 60 seconds
Time 8:07:50 8:07:51 8:07:52 8:07:53 8:08:10 8:08:11 8:08:19 8:08:54 8:08:55 8:09:01
Ticks x
S2 x x
1 x
1 x x x
1 x x x
1
T1
Result
1 1 1
1
1 1
The result is enumerated as: S2 (logical and) T1.
Note that the state of S2 is reset only when the global result is 1.
S2+T2 combination
• S2: three ticks within ten seconds
• T2: Allow at most once every 20 seconds
Time 00 01 02 03 04 05 06 07 … 16 17 18 19 20 21 22 23 24
Ticks x x x x x x x x x x x x x x x x x
S2
T2 1 1
1
1
1 1 1 1 1 1 1 1
1
Result 1 1
The result is enumerated as: S2 (logical and) T2.
Note that the state of S2 is reset only when the global result is 1.
Tasks overview
In Tasks you can see the
,
details for each created task.
Important
to execute a Client Task.
185
Click a task to take further task actions:
Show Details
Audit Log
Tags
Edit
Duplicate
Run Now
Run on
: summary, executions, triggers (trigger details are available only for Client
Tasks).
View the
for the selected item.
Edit tags (assign, unassign, create, delete).
Edit the selected
. Editing existing tasks is useful when you only need to make small adjustments. For more unique tasks, you might prefer to create a new task.
Create a new task based on the selected task; a new name is required for the duplicate.
Server Tasks only: Run the selected Server Task.
Client Tasks only: Add a
new Trigger and select Target computers or groups for the Client
Task.
Rerun on failed Client Tasks only: Create a new Trigger with all computers that failed during previous Task execution set as targets. You can edit the task settings if you prefer, or click Finish to rerun the task unchanged.
Triggers
Client Tasks only: See the list of
Triggers for the selected Client Task.
Delete
Executions
Remove the selected task(s) completely.
• If the task is deleted after it was created but before it was scheduled to start, it will be deleted and it will not run and never start.
• If the task is deleted after it was scheduled to run, the task will be completed but the information will not be displayed in Web Console.
Client Tasks only: You can select from task execution results and take further actions if
necessary; see Task details for more details.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
186
Progress indicator
The progress indicator is a color bar that shows the execution status of a Task. Each Task has its own indicator
(shown in the Progress row). The execution status of a Task is shown in different colors, and includes the number of computers in that state for a given task:
Running (blue)
Successfully finished (green)
Failed (orange)
Newly created Task (white) – it might take some time for the indicator to change color, ESET PROTECT Cloud
Server must receive a response from an ESET Management Agent to show the execution status. The progress indicator will be white if there is no Trigger assigned.
A combination of the above:
Refer to
status icon for details about different icon types and statutes.
Important
The progress indicator shows the status of a Task when it was last executed. This information comes from the ESET Management Agent. The progress indicator shows exactly what the ESET Management
Agent is reporting from client computers.
Status icon
The icon next to
Progress indicator provides additional information. It shows whether there are any planned
executions for a given Task as well as the result of executions that were completed. This information is enumerated by ESET PROTECT Cloud Server. The following statuses can be indicated:
Running
Success
Task is being executed on at least one target, there are no scheduled and no failed executions. This applies even if the Task has already finished on some targets.
Task has finished successfully on all targets, there are no scheduled or running executions.
187
Running
Error
Task is being executed on at least one target, there are no scheduled and no failed executions. This applies even if the Task has already finished on some targets.
Task has run on all targets, but has failed on at least one. No further executions are planned (scheduled).
Task is planned for execution, but no executions are running.
Planned
Planned/Running
Task has scheduled executions (from the past or in the future). No executions have failed and at least one execution is currently running.
Planned/Successful Task still has some scheduled executions (from the past or in the future), there are no failed or running executions and at least one execution has finished successfully.
Planned/Error
Task still has some executions scheduled (from the past or in the future), there are no running executions and at least one execution has failed. This applies even if some executions have completed successfully.
Task details
Click a task and select Show Details to view task details in the following tabs:
Summary
This tab contains an overview of task settings.
Executions
Click the Executions tab to switch view to see each execution result. If there are too many executions, you can filter the view to narrow down the results.
Executions for Client Tasks displays a list of computers with your selected result (using a filter). Click Add Filter to filter the selected executions by status:
• Planned - yes (Client Task is planned for execution), no (Client Task execution is completed).
• Last Status: No status, Running, Finished, Failed
Computers with a result other than the one selected will not be shown. You can modify the filter or turn it off to see all computers regardless of their last status.
You can also drill down further, for example, by selecting History to see details about the Client Task execution including the time when it Occurred, current Status, Progress and Trace message (if available). You can click
specific client. To take actions on more computers, use the check boxes to select the computers and click the
Actions button.
188
Note
• If you do not see any entries in the Executions History table, try setting the Occurred filter to a longer duration.
• When installing older ESET products, the Client Task report will display: Task delivered to the
managed product.
Triggers
The Triggers tab is available only for Client Tasks and it shows the list of Triggers for the selected Client Task. To manage the trigger, click the trigger and select one of the following items:
Edit
.
Rerun ASAP Run the Client Task again (ASAP) using an existing
Trigger straight away with no modification.
Delete
Duplicate
Remove the selected trigger completely. To delete multiple triggers, select the check boxes on the left and click the Delete button.
Create a new Trigger based on the selected one; a new name is required for the duplicate.
189
Installers
This section allows you to create Agent installer packages to deploy ESET Management Agent on client computers.
The installer packages are saved in ESET PROTECT Cloud Web Console and you can download them again when necessary.
1. Click Installers > Create Installer.
2. Select the installer type you want to create. The options are as follows:
•
Agent and ESET security product installer
package allows advanced configuration options, including Policy settings for ESET Management Agent and ESET products, ESET PROTECT Cloud Server
Hostname and Port, and the ability to select a Parent Group.
Note
After creating and downloading the All-in-one installer package, there are two options for deploying the ESET Management Agent:
• Locally on a client computer
• Using the ESET Remote Deployment Tool
to deploy ESET Management Agents to multiple client computers at the same time.
•
•
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Installers and permissions
A user can create or edit installers contained in groups where the user has Write permission for Stored
190
Installers.
Note
• A user needs to be assigned Use permission for Policies that are selected in Advanced > Initial
installer configuration > Configuration type when creating an All-in-one installer, GPO installer or SCCM script.
• A user needs to be assigned Use permission for Licenses if the license for static group is specified.
How to allow user to create installers
Example
Administrator wants to allow user John to create or edit new installers in John's Group. Administrator has to follow these steps:
1.
called John's Group
2.
a.
name it Permissions for John - Create Installers b.
add the group John's Group in the section Static Groups c.
in the Functionality section, select
• Write for Stored Installers
• Use for Certificates
• Write for Groups & Computers d.
click Finish to save the permission set
3.
a.
name it Permissions for John - Certificates b.
add the group All in the section Static Groups c.
in Functionality section select Use for Certificates.
d.
click Finish to save the permission set
These permissions are the minimal requirements for full (create and edit) installer usage.
4. Create a
User a.
name it John b.
in the Basic section select John's Group as the Home Group c.
set the password to user John d.
in Permission Sets section select Permissions for John - Certificates and Permissions for John -
Create Installers e.
click Finish to save the user
191
How to download installers from the installers menu
Policies
1. Click Installers.
2. Select the check box next to the installer you want to download.
3. Click Actions > Download.
Policies are used to push specific configurations to ESET products running on client computers. This allows you to avoid configuring each client's ESET product manually. A policy can be applied directly
and Dynamic ). You can also assign multiple policies
to a computer or a group.
Policies and permissions
The user must have sufficient
permissions to create and assign policies. Permissions needed for certain Policies
actions:
• To read the list of policies and their configuration a user needs Read permission.
• To assign policies to targets, a user needs Use permission.
• To create, modify or edit policies, a user needs Write permission.
See the list of permissions for more information on access rights.
Example
• If user John needs only to read policies created by himself, Read permission for Policies are needed.
• If user John wants to assign certain policies to computers, he needs Use permission for Policies and Use permission for Groups and Computers.
• To allow John full access for policies, Administrator must set Write permission for Policies.
Policy application
192
Policies are applied in the order that Static Groups are arranged. This is not true for Dynamic Groups, where child
Dynamic Groups are traversed first. This allows you to apply policies with greater impact at the top of the Group tree and apply more specific policies for subgroups. Using
, an ESET PROTECT Cloud user with access to groups located higher in the tree can override the policies of lower groups. The algorithm is explained in detail in
How Policies are applied to clients .
Policy removal rules
When you have a policy in place and decide to remove it later on, the resulting configuration of the client computers will depend on the version of installed ESET security product on the managed computers:
• ESET security products version 6 and older: The configuration will not automatically revert back to the original settings once the policy is removed. The configuration will remain according to the last policy that was applied to the clients. The same thing happens when a computer becomes a member of a
to which a certain policy is applied that changes the computer's settings. These settings remain even if the computer leaves the Dynamic Group. Therefore, we recommend that you create a policy with default settings and assign it to the root group (All) to have the settings revert to defaults in such a situation. This way, when a computer leaves a Dynamic Group that changed its settings, this computer will revert to default settings.
• ESET security products version 7 and later: When a policy is removed, the configuration will automatically revert back to the previous policy that was applied to the clients. When a computer leaves a Dynamic Group where particular policy setting were in place, these policy settings will be removed from the computer. Not
apply flag turns individual policy settings to the default state on client computers.
Merging policies
A policy applied to a client is usually the result of multiple policies being merged
into one final policy.
Note
We recommend that you assign more generic policies (for example, the update server) to groups that are higher within the group tree. More specific policies (for example, device control settings) should be assigned deeper in the group tree. The lower policy usually overrides the settings of the upper policies when merged (unless defined otherwise using
).
Policies Wizard
Policies are grouped/categorized by ESET product. Built-in policies contain pre-defined policies and custom
policies list categories of all the policies you've manually created.
Use policies to configure your ESET product the same way you would from within the Advanced setup window of the product GUI. Unlike policies in Active Directory, ESET PROTECT Cloud policies cannot carry any script or series of commands. Type to search for an item in Advanced setup (for example, HIPS). All HIPS settings will be displayed.
When you click the icon in the upper right corner, an Online Help page for the particular setting will be displayed.
193
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Create a new policy
Flags
1. Click Actions > New.
2. Enter basic information about the policy, such as a Name and Description (optional). Click Select tags to assign tags .
3. Select the correct product in the Settings section.
4. Use
to add settings that will be handled by the policy.
5. Specify the clients that will receive this policy. Click Assign to display all Static and Dynamic Groups and their members. Select the computer that you want to apply a policy on and click OK.
6. Review the settings for this policy and click Finish.
When merging policies, you can change the behavior by using policy flags. Flags define how a setting will be handled by the policy.
For each setting, you can select one of the following flags:
Not apply - Any setting with this flag is not set by policy. Because the setting is not forced, it can be changed by other policies later on.
Apply - Settings with this flag will be sent to the client. However, when merging policies, it can be overwritten by a later policy. When a policy is applied to a client computer and a particular setting has this flag, that setting is changed regardless of what was configured locally on the client. Because the setting is not forced, it can be changed by other policies later on.
194
Force - Settings with the Force flag have priority and cannot be overwritten by a later policy (even if the later policy has a Force flag). This assures that this setting won’t be changed by later policies during merging.
To make navigation easier, all rules are counted. The number of rules you have defined in a particular section will be displayed automatically. Also, you'll see a number next to the category names in the tree on the left. This shows a sum of rules in all its sections. This way, you'll quickly see where and how many settings/rules are defined.
You can also use the following suggestions to make policy editing easier:
• Use to set the Apply flag to all items in a current section
• Use to delete rules applied to the items in the current section.
Important
ESET security products version 7 and later:
Not apply flag turns individual policy settings to the default state on client computers.
How can Administrator allow users to see all policies
Example
Administrator wants to allow user John to create or edit policies in his home group and allow John to see policies that are created by Administrator. Policies created by Administrator include Force flags. User John can see all policies, but cannot edit policies created by Administrator because Read permission for Policies with access to Static Group All is set. User John can create or edit policies in his Home Group San Diego.
Administrator has to follow these steps:
Create environment
1. Create a new
called San Diego.
2. Create new
Permission set called Policy - All John with access to Static Group All and with Read
permission for Policies.
3. Create a new
Permission set called Policy John with access to Static Group San Diego, with
functionality access Write permission for Group & Computers and Policies. This permission set allows John to create or edit policies in his Home Group San Diego.
4. Create new
John and in Permission Sets section select Policy - All John and Policy John.
Create policies
5. Create new
All- Enable Firewall, expand Settings section, select ESET Endpoint for
Windows, navigate to Network protection > Firewall > Basic and apply all settings by Force flag. Expand the Assign section and select Static Group All.
6. Create new
John Group- Enable Firewall, expand Setting section, select ESET Endpoint for
Windows, navigate to Personal Firewall > Basic and apply all settings by Apply flag. Expand the Assign section and select Static Group San Diego.
Result
Policies created by Administrator will be applied first because they are assigned to group All. Settings with the Force flag have priority and cannot be overwritten by a later policy. Then policies created by user John will be applied.
Navigate to More > Groups > San Diego, click the computer and select Show details. In
Configuration > Applied policies is the final policy application order.
The first policy is created by Administrator and the second created by user John.
195
Manage Policies
Policies are grouped/categorized by ESET product. Built-in policies contain pre-defined policies and custom policies list categories of all the policies you have manually created or modified.
Actions available for policies:
Show Details
Audit Log
New
Tags
Show policy details.
View the
for the selected item.
Create a new policy.
Edit tags (assign, unassign, create, delete).
Edit
Duplicate
Modify an existing policy.
Create a new policy based on an existing policy you have selected. Duplicate policy requires a new name.
Change Assignment Assign a policy to a group or a client.
Delete
Delete a policy. See also policy removal rules .
Import
Export
Access group
Click Policies > Import, click Choose File and browse for the file you want to import.
You can import only a .dat file that contains the policies exported from ESET PROTECT
Cloud Web Console. You cannot import an .xml file that contains the policies exported from ESET security product. The imported policies will apppear under Custom Policies.
Select check boxes next to policies you want to export from the list and click Actions >
Export. The policies will be exported to a .dat file. To export all policies from the selected category, select the check box in the table header.
Move a policy to another group.
How Policies are applied to clients
Groups and Computers can have several policies assigned to them. Moreover, a Computer can be in a deeply nested Group, the parents of which have their own policies.
The most important thing for the application of policies is their order. This is derived from the Group order and order of policies assigned to the Group.
To see all policies applied to a selected computer, see Applied Policies in computer details.
Follow the steps below to determine the active policy for any client:
1. Find the order of groups in which the client resides
2. Replace groups with assigned Policies
3. Merge Policies to get final settings
Ordering Groups
Policies can be assigned to groups, and are applied in a specific order. Rules written below determine in which order policies are applied to clients.
Rule 1: Static Groups are traversed from the root Static Group (All).
Rule 2: On every level, the Static Groups of that level are traversed first in the order they appear in the tree (this is also called "breadth-first" search).
Rule 3: After all Static Groups at a certain level are accounted for, Dynamic Groups are traversed.
Rule 4: In every Dynamic Group, all its children are traversed in the order that they appear in the list.
Rule 5: Traversal ends at a computer.
196
Important
The policy is applied to the computer. This means that traversal ends at the computer which you want to apply the policy on.
Using the rules written above, the order in which policies will be applied on individual computers would be as follows:
PC1: PC2: PC3:
1. ALL
2. SG1
3. PC1
1. ALL
2. SG1
3. DG1
4. PC2
1. ALL
2.
3.
SG2
SG3
4. PC3
Enumerating Policies
Once the order of Groups is known, the next step is to replace each group with the policies assigned to it. Policies are listed in the same order as they are assigned to a Group. It is possible to edit the priority of policies for a group with more policies assigned. Each policy configures only one product (ESET Management Agent, EES, etc.).
Note
A group without a policy is removed from the list.
We have 3 policies applied to both static and Dynamic Groups (see picture below):
197
The order in which policies will be applied on the Computer
The list below displays groups and policies applied on them:
1. All -> removed, no Policy here
2. SG 2 -> Policy 1, Policy 2
3. SG 3 -> removed for no Policy
4. DG 1 -> Policy 1, Policy 2
5. DG 3 -> removed, no Policy
6. DG 2 -> Policy 3
7. DG 4 -> removed, no Policy
8. Computer -> removed, no Policy
The final list of policies is:
1. Policy 1
2. Policy 2
3. Policy 1
4. Policy 2
5. Policy 3
198
Merging Policies
When you apply a policy to an ESET security product where another policy is already applied, the overlapping policy settings are merged. Policies are merged one by one. When merging policies, the general rule is that the later policy always replaces the settings set by the former one. To change this behavior, you can use
the policies are merged. Merging of any two policies may have different results depending on their order.
When creating policies, you will notice that some settings have additional rules that you can configure. These rules allow you to arrange the same settings in various policies.
• Replace: The default rule which is used when merging policies. It replaces the settings set by the former policy.
• Append: When applying the same setting in more than one policy, you can append the settings with this rule. The setting will be placed at the end of the list that was created by merging policies.
• Prepend: When applying the same setting in more than one policy, you can prepend the settings with this rule. The setting will be placed at the beginning of the list that was created by merging policies.
Merging of local and remote lists
The recent ESET security products (see supported versions in table below) support merging of local settings with the remote policies in a new way. If the setting is a list (for example, a list of websites) and a remote policy is conflicting with an existing local setting, the remote policy overwrites it. You can choose how to combine local and remote lists. You can select different merging rules for:
• Merging settings for remote policies.
• Merging of remote and local policies - local settings with the resulting remote policy.
Options are the same as mentioned above: Replace, Append, Prepend.
List of products supporting local and remote lists:
ESET security product
ESET Endpoint for Windows
Version
7+
ESET Mail Security for Microsoft Exchange 6+
ESET File Security for Windows Server 6+
ESET Mail Security for IBM Domino 6+
ESET Security for Microsoft SharePoint Server 6+
199
Important
Policy removal in ESET security products version 7 and later
When a policy is removed, the configuration will automatically revert back to the previous policy that was applied to the clients.
Not apply flag turns individual policy settings to the default state on client computers.
Example scenario of merging policies
This example describes:
• Instructions on how to apply policy settings to ESET Endpoint security products
• How policies are merged when applying flags and rules
In situations where the Administrator wants to:
• Deny access for San Diego Office to the websites www.forbidden.uk, www.deny-access.com,
www.forbidden-websites.uk and www.forbidden-website.com
• Allow access for Marketing Department to the websites www.forbidden.uk , www.deny-access.com
The Administrator has to follow these steps:
200
1. Create a
new static group San Diego Office and then Marketing Department as a subgroup of static group
San Diego Office.
2. Navigate to Policies and create a new policy as follows: i.
Called San Diego Office ii.
Expand Settings and select ESET Endpoint for Windows iii.
Navigate to Web and Mail > Web access protection > URL Address Management iv.
Click the button to Apply policy and edit Address list by clicking Edit v.
Click List of blocked addresses and select Edit.
vi.
Add the following web addresses: www.forbidden.uk, www.deny-access.com,
www.forbidden-websites.uk and www.forbidden-website.com. Save the list of Blocked addresses and then address list.
vii.
Expand Assign and assign the policy to San Diego Office and its subgroup Marketing Department. viii.
Click Finish to save the policy.
This policy will be applied to San Diego Office and Marketing Department and will block the websites as shown below.
3. Navigate to Policies and create new policy: i.
Called Marketing Department ii.
Expand Settings and select ESET Endpoint for Windows iii.
Navigate to Web and Mail section > Web access protection > URL Address Management iv.
Click the button to Apply policy, select the
Append rule and then edit the Address list by
clicking Edit. Rule Append causes that the Address list will be placed at the end when merging policies.
v.
Click List of allowed addresses > Edit.
vi.
Add the following web addresses: www.forbidden.uk, www.deny-access.com. Save the list of allowed addresses and then address list.
vii.
Expand Assign and assign the policy to Marketing Department. viii.
Click Finish to save the policy.
This policy will be applied to Marketing Department and will allow access to the websites as shown below.
201
4. The final policy will include both policies applied to San Diego Office and Marketing Department. Open
Endpoint Security product and navigate to Setup > Web and email > Advanced setup, select the
Web and email tab > Web access protection and expand URL address management. The final
Endpoint product configuration will be shown.
202
The final configuration includes:
1. Address list of San Diego Office policy
2. Address list of Marketing Department policy
Configuration of a product from ESET PROTECT Cloud
You can use policies to configure your ESET product the same way you would from within the Advanced setup window of the product GUI. Unlike policies in Active Directory, ESET PROTECT Cloud policies cannot carry any script or series of commands.
For Version 6 and newer ESET products you can set certain statuses to be reported on the client or in the Web
Console. This can be set in a policy for v6 product under User Interface > User Interface Elements >
Statuses:
• Show - status is reported on the client GUI
• Send - status is reported to ESET PROTECT Cloud
Examples of policy usage to configure ESET products:
• ESET Management Agent policy settings
• ESET Roque Detection Sensor policy settings
Assign a Policy to a Group
After a policy is created, you can assign it to a Static or Dynamic Group. There are two ways to assign a policy:
Method I.
Under Policies, select a policy and click Actions > Show Details > Assigned To > Assign Group(s). Select a
Static or Dynamic Group from the list (you can select more groups) and click OK.
Method II.
203
1. Click Computers, click the gear icon next to the group name and select Manage Policies.
2. In the Policy application order window click Add Policy.
3. Select the check box next to the policies that you want to assign to this group and click OK.
4. Click Close.
To see what policies are assigned to a particular group, select that group and click the Policies tab to view a list of policies assigned to the group.
To see what groups are assigned to a particular policy, select the policy and click Show Details > Applied on.
Note
For more information about policies, see the
Assign a Policy to a Client
To assign a policy to a client workstation, click Policies, select a policy and click Actions > Show Details >
Assigned To > Assign Client(s).
204
Select your target client computer(s) and click OK. The policy will be assigned to all computers you have selected.
To see which clients are assigned to a particular policy, select the policy and see the first tab Assigned to.
How to use Override mode
Users with ESET Endpoint products (version 6.5 and above) for Windows installed on their machine can use the
Override feature. Override mode allows users on the client-computer level to change settings in the installed ESET
205
product, even if there is a policy applied over these settings. Override mode can be enabled for AD users, or it can be password-protected. The function cannot be enabled for more than four hours at once.
Warning
• Override mode cannot be stopped from the ESET PROTECT Cloud Web
Console once it is enabled. Override is disabled only after the time of override expires, or after it is turned off on the client itself.
• The user who is using the Override mode needs to have Windows admin rights too. Otherwise, the user cannot save the changes in settings of the ESET product.
• Active Directory group authentication is supported for selected managed products from version
ESET Endpoint Security version 7.0.2100.4 and later.
ESET File Security for Microsoft Windows Server version 6.5.12013.0 and later.
ESET Mail Security for IBM Domino version 6.5.14020.0 and later.
ESET Mail Security for Microsoft Exchange Server version 6.5.10019.1 and later.
To set the Override mode:
1. Navigate to Polices > New Policy.
2. In the Basic section, type in a Name and Description for this policy.
3. In the Settings section, select ESET Endpoint for Windows.
4. Click Override mode and configure rules for override mode.
5. In the Assign section, select the computer or group of computers on which this policy will be applied.
6. Review the settings in the Summary section and click Finish to apply the policy.
206
Example
If John has a problem with his endpoint settings blocking some important functionality or web access on his machine, the Administrator can allow John to override his existing endpoint policy and tweak the settings manually on his machine. Afterward, these new settings can be requested by ESET
PROTECT Cloud so the Administrator can create a new policy out of them.
To do so, follow the steps below:
1. Navigate to Polices > New Policy.
2. Complete the Name and Description fields. In the Settings section, select ESET Endpoint for
Windows.
3. Click Override mode, enable the override mode for one hour and select John as the AD user.
4. Assign the policy to John's computer and click Finish to save the policy.
5. John has to enable the Override mode on his ESET endpoint and change the settings manually on his machine.
6. On the ESET PROTECT Cloud Web Console, navigate to Computers, select John's computer and click Show Details.
7. In the Configuration section, click Request configuration to schedule a Client Task to get the configuration from the client ASAP.
8. After short time, the new configuration will appear. Click the product which settings you want to save and then click Open Configuration.
9. You can review settings and then click Convert to policy.
10. Complete the Name and Description fields.
11. In the Settings section, you can modify the settings if needed.
12. In the Assign section, you can assign this policy to John's computer (or others).
13. Click Finish to save the settings.
14. Do not forget to remove the override policy once it is no longer needed.
Notifications
Notifications are essential for keeping track of the overall state of your network. When a new event occurs (based on the notification configuration), you will be notified by an email to the specified email address and you can respond accordingly. The SMTP server required for sending the notifications is configured automatically, so no additional modification is required. You can configure automatic notifications based on specific events such as detected threats, out-of-date endpoints, and more. See the Notification Description for more information about a specific notification and its trigger.
To create a new notification, click
on the bottom of the page.
Select an existing notification and click Actions to
.
To add filtering criteria, click Add filter and select item(s) from the list. Enter the search string(s) into the filter field(s). Active filters are highlighted in blue.
Notifications, users and permissions
The use of Notifications is restricted by the permissions of the current user. Every time the notification is executed, there is an executing user whose permissions are taken into account. The executing user is always the one who edited the notification last. A user can see only notifications that are contained in a group for which he has Read permissions.
Important
For a notification to work well, it is necessary that the executing user has sufficient permissions for all referenced objects (devices, groups, templates). Typically, Read and Use permissions are required. If the user does not have these permissions, or he loses them afterward, the notification will fail. Failed notifications are highlighted with orange and will trigger an email to notify the user.
Create notification - To create a notification the user must have Write permissions for notifications on his home group. A new notification is created in the user's home group.
207
Modify notification - To be able to modify a notification, the user must have Write permissions for notifications on a group where the notification is located.
Remove notification - To be able to delete a notification, the user must have Write permissions for notifications on a group where the notification is located.
Example
John, whose Home Group is John’s Group, wants to remove (or modify) Notification 1. The notification was originally created by Larry, therefore it is automatically contained in Larry's Home group, Larry's Group. The following conditions must be met for John to remove (or modify)
Notification 1 :
• John must be assigned a permissions set with Write permissions for notifications
• The permissions set must contain Larry’s Group under Static Groups
Cloning and VDI
There are three
to notify user about cloning-related events or user can create a custom new notification.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Manage Notifications
Notifications are managed in the Notifications section. You can perform the following actions:
• Click
New Notification to create a new notification.
• Click an existing notification and select an action from the drop-down menu:
Show Details
Audit Log
Tags
Enable / Disable
Edit
Duplicate
Delete
Access Group >
Move
Show notification details, including its configuration, and distribution settings. Click
See message preview to see notification preview.
View the Audit Log for the selected item.
Edit tags (assign, unassign, create, delete).
Change the status of the notification. Disabled notification is not evaluated. All notifications are set to Disabled by default.
Configure the settings and distribution of the notification.
Create a duplicate notification in your home group.
Remove the notification.
Move a notification to another static group.
New Notification
Basic
Enter a Name and Description for your notification to make it easier to filter between different notifications.
If you are editing an enabled notification and you want to disable the notification, click the slider status will change to Disabled .
Configuration
• Event
and its
208
There are three basic types of events that can trigger a notification. Each type of event provides different options in the Settings section. Select one of following event types:
• Status update on ESET PROTECT Cloud
Advanced settings - Throttling
Throttling allows you to set up advanced rules that determine when a notification is triggered. See
throttling for more information.
Distribution
Configure the
distribution settings for notifications.
Events on managed computers
This option is used for notifications not associated with a Dynamic Group, but based on system events filtered out from the event log. Select a log category on which the notification will be based and a logical operator for filters.
Category - Choose from the following event categories:
• Firewall detection
• Antivirus detection
• Scan
• HIPS
• Computer first connected
• Computer identity recovered
• Computer cloning question created
• New MSP customer found
According to the selected category, there is a list of available events under Settings > Filter By. Values in filters are compared directly with the events sent by the clients. There is no definite list of available values.
Monitored static group - Select a static group with devices which will be monitored.
Settings
Under Settings, select an Operator and values for the filter (Filter By). Only one operator can be selected and all values will be evaluated together using that operator. Click Add Filter to add a new value for the filter.
Status update on ESET PROTECT Cloud
This option notifies you of object state changes. The notification interval depends on the selected Category. You can select one of existing settings or set up your own parameters.
Load settings preset - Click Select to choose one from existing settings, or leave blank. Click Clear to clear the
Settings section.
Category - Select a category of objects. According to a selected category, objects are displayed in the in the
Settings section below.
Monitored static group - For categories where the notification relates to a client (Managed clients, Installed
software) you can select a static group to be monitored. If nothing is selected, all objects where the executing user has sufficient permissions will be monitored.
209
Settings
Select an Operator and values for the filter (Filter By). Only one Operator can be selected and all values will be evaluated together using that Operator. Click Add Filter to add new value for the filter. If more filters are selected, execution of a notification is evaluated with AND operator (the notification is sent only if all filter fields are evaluated as true).
Note
Some filters may cause the notification to notify too often. It is recommended to use Throttling
to aggregate the notifications.
List of available filter values
Category Value
Managed clients
Licenses
Not connecting computers percentage
Client Tasks
Comment
A value between 0 and 100. It can be used only in combination with
Relative time interval filter.
Relative time interval Select a time interval to be monitored for a license expiration.
License usage percent A value between 0 and 100 calculated based on license Units used for activation.
Task
Task is valid
Select tasks for validity filter. If nothing is selected, all are considered.
Select Yes / No. If No is selected, notification triggers when at least one task from the selection (filter Task) is invalid.
Server tasks Count (Failed)
Last status
Task
Task is valid
Number of failures of selected tasks.
Last reported status of selected task.
Select tasks for this filter. If nothing is selected, all are considered.
Select Yes / No. If No is selected, notification triggers when at least one task from the selection (filter Task) is invalid.
Installed software
Relative time interval Select a time interval to be monitored.
Application name Full application name. If more application are monitored, use the in operator and add more fields.
Application vendor Full vendor name. If more vendors are monitored, use the in operator and add more fields.
Notifications
Version check status If Outdated version is selected, the notification triggers when at least one application is outdated.
Server state If ESET PROTECT Cloud Server is overloaded by writing logs, it changes its state:
• Normal - immediate response from server
• Limited - server responds to agent once in an hour
• Overloaded - server is not responding to agents
Notification Select notification for this filter. If nothing is selected, all are considered.
Notification is enabled Select Yes / No. If No is selected, notification triggers when at least one notification from the selection (filter Notification) is disabled.
Notification is valid Select Yes / No. If No is selected, notification triggers when at least one notification from the selection (filter Notification) is invalid.
Dynamic group changes
The notification will be sent when the condition is fulfilled. You can only select one condition to be monitored for a given dynamic group.
Dynamic group - Select a dynamic group to be evaluated.
Settings - Conditions
Select the type of condition that will trigger a notification.
• Notify everytime the dynamic group content changes
Enable this to be notified when members of the selected group are added, removed or changed.
210
Important
ESET PROTECT Cloud checks the Dynamic Group status once every 20 minutes.
For example, if the first check occurs at 10:00, the other checks are performed at 10:20, 10:40,
11:00. If the Dynamic Group content changes at 10:05 and then changes back at 10:13, during the next check performed at 10:20 ESET PROTECT Cloud does not recognize the previous change and does not notify about it.
• Notify when the group size exceeds a specific number
Select the Group size operator and Threshold for the notification:
▪ More than - Send a notification when the group size is greater than the threshold.
▪ Less than - Send a notification when the group size is less than the threshold.
• Notify when group growth exceeds a specific rate
Define a threshold and time period that will trigger a notification. You can either define a number of clients, or a percentage of clients (members of the Dynamic Group). Define the time period (in minutes, hours or days) for the comparison with the new state. For example, seven days ago the number of clients with outdated security products was 10 and the threshold was set to 20. If the number of clients with an outdated security product reaches 30, you will be notified.
• Notify when number of clients in dynamic group changes in comparison to another group
If the number of clients in a Dynamic Group changes according to a compared group (either static or dynamic), a notification will be sent. Threshold - Define a threshold that will trigger the sending of a notification.
Note
You can only assign a notification to a Dynamic Group where you have sufficient permissions. To see a dynamic group, you must have Read permission for its parent static group.
Distribution
Recipients
• Email address - Enter the email address of the recipients of the notification messages.
• Click to add a new address field.
• To add multiple users at once, click Add user (add address of the user from the
), or
Import CSV (
a custom list of addresses from a CSV file structured with delimiters).
• More > Paste from clipboard - Import a custom list of addresses separated with custom delimiters. This feature works similarly to CSV import.
Basic fields in the Distribution
• Message preview - A preview of the message that will appear in the notification. The preview contains configured settings in text form. You can customize both content and the subject of the message and use variables that will be converted to actual values when the notification is generated. This is optional, but it is recommended for better filtering of notifications and overview.
o Subject - The subject of a notification message. Click the icon to edit the content. An accurate subject can improve message sorting and filtering.
o Content - Click the icon to edit the content.
You can add variables to Subject and Content to include specific information in the notification. Click Add
variable or start typing $ to display the list of variables.
• General o Locale - Language of the default message. Message content is not translated.
o Timezone - Set the time zone for the Time of occurrence ${timestamp} variable, which can be used
211
in the customized message.
Example
If the event happens at 3:00 of local time, local time is UTC+2, selected time zone is UTC+4, the time reported in the notification would be 5:00.
Click Finish to create a new template based on the template you are editing.
Status Overview
The ESET PROTECT Cloud Server performs periodic diagnostics checkups. Use the Status Overview to see usage statistics and general status of your ESET PROTECT Cloud. It can also help you with the initial configuration of ESET PROTECT Cloud. Click Status Overview to see detailed status information about ESET PROTECT Cloud.
Click a section tile to display a taskbar on the right with actions. Each section tile can have one of several colors, which are based on the highest severity status of included items:
Color Icon
Green
Yellow
Red
Gray
Blue
Icon meaning
OK
Warning
Error
Content unavailable
Information
Description
All items in the section are without any issues.
At least one item in the section is marked with a warning.
At least one item in the section is marked with an error.
Content is unavailable due to insufficient access rights of the ESET PROTECT
Cloud Console user. An administrator needs to set additional
the user or you need to log in as another user with proper access rights.
There is a question related to connected computer(s) (see Questions section description below).
Status Overview contains the following sections:
Licenses
Computers
ESET PROTECT Cloud uses the ESET licensing system . For license management, follow up to your
ESET Business Account .
• Add Computer - Add computers on your network to the ESET PROTECT Cloud structure.
Products • New Policy - Create a new policy to change the configuration of the ESET security product installed on the client computers.
•
Install Software - With the ESET Management Agent deployed, you can install software
directly from the ESET repository or specify an installation package location (URL or a shared folder).
Invalid Objects Contains the list of client
,
with references to unreachable or invalid objects. Click any of the result fields to view a menu with the selected list of objects.
Questions
MSP Status
When a cloned device or change of hardware is detected on a client device, a question is listed.
Read more about
.
are available in instances with an MSP account .
212
More
The More section is the advanced configuration component of ESET PROTECT Cloud. This section contains tools that administrator can use to manage client security solutions, as well as the ESET PROTECT Cloud Server settings.
You can use these tools to configure your network environment in such a way that it won't require a lot of maintenance.
The More section contains the following items:
Detections o
o
o
Computers o
o
Licenses o
o
o
Activity Audit o
Admin o
Submitted Files
ESET Dynamic Threat Defense is a service that provides advanced protection from never-before-seen detections.
ESET PROTECT Cloud user can submit files for malware analysis in the cloud environment and receive a report about sample behavior. See the ESET Dynamic Threat Defense User guide for step-by-step instructions.
213
The Submitted files window provides a list of all files submitted to ESET servers. These include files automatically sent to ESET LiveGrid® from client computers (in case ESET LiveGrid® is enabled in their ESET security product) and files sent to ESET Dynamic Threat Defense manually from ESET PROTECT Cloud Web Console.
Submitted files window
You can see the list of submitted files and information related to those files, like the user who submitted the file and submission date. Click the submitted file and select an action from the drop-down menu.
Show Details
View Behavior
Create Exclusion
State
Last processed on
Sent on
Behaviors
Computer
User
Reason
Sent to
Hash
Size
Category
Click to view the latest submission tab.
View the behavioral analysis report for a given sample.
Select one or more files and click Create Exclusion to add a detection exclusion for the selected files to an existing policy.
File Details Window
File Details window contains a list of file details for the selected file. It a file is submitted multiple times, details for the last submission are displayed.
Status Result of malware analysis.
Unknown - the file was not analyzed.
Clean - none of the detection engines evaluated file as malware.
Suspicious, Highly suspicious - the file displays suspicious behavior but may not be malware.
Malicious - the file displays dangerous behavior.
State of the analysis. The status Re-analyzing means the result is available, but it may change after further analysis.
A file can be submitted for analysis many times, from more computers. This is the time of the last analysis.
The time of submission.
Click View behavior to see the analysis from ESET Dynamic Threat Defense. This is only valid if the computer which submitted the file has an active ESET Dynamic
Threat Defense license.
The name of the computer from which the file was submitted.
Computer user who submitted the file.
The reason the file was submitted.
Part of the ESET cloud that has received the file. Not every submitted file is analyzed for malware.
SHA1 hash of the submitted file.
Size of the submitted file.
Category of the file. Category may not follow the file extension.
For more information about ESET Dynamic Threat Defense behavioral reports see the documentation .
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Exclusions
new section contains all exclusions, increases their visibility and simplifies their management.
Click an exclusion or select more exclusions and click the Actions button to manage the exclusions:
214
• Change Assignment - Change the target computers where the exclusion will be applied.
• Show Affected Computers - See computers where the exclusion is applied.
• Delete - Delete the exclusion.
• Access Group > Move - Move the exclusion to a different static group.
If the excluded detection or firewall action appears again on the managed computers, the Hit count column displays the number of times the exclusion has been applied.
Migrate exclusions from a Policy
In ESET PROTECT Cloud, you cannot create Antivirus detection exclusions via a Policy. In case your policies previously contained exclusions, follow the steps below to migrate exclusions from Policies to the Exclusions list in ESET PROTECT Cloud:
1. Navigate to Policies and click the policy that contains exclusions and select Show Details.
2. Click Settings > Detection Engine.
3. Click View next to Detection exclusions.
215
4. Click the Export button and then click the button next to Download exported data and save the
export.txt file. Click OK.
5. In the ESET PROTECT Cloud Web Console, navigate to More > Exclusions.
6. Click the Import button to import detection exclusions from a file. Click Choose file to upload and navigate to the export.txt file or drag and drop the file.
216
7. Click the Import button to import the detection exclusions. Imported detection exclusions will appear in the exclusions list.
Warning
• The original exclusion assignments are not preserved. Imported detection exclusions are by default assigned to computers in your home group. To change the exclusion assignment, click the exclusion and select Change assignment.
• You can assign exclusions (for Antivirus detections and Firewall IDS rules) only to
computers with a compatible ESET security product installed. Exclusions will not be applied to
incompatible ESET security products and will be ignored on them.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Quarantine
This section shows all files quarantined on client devices. Files should be quarantined if they cannot be cleaned, if it is not safe or advisable to delete them, or if they are being falsely detected by an ESET product.
Note
Not all detections found on client devices are moved to quarantine. Detections that are not quarantined include:
• Detections that cannot be deleted.
• Detections that are suspicious based on their behavior, but are not identified as malware, for example, PUAs .
217
You can Delete the quarantined file or Restore it to its previous location. You can use Restore and Exclude the quarantined file to prevent it from being reported by the ESET product again.
You can use various filters to filter the list of files in quarantine.
There are two ways to access Quarantine:
1. More > Quarantine.
2. Computer details > Detections and quarantine > Quarantine tab.
If you click an item in the Quarantine section you will open Quarantine Management menu.
Show Details - Displays the source device, detection name and type, object name with full file path, hash, size, etc.
Computers - Opens
Computers section with filtered devices connected with the quarantined file.
Delete - Removes the file from quarantine and the affected device.
Restore - Restores the file to its original location.
Restore and Exclude - Restores the file to its original location and excludes it from scanning.
Upload - Opens Upload Quarantined File task. This action is available after you click Show Details.
Important
The Upload function is recommended only for experienced users. If you want to investigate the quarantined file more, you can Upload it to a shared directory.
Filters and layout customization
218
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Computer Users
Computer Users section allows you to manage Users and User Groups. You can pair a user with a device in order to synchronize some user-specific settings. Upon creation of a new computer, you can pair the computer with a specific user. You can then search for the user to view details about computers assigned to them and their activity.
Important
Computer Users are different from ESET PROTECT Cloud Web Console users. Computer Users section allows you to pair a user with a device in order to synchronize some user-specific settings. To manage ESET PROTECT Cloud Web Console users and permission sets, navigate to ESET Business
Account.
• User highlighted in orange have no device assigned to them. Click the user, select
and click
Assigned Computers to view details for that user. Click Add computers to assign device(s) to this user.
• You can also add or remove Assigned users from within
. When you are in Computers, select a device and click Show Details. The user can be assigned to more than one device. You can also use Assign User to assign a user directly to selected device(s). If there is a device assigned to a user, you can click the device name to view details about that device.
• You can Drag & Drop users and user groups. Select the user (or group), hold the mouse button and move it to another group.
User management actions
actions.
Show Details - The menu displays information such as Email Address, Office or Location, and Assigned
Computers. The user can have more than one assigned device. You can change the user's Name, Description or
Parent Group.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Add New Users
1. Click Computer Users > Add Users to add users.
219
220
2. Type the name of the user you want to add into the User Name field. Click + Add to add additional users. If
added. Click Copy & Paste to import a custom list of addresses separated with custom delimiters (this feature works similarly to CSV import). Optionally, you can enter a Description of the users for easier identification.
3. You can select an existing Parent Group or create a new group.
4. Click Select tags to assign tags .
5. Use the Conflict Resolution drop-down menu to select the action to take if a user you are adding already exists in ESET PROTECT Cloud:
• Ask when conflicts are detected: When a conflict is detected, the program will ask you to select an action (see the options below).
• Skip conflicting users: Users with the same name will not be added.
• Overwrite conflicting users: Existing users in ESET PROTECT Cloud will be overwritten. If two users have the same SID, the existing user in ESET PROTECT Cloud is removed from its previous location (even if the user was in a different group).
6. Click Add when you are finished making changes. Users will appear in the parent group that you specified.
Edit Users
You can modify user's details such as Basic information and Assigned Computers.
Basic
Here you can edit user details such as:
• User Name and Description - For informative purposes only.
• Tags - Edit tags (assign, unassign, create, delete).
• Email Address - You can use it as recipient address for delivery of notifications.
• Phone and Office or Location - For informative purposes only.
• SID - Can be associated with several ESET PROTECT Cloud functions that require this AD information (for
example Endpoint Policy Override mode ).
221
Assigned Computers
Here you can select individual devices. To do so, click Add Computers - all Static and Dynamic Groups with their members will be listed. Use check boxes to make your selection and click OK.
Create New User Group
Click Computer Users > and select New User Group
222
Basic
Enter a Name and Description (optional) for the new User Group. By default, the parent group is the group you selected when you started creating the new User Group. If you want to change its parent group, click Change
Parent Group and select a parent group from the tree. Click Finish to create the new User Group.
Dynamic Group Templates
Dynamic group templates establish the criteria computers must meet to be placed in a
. When these criteria are met by a client, a client will automatically be moved into the appropriate Dynamic Group.
Note
A template is a static object stored in a Static group. Users must have appropriate
access templates. A user needs access permissions to be able to work with Dynamic Group templates. All pre-defined templates are located in the static group All and are by default available only to the Administrator. Other users need to be
assigned additional permissions . As a result, users
may be unable to see or use default templates. The templates can be moved to a group where the users have permissions.
To duplicate a template, the user must be assigned Use permissions (for Dynamic Group templates) for the group where the source template is located, and Write permissions for the user's home group (where the duplicate will be stored). See the object duplication example .
• Create New Dynamic Group Template
• Rules for a Dynamic Group Template
• Dynamic Group Template - examples
Manage Dynamic Group Templates
Templates can be managed from More > Dynamic Group Templates.
New Template Click to create a
New Template in your home group.
223
Show Details
Audit Log
Tags
Edit
Duplicate
Delete
Import
Export
Access Group
See the summary of information about selected template.
View the
Audit Log for the selected item.
Edit tags (assign, unassign, create, delete).
Edit selected template. Click Save as if you want to keep your existing template and create a new one based on the template you are editing. When prompted, specify the name for your new template.
Create a new Dynamic Group Templates based on the selected template. A new name will be required for the duplicate task. The duplicated template will be stored in your home group.
Remove the template permanently.
Import Dynamic Group Templates from a file. During import, file structure is being verified to ensure file is not corrupted.
Export the selected Dynamic Group Templates to a file for backup or migration purposes. We do not recommend any edits to the file - they may make the data unusable.
Move selected template to another static group. This is useful when solving access
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
New Dynamic Group Template
Click New Template under More > Dynamic Group Templates.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Click Select tags to assign tags .
Expression
with illustrated step-by-step instructions for samples of how to use Dynamic Groups on your network.
224
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
Rules for a Dynamic Group template
When you set rules for a Dynamic Group template, you can use different operators for different conditions to achieve your desired scenario.
The following chapters explain rules and operations used in Dynamic Group templates:
• Rules and logical connectors
• How to create automation in ESET PROTECT Cloud
• Use cases - create a specific Dynamic Group template
Operations
If you specify multiple rules (conditions), you must select which operation should be used to combine the rules.
Depending on the result, a client computer will or will not be added to a Dynamic Group which uses this Template.
Note
• The selected Operation works not only when combining more rules, but also when there is only one rule.
• It is not possible to combine operations. Only one operation is used per Dynamic Group Template and applies to all its rules.
AND (All conditions have to be true)
225
Checks if all conditions are evaluated positively – computer must meet all required parameters.
OR (At least one condition has to be true)
Checks if at least one of the conditions is evaluated positively – computer must meet at least one of the required parameters.
NAND (At least one condition has to be false)
NOR (All conditions have to be false)
Checks if at least one of the conditions cannot be evaluated positively – computer must not meet at least one parameter.
Checks if all conditions cannot be evaluated positively – computer doesn't meet any of required parameters.
Rules and logical connectors
A rule consists of an item, logical connector (logical operator) and defined value.
When you click + Add Rule a pop-up window will open with a list of items divided into categories. For example:
Installed software > Application name
Network adapters > MAC address
OS edition > OS name
You can browse the list of all available rules in this ESET Knowledgebase article .
To create a rule, select an item, choose a logical operator and specify a value. The rule will be evaluated according to the value you've specified and the logical operator used.
Acceptable value types include number(s), string(s), enum(s), IP address(es), product masks and computer IDs.
Each value type has different logical operators associated with it and ESET PROTECT Cloud Web Console will automatically show only supported ones.
• "= (equal)" - Symbol value and template value must match. Strings are compared without case sensitivity.
• "> (greater than)" - Symbol value must be greater than template value. Can also be used to create a range comparison for IP address symbols.
• "≥ (greater or equal)" - Symbol value must be greater or equal to template value. Can also be used to create a range comparison for IP address symbols.
• "< (less than)" - Symbol value must be less than template value. Can also be used to create a range comparison for IP address symbols.
• "≤ (less or equal)" - Symbol value must be less than or equal to template value. Can also be used to create a range comparison for IP address symbols.
• "contains" - Symbol value contains template value. In case of strings, this searches for a sub-string.
Search is done without case sensitivity.
• "has prefix" - Symbol value has the same text prefix as template value. Strings are compared without case sensitivity. Set the first characters from your search string, for example, for "Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319", the prefix is "Micros" or "Micr" or "Microsof"etc.
• "has postfix" - Symbol value has same text postfix as template value. Strings are compared without case sensitivity. Set the first characters from your search string, for example, for "Microsoft Visual C++ 2010 x86
Redistributable - 10.0.30319", the postfix is "319" or "0.30319", etc.
• "has mask" - Symbol value must match a mask defined in a template. Mask formatting allows any characters, the special symbols '*' - zero, one or many characters and '?' exactly one character, e.g.: "6.2.*" or "6.2.2033.?".
• "regex" - Symbol value must match the regular expression (regex) from a template. Regex must be written in Perl format.
Note
A regular expression, regex or regexp is a sequence of characters that define a search pattern. For example, gray|grey and gr(a|e)y are equivalent patterns which both match these two words: "gray",
"grey".
• "is one of" - Symbol value must match any value from a list in a template. To add an item, click + Add.
Each line in a new item in the list. Strings are compared without case sensitivity.
226
• "is one of (string mask)" - Symbol value must match any mask from a list in a template. Strings are compared with case sensitivity. Examples: *endpoint-pc*, *Endpoint-PC*.
• "has value"
Negated operators:
Important
Negated operators must be used with care, because in the case of multiple line logs such as
"Installed application", all lines are tested against these conditions. Please consult the included examples (
Dynamic Group template - examples ) to see how negated
operators or negated operations must be used to get expected results.
• "≠ (not equal)" - Symbol value and template value must not match. Strings are compared without case sensitivity.
• "doesn't contain" - Symbol value does not contain template value. Search is done without case sensitivity.
• "doesn't have prefix" - Symbol value does not have the same text prefix as template value. Strings are compared without case sensitivity.
• "doesn't have postfix" - Symbol value does not have text postfix as template value. Strings are compared without case sensitivity.
• "doesn't have mask" - Symbol value must not match a mask defined in a template.
• "not regex" - Symbol value must not match a regular expression (regex) from a template. Regex must be written in Perl format. Negation operation is provided as a helper to negate matching regular expressions without rewrites.
• "is not one of" - Symbol value must not match any value from the list in a template. Strings are compared without case sensitivity.
• "is not one of (string mask)" - Symbol value must not match any mask from a list in a template.
• "has no value"
Template rules evaluation
Template rules evaluation is handled by ESET Management Agent, not ESET PROTECT Cloud Server (only the result is sent to ESET PROTECT Cloud Server). The evaluation process happens according to the
that are configured in a Template. Below are a few examples of template rules evaluation process.
Example
You need to distinguish between test for existence (something does not exist at all with that value) and test for difference (something exists but has different value). Here are some basic rules to make this distinction:
• To verify existence: Operation without negation (AND, OR) and operator without negation (=, >,
<, contains,...).
• To verify existence of a different value: Operation AND and operators including at least one negation (=, >, <, contains, does not contain,...).
• To verify non-existence of a value: Operations with negation (NAND, NOR) and operators without negation (=, >, <, contains,...).
To verify presence of a list of items (for example, a specific list of applications installed on a computer), you need to create a separate Dynamic Group template for each item in the list and assign the template to a separate Dynamic Group, each Dynamic Group being a sub-group of another. Computers with the list of items are in the last sub-group.
Status is a cluster of various information. Some sources provide more than one dimensional status per machine
(for example, Operating System, RAM size, etc.), others provide multidimensional status information (for example,
IP Address, Installed Application, etc).
Below is a visual representation of the status of a client:
227
Network Adapters - IP
Address
192.168.1.2
10.1.1.11
124.256.25.25
Network Adapters - MAC
Address
4A-64-3F-10-FC-75
2B-E8-73-BE-81-C7
52-FB-E5-74-35-73
OS Name
Windows 7
Enterprise
OS Version HW -
RAM size in MB
6.1.7601
2048
Installed Application
ESET Endpoint
Security
PDF Reader
Office Suite
Weather Forecast
Status is made of information groups. One group of data always provides coherent information organized into rows.
The number of rows per group may vary.
Conditions are evaluated per group and per row - if there are more conditions regarding the columns from one group, only the values on the same row are considered.
Example 1:
For this example consider the following condition:
Network Adapters.IP Address = 10.1.1.11 AND Network Adapters.MAC Address = 4A-64-3F
-10-FC-75
This rule matches no computer, as there is no such row where both conditions hold true.
Network Adapters - IP
Address
192.168.1.2
10.1.1.11
124.256.25.25
Example 2:
Network Adapters - MAC
Address
4A-64-3F-10-FC-75
2B-E8-73-BE-81-C7
52-FB-E5-74-35-73
OS Name
Windows 7
Enterprise
OS Version HW -
RAM size in MB
6.1.7601
2048
Installed Application
ESET Endpoint
Security
PDF Reader
Office Suite
Weather Forecast
For this example consider the following condition:
Network Adapters.IP Address = 192.168.1.2 AND Network Adapters.MAC Address = 4A-64-
3F-10-FC-75
This time, both conditions match cells on the same row and therefore, the rule as a whole is evaluated as TRUE.
The computer is selected.
Network Adapters - IP
Address
Network Adapters - MAC
Address
OS Name OS Version HW -
RAM size in MB
6.1.7601
2048
Installed Application
192.168.1.2
4A-64-3F-10-FC-75 Windows 7
Enterprise
10.1.1.11
124.256.25.25
Example 3:
2B-E8-73-BE-81-C7
52-FB-E5-74-35-73
For conditions with the OR operator (at least one condition must be TRUE), such as:
ESET Endpoint
Security
PDF Reader
Office Suite
Weather Forecast
Network Adapters.IP Address = 10.1.1.11 OR Network Adapters.MAC Address = 4A-64-3F-
228
10-FC-75
The rule is TRUE for two rows, as only either of the conditions must be satisfied. The computer is selected.
Network Adapters - IP
Address
Network Adapters - MAC
Address
192.168.1.2
4A-64-3F-10-FC-75
10.1.1.11
124.256.25.25
2B-E8-73-BE-81-C7
52-FB-E5-74-35-73
Dynamic Group template - examples
OS Name
Windows 7
Enterprise
OS Version HW -
RAM size in MB
6.1.7601
2048
Installed Application
ESET Endpoint
Security
PDF Reader
Office Suite
Weather Forecast
You can find useful pre-defined Dynamic Group templates in More > Dynamic Group Templates.
The sample Dynamic Group templates and examples of their use in this guide demonstrate some of the ways you can use Dynamic Groups to manage your network:
Dynamic Group that detects if a security product is installed
Dynamic Group that detects if a specific version of a software is installed
Dynamic Group that detects if a specific version of software is not installed
Dynamic Group that detects if a computer is in a specific subnet
Dynamic Group that detects installed but not activated versions of server security products
Automatically deploy ESET products on newly connected Windows desktops
See also our Knowledgebase articles with examples of Dynamic Group templates and their use:
Useful Dynamic Group template examples in ESET PROTECT Cloud - examples how you can use
details to create rules for a Dynamic Group containing the devices that meet the selected HW criteria.
Configure ESET PROTECT Cloud to automatically deploy ESET endpoint products to unprotected computers
Configure endpoints to use different update settings depending on the network they are connected to using ESET
PROTECT Cloud
Create a new certificate for new workstations to automatically join a Dynamic Group in ESET PROTECT Cloud
Note
Knowledgebase articles may not be available in your language.
There are many other objectives that can be achieved using Dynamic Groups Templates with a combination of rules. The possibilities are almost endless.
Dynamic Group - a security product is installed
This Dynamic Group can be used to execute task immediately after ESET security product is installed on a machine: Activation, Custom scan, etc.
You can create a New Template under More > Dynamic Group Templates and create new Dynamic Group with template.
229
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
1. Select a logical operator in the
menu: AND (All conditions have to be true).
2.
Click + Add Rule and select a condition
. Select Computer > Managed products mask > is one of >
ESET protected: Desktop. You can also choose different ESET products.
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
Dynamic Group - a specific software version is installed
This Dynamic Group can be used to detect installed ESET security software on a machine. Then you will be able to execute for example upgrade task or run custom command on those machines. Different operators like "contains" or "has prefix" can be used.
You can create a New Template under More > Dynamic Group Templates and create new Dynamic Group with template.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
1. Select a logical operator in the
menu: AND (All conditions have to be true).
2.
Click + Add Rule and select a condition
:
• Installed software > Application name > = (equal) > ESET Endpoint Security
• Installed software > Application version > = (equal) > 6.2.2033.0
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
Dynamic Group - a specific version of a software is not installed at all
This Dynamic Group can be used to detect missing ESET security software on a machine. The settings from this example will include machines that do not contain the software at all or machines with different versions than one specified.
This group is useful because you will be able to execute software installation task on those computers to either install or upgrade. Different operators like "contains" or "has prefix" can be used.
Click New Template under More > Dynamic Group Templates.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
1. Select a logical operator in the
menu: NAND (At least one condition has to be false).
2.
Click + Add Rule and select a condition
:
• Installed software > Application name > = (equal) > ESET Endpoint Security
• Installed software > Application version > = (equal) > 6.2.2033.0
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
230
Dynamic Group - a specific version of a software is not installed but other version exists
This Dynamic Group can be used to detect software that is installed but with different version than you are requesting. This group is useful because you will be able to execute upgrade tasks on those machines where the required version is missing. Different operators can be used but make sure that version testing is done with negated operator.
Click New Template under More > Dynamic Group Templates.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
1. Select a logical operator in the
menu: AND (All conditions have to be true).
2.
Click + Add Rule and select a condition
:
• Installed software > Application name > = (equal) > ESET Endpoint Security
• Installed software > Application version > ≠ (not equal) > 6.2.2033.0
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
Dynamic Group - a computer is in specific subnet
This Dynamic Group can be used to detect specific subnet. Then it can be used to apply custom policy for web control or update. You can specify different ranges.
Click New Template under More > Dynamic Group Templates.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
1. Select a logical operator in the
menu: AND (All conditions have to be true).
2.
Click + Add Rule and select a condition
:
• Network IP addresses > Adapter IP address > ≥ (greater or equal) > 10.1.100.1
• Network IP addresses > Adapter IP address > ≤ (less or equal) > 10.1.100.254
• Network IP addresses > Adapter subnet mask > = (equal) > 255.255.255.0
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
Dynamic Group - installed but not activated version of server security product
This Dynamic Group can be used to detect inactive server products. Once these products are detected, you can assign a Client Task to this group to activate client computers with proper license. In this example only ESET Mail
Security for Microsoft Exchange Server is specified, but you can specify multiple products.
Click New Template under More > Dynamic Group Templates.
Basic
Enter a Name and a Description for the new Dynamic Group template.
Expression
231
1. Select a logical operator in the
menu: AND (All conditions have to be true).
2.
Click + Add Rule and select a condition
:
• Computer > Managed products mask > is one of > ESET protected: Mail Server
• Functionality/Protection problems > Source > = (equal) > Security product
• Functionality/Protection problems > Problem > = (equal) > Product not activated
Summary
Review the configured settings and click Finish to create the template. This new template will be added to the list of all templates, and can be used later to
.
How to automate ESET PROTECT Cloud
By using techniques like the example shown below, you can automate a variety of actions, from product and OS updates, scanning, and automatic activations of newly added products with preselected licenses, to solving sophisticated incidents.
Automatically deploy ESET products on newly connected Windows desktops
Warning
This example should be performed only on clients without third-party security software or ESET security software from home segment (e.g. ESET Smart Security). The installation of ESET products on clients with third-party security software is not recommended. You can use ESET AV Remover to remove other antivirus programs from your computer.
Example
, called Without security product.
a.
Make it a child group of the pre-defined group Windows computers > Windows (desktops).
b.
Click New Template.
c.
Add the following rule: Computer > Managed products mask.
d.
As operator select not equal.
e.
Select the mask ESET protected: Desktop f.
Click Finish to save the group.
2. Navigate to Tasks > New > Client Task.
a.
Select Software Install from the Task drop-down menu and type the name of the task a Name.
b.
Choose the package in the Settings section and set other parameters if needed.
c.
Click Finish > Create Trigger.
d.
In the Target section, click Add Groups and select Without security product.
e.
In the Trigger section, select Joined Dynamic Group Trigger.
f.
Click Finish to save the task and the trigger.
This task will be executed on clients connected to the dynamic group since this moment. You will need to execute this task manually on clients which were in the dynamic group before the task was created.
Enforce location-based policy
232
Example
called Subnetwork 120.
a.
Make it a child group of the All group.
b.
Click New Template.
c.
Add rule: Network IP addresses > IP subnetwork.
d.
As operator select equal.
e.
Enter the subnetwork you want to filter, for example, 10.1.120.0 (the last number has to be 0 to filter all the IP addresses from the 10.1.120. subnetwork).
f.
Click Finish to save the group.
2. Navigate to Policies. a.
Click New policy and give the policy a Name.
b.
In the Settings section, select ESET Management Agent.
c.
Make the policy change; for example, change the Connection interval to 5 minutes.
d.
In the Assign section, click Assign and select the check box next to your group Subnetwork
120 and click OK to confirm.
e.
Click Finish to save the policy.
This policy will be applied on clients connected to the dynamic group since this moment.
Warning
See policy removal rules to verify what happens to the applied policy settings when the client machine leaves the dynamic group (conditions matching the dynamic group membership are not valid anymore).
See other examples listed
License Management
You can easily manage your licenses via ESET PROTECT Cloud from the main menu under More > License
Management. You can see here licenses synchronized from the ESET Business Account that you used for deployment of ESET PROTECT Cloud.
Important
To use licenses from another ESET Business Account, you need to move licenses to the ESET
Business Account that you used for deployment of ESET PROTECT Cloud.
your ESET business product using ESET PROTECT Cloud.
Permissions for license management
Each user can be assigned a permission
for Licenses. Permissions are valid only for licenses contained in the static group where that permission set is assigned. Each type of permission allows a user to perform
Important
Only Administrators whose home group is set to All, with Write permission for licenses in the home group can add or remove licenses. Each license is identified by its Public ID and can contain one or more units. Licenses can only be distributed by the Administrator to other users with sufficient
permissions . A license is not reducible.
When you import an MSP account, all licenses are stored in one license pool. You cannot move a license out of the pool. You can move the whole license pool. To move the pool, select the pool > Actions > Access Group > Move and select the new access group. If you synchronize the MSP account afterwards, any new licenses appear in the pool's actual location.
License Management in Web Console
233
Licenses from the same ESET Business Account user or the same company are grouped into license pools. Click to expand the license pool and see license details.
In ESET Business Account and ESET PROTECT Cloud, each license is identified by:
• Public ID
• License Type - Business (paid license), Trial (trial license), MSP (Managed Services Provider license), and NFR (Not For Resale license).
The additional license information includes:
• The license Owner name and Contact.
• The License User name and type: Company, Site, MSP Customer.
• The security Product name for which its license is intended.
• License Status (if the license is expired, overused, or at risk of expiration or overuse, a warning message will be displayed here).
• The number of Units that can be activated with this license and number of offline units.
• The number of Subunits of ESET server products (mailboxes, gateway protection, connections).
• The license Expiration date.
o Subscription licenses might not have an expiration date.
You can filter licenses by their Status:
OK - Green
Erorr(s) - Red
Your license is activated successfully.
The license is not registered, or the license has expired.
Warning(s) - Orange
Your license is still depleted or is about to expire (expiration is due in 30 days).
Deactivated or suspended Your license is deactivated or suspended.
Obsolete
Your license has expired.
Click the Actions button to manage the selected license pool(s):
234
Tags
Edit tags (assign, unassign, create, delete).
Remove Licenses Remove the selected license pool(s). You will be asked to confirm this action. Removal of the license does not trigger deactivation of the product. Your ESET product will remain activated even after the license has been deleted in ESET PROTECT Cloud License
Management.
Access Group
Move the selected license pool(s) to another Static Group.
Synchronize
Licenses
Open EMA
Refresh license information in ESET PROTECT Cloud immediately. Licenses synchronize automatically once a day with ESET license servers. If you are using ESET Business
Account, ESET License Administrator, or ESET MSP Administrator licenses synchronize automatically once a day also with these services.
Open the ESET MSP Administrator portal .
Open EBA
Open the ESET Business Account portal .
Expand a license pool and click a license to perform the following actions. The action set depends on the type of selected license:
Use License For
Activation
Run Product Activation task using this license.
Create All-in-one installer Use the selected license in the
.
Tags
Edit tags (assign, unassign, create, delete).
Manage license
Renew license
Upgrade license
If the license is synchronized from ESET Business Account or ESET MSP
Administrator, you can manage the license.
Renew the expiring, expired, suspended or deactivated license in ESET Business
Account or ESET MSP Administrator.
Upgrade the trial license in ESET Business Account or ESET MSP Administrator.
Audit Log
View the
Audit Log for the selected item.
Subscription licenses
ESET PROTECT Cloud supports management of subscription licenses. You can check your subscription's validity under License Management in the Validity column or Computers > Show Details .
Support for ESET Business Account Sites
You can import the complete structure of your ESET Business Account, including the distribution of license seats among the sites .
Activation of ESET business products
Important
You cannot use ESET PROTECT Cloud license for activation of ESET security products on managed endpoints. To activate individual ESET security products, use the applicable licenses for those products.
You can distribute licenses to ESET products from ESET PROTECT Cloud using two tasks:
• The software installation task
Deactivation of ESET business products
You can deactivate the ESET business product (remove the license from the product) in several ways using the
ESET PROTECT Cloud Web Console:
235
• in Computers, select the computer(s) and select Deactivate Products - Remove license from all selected devices via ESET license server. Product is deactivated even if it was not activated from ESET
PROTECT Cloud or license is not managed by ESET PROTECT Cloud.
Note
If you select only one computer with more ESET products installed (for example ESET endpoint product and ESET Enterprise Inspector Agent), you can select to deactivate individual products.
• Remove computer from management
•
Create the Delete Not Connecting Computers
Task with the Deactivate License option.
Filters and layout customization
You can customize the current Web Console screen view:
• Manage the side panel and main table .
•
Add filters and filter presets. You can use
for filtering the displayed items.
Sharing licenses among branch admins
Example
There are three users and Administrator, each user has their own home group:
• John, San Diego
• Larry, Sydney
• Makio, Tokyo
The administrator imports 3 licenses. These are contained in the static group All and other users cannot use them.
To assign a license to another user, the administrator can select the check box next to the license pool they want to assign to another user, click the Actions button and then click Access Group
> Move and select group where that user has permission. For the user John, select the group San
Diego. John needs to have Use permission for Licenses in the group San Diego to use the license.
When the user John logs in, he can only see and use the license that was moved to his group. The administrator should repeat the process for Larry and Makio, afterward, users can see only their license, while Administrator can see them all.
Access Rights
Access rights let you manage ESET PROTECT Cloud Web Console
.
The security model
Important
These access rights settings apply only to users when a Custom permission is set in the ESET
Business Account (EBA) account management. Custom permissions can be added in the ESET
PROTECT Cloud Web Console only by an account with Superuser permissions in the ESET Business
Account portal.
These are key terms used in the security model:
Term Explanation
Home Group Home Group is the group where all objects (devices, tasks, templates, etc.) a user creates are automatically stored. Each user must only have one home group.
236
Object Objects are located in Static Groups. Access to objects is by groups, not users (providing access by group makes it easy to accommodate multiple users, for example, if one user is on holiday).
notifications are exceptions that require an "executing" user.
Access Group Access Group functions as a static group which allows users to filter the location of the object based on access rights.
Administrator A user that has home group All with a full Permission Set over the group is effectively an administrator.
of all access rights and their functions for more details.
Permission Set A Permission Set represents the permissions for users that access ESET PROTECT Cloud Web
Console. They define what the user can see or do in ESET PROTECT Cloud Web Console. A user can be assigned multiple Permission Sets.
Permission sets are applied only over objects in defined
groups. These Static Groups are set in the Static Groups section when creating or editing a permission set.
Functionality A functionality is one type of object or action. Typically, functionalities get these values: Read,
Write, Use. The combination of functionalities applied to an Access Group is called a Permission
Set.
List of Access Rights related examples
There are various examples across Administration guide concerning access rights. This is a list of them:
• How to duplicate policies
• Difference between Use and Write
• How to create a solution for branch office admins
•
How to share objects via duplication
• How to allow user to create installers
•
• How to create policies
• Allow users to see all policies
• Share licenses among branch admins
Users
User management is part of the More section of the ESET PROTECT Cloud Web Console.
Important
A fresh ESET PROTECT Cloud setup has the Administrator (Native User with home group All and access to everything) as the only user.
• We do not recommend using this user account on a regular basis. We strongly advise that you
create another administrator account
. Use the default administrator account only as a backup option.
• You can also create additional users with narrower access rights based on your desired competences.
• Optionally, you can set up
Two-Factor Authentication for ESET PROTECT Cloud Web Console users.
This will increase security when logging into and accessing ESET PROTECT Cloud Web Console.
Branch office admins solution
237
Example
If a company has two offices, each with local admins, they need to be assigned with more permission sets for different groups.
Let's say there are admins John in San Diego and Larry in Sydney. Both of them need to take care only of their local computers, use Dashboard, Policies, Reports and Dynamic Groups
Templates with their machines. The main Administrator has to follow these steps:
1. Create new
Static Groups : San Diego office, Sydney office.
2. Create new
a.
Permission set called Sydney permission set, with Static Group Sydney office, and with full access permissions (exclude Server Settings).
b.
Permission set called San Diego permission set, with Static Group San Diego office, and with full access permissions (exclude Server Settings).
c.
Permission set called All Group / Dashboard, with Static Group All, with the following permissions:
• Read for Client Tasks
• Use for Dynamic Group Templates
• Use for Reports and Dashboard
• Use for Policies
• Use for Send Email
• Use for Send SNMP Trap
• Use for Export report to file
• Use for Licenses
• Write for Notifications
John with home group San Diego office, assigned with the permission sets San
Diego permission set and All Group / Dashboard.
4. Create new user Larry with home group Sydney office, assigned with the permission sets Sydney
permission set and All Group / Dashboard.
If permissions are set like this, John and Larry can use same tasks and policies, reports and dashboard, use dynamic group templates without restrictions; however each can only use templates for machines contained in their home groups.
Sharing objects
If an Administrator wants to share objects, such as dynamic group templates, report templates, or policies, the following options are available:
• Move those objects into shared groups
• Create duplicate objects and move them into static groups which are accessible to other users (see the example below)
Example
For an object duplication the user needs to have Read permission on the original object and Write permission on his Home Group for this type of action.
Administrator, whose home group is All, wants to share Special Template with user John. The template was originally created by Administrator, therefore it is automatically contained in the group
All. Administrator will follow these steps:
1. Navigate to More > Dynamic Group Templates.
2. Select the Special Template and click Duplicate, if needed, set name and description and click
Finish.
3. The duplicated template will be contained in the home group of Administrator, group All.
4. Navigate to More > Dynamic Group Templates and select the duplicated template, click
Access Group > Move and select the destination static group (where John has permission). Click
OK.
How to share objects among more users via Shared Group
To better understand how the new security model works, see the scheme below. There is a situation where there are two users created by the administrator. Each user has his own home group with objects he has created. San
238
Diego permission set gives John rights to manipulate Objects in his home group. The situation is similar for Larry. If these users need to share some objects (for example, computers), these objects should be moved to Shared Group
(a static Group). Both users should be assigned with Shared permission set which has Shared Group listed in the
Static Groups section.
San Diego office
San Diego permission set
Objects I.
John
Shared Group
Shared permission set
Objects III.
Larry
Sydney office
Sydney permission set
Objects II.
Filters and layout customization
You can customize the current Web Console screen view:
•
•
You can use tags for filtering the displayed items.
User actions and user details
To manage a user, select the applicable user and select one of the available actions:
Actions
• Show Details - View user details .
•
Audit Log - View the Audit Log for all users.
•
Audit Log for selected user - View the Audit Log for the selected user.
• Tags - Edit tags (assign, unassign, create, delete).
•
Assign permission sets - Assign a permission set
to the user.
Access Rights
• Access Group > Move - Move the user to another Static Group.
239
User details
There are two sections in user details:
• Overview - Basic information about the user. You can manage the user using the Actions and Two-
Factor Authentication buttons at the bottom.
• Permission Sets - The list of permission sets assigned to the user. Click a permission set to
it.
Assign a Permission Set to a User
1. There a two ways to assign a permission set to a user: a) Click More > Users > click a user and select Assign Permission Sets to assign specific permission sets to the user.
b) In the Users section, edit a specific user by clicking Edit.
240
2. Select the check box next to a specific Permission Set in the Unassigned (Available) Permission Sets section. See
Manage Permission Sets for more details.
Two-Factor Authentication
• Two-Factor Authentication (2FA) provides a more secure method to log into and access ESET PROTECT
Cloud Web Console.
• 2FA is provided by ESET using ESET Secure Authentication technology. You do not need to deploy or install
241
ESET Secure Authentication within your environment, as ESET PROTECT Cloud automatically connects to ESET servers to authenticate users who log into your ESET PROTECT Cloud Web Console.
• Users with 2FA enabled will be required to log into ESET PROTECT Cloud using ESET Secure Authentication .
• For more information about product features and benefits, visit the ESET Secure Authentication product page .
• There is no limit to the number of users who can log into ESET PROTECT Cloud via ESA 2FA.
• HTTP Proxy settings are not applied for communication with Secure Authentication servers (2FA).
• You can enable 2FA also for the Administrator account.
Prerequisites
• To enable 2FA for another user's account, one needs to have Write permission over that user. Once enabled, a user needs to configure 2FA themselves before they can log in. Users will receive a link via text message (SMS), which they can open in their phone's web browser to view instructions for configuring 2FA.
• 2FA does not work without direct network access to ESET 2FA servers . Allowing at least specific 2FA servers in the firewall is necessary. If the proxy is set-up in the More > Server Settings > Advanced Settings >
HTTP Proxy, it does not apply for the 2FA.
Note
You cannot use users with 2FA for server assisted installations.
How to enable Two-Factor Authentication for a Web Console user?
1. Create a new user or use an existing one.
2. Navigate to More > Users in the ESET PROTECT Cloud Web Console.
3. Click the user and select Two-Factor Authentication > Enable.
4. Upon the user's next login, enter the user's phone number when prompted.
5. Install ESET Secure Authentication mobile app on the user's mobile phone using the link from SMS or QR code.
6. When the app is installed using the token, your ESET PROTECT Cloud instance is added in the app.
7. Proceed to login and enter the one-time password from the mobile app to the Web Console when prompted. A new password is generated in the mobile app for each login.
Permission Sets
A permission set represents the permissions for users that access ESET PROTECT Cloud Web Console. They define what the user can do or see in the Web Console. Each permission set has its domain of application (static groups).
Permissions which are selected in the Functionality section will apply over objects in the groups which are set in the Static Groups section for each user assigned by this permission set. Having access to certain
automatically means access to every one of its subgroups. With proper setting of static groups it is possible to build separated branches for local admins ( see the example ).
A user can be assigned a permission set even without being able to see it. A permission set is also an object which is automatically stored in the home group of the user who created it. When a user account is created, the user is stored as object in the home group of the creating user. Usually the Administrator creates users, so they are stored in the group All.
Permission sets are additive. If you assign more permission sets to a single user, the sum of all permission sets is the resulting access that the user has.
Combining of more permission sets
The final access user has to an object is the result of the combination of all permission sets assigned to the user.
For example, a user has two permission sets, one for homegroup with full permissions and another one for a group with computers, only with permissions Read, Use for Computer & Groups. This user can run all tasks from homegroup on computers in the other group.
In general, a user can run objects from one static group over objects in another static group, if the user has permissions for certain object type in the certain group.
242
The Access Group filter button allows users to select a static group and filter viewed objects according to the group where they are contained.
You can use
for filtering the displayed items.
Important
Good practice for working with permissions:
• Consider restricting access to Client Tasks > Run Command - it is a very powerful task that could be abused.
• Non-admin level users should not have permissions for Permission Sets, Native Users, Server
Settings.
• If a more complex model of permissions is needed, do not hesitate to create more permission sets and assign them accordingly.
After setting permissions to ESET PROTECT Cloud functionality, you can also assign Read, Use, Write access to
.
Duplication
Example
For an object duplication the user needs to have Read permission on the original object and Write permission on his Home Group for this type of action.
John, whose home group is John’s Group, wants to duplicate Policy 1, which was originally created by
Larry, therefore the policy is automatically contained in Larry's home group, Larry's Group.
1. Create a new static group. Name it, for example, Shared policies.
2. Assign both John and Larry with Read permissions for Policies in the group Shared policies.
3. Larry moves Policy 1 to the Shared policies group.
4. Assign John with Write permissions for Policies in his home group.
5. John can now Duplicate the Policy 1 - duplicate will appear in his home group.
243
Difference between Use and Write
Example
If Administrator does not want to allow user John to modify policies in the Shared policies group, he would create a permission set with:
• Functionality Policies: Read and Use permissions selected
• Static Groups: Shared Policies
With these permissions assigned to John, John is able to run those policies but he cannot edit them, create new, nor delete them. If an administrator were to add Write permission, John could create new, edit and delete policies within the selected static group (Shared policies).
Manage Permission Sets
To manage a permission set, click the permission set and select one of the available actions:
Permission Set
• Show Details - View permission set details.
•
Audit Log - View the Audit Log for the selected item.
• Tags - Edit tags (assign, unassign, create, delete).
• Edit -
the permission set.
• Duplicate - Create a duplicate permission set which you can modify and assign to a specific user. The duplicate will be stored in the home group of the user who duplicated it.
• Delete - Delete the permission set.
Assignments
• Show native users - Show the list of assigned native users.
• Show mapped security groups - Show the list of assigned mapped domain security groups.
244
Access Rights
• Access Group > Move - Move the permission set to another Static Group.
Warning
All pre-defined permission sets have the All group in the Static Groups section. Be aware of this when assigning it to a user. Users will have these permissions over all objects in ESET PROTECT
Cloud.
Create or edit a permission set
To create a new permission set, click New. To edit an existing permission set, select the applicable permission set and click Edit.
Basic
Enter a Name for the set (mandatory setting). You can also enter a Description and Tags.
Click Select tags to assign tags .
Static Groups
You can Select a Static Group (or multiple Static Groups) or Create new group that will take this competence.
Permissions that are checked in the Functionality section will apply over objects contained in groups selected in this section.
Functionality
Select individual modules for which you want to grant access. The user with this competence will have access to these specific tasks. It is also possible to set different permissions for each type of
There are available four pre-defined functionality sets. Select one of the four or select manually functionality check boxes.
Granting Write permission automatically grants Use and Read rights; granting Use rights automatically grants
Read rights.
User Groups
example
).
Users
Choose a user to be assigned by this permission set. All available
are listed on the left. Select specific users or select all users using the Add All button. Assigned users are listed on the right. It is not mandatory to assign a user, you can do it later.
Summary
Review the settings configured for this competence and click Finish. The permission set is stored in the Home
Group of the user who created it.
Click Save as to create a new permission set based on the permission set you are editing. You will be required to enter a name for the new permission set.
245
List of permissions
Permission types
When creating or editing a permission set in More > Permission Sets > New / Edit > Functionality there is a list of all available permissions. ESET PROTECT Cloud Web Console permissions are divided into categories; for example, Groups & Computers, Native Users, Certificates, Policies and so on. A given permissions set can allow for Read, Use or Write access. In general:
Read permissions are good for auditing users. They can view data but cannot make changes.
Use permissions allow users to use objects, run tasks, but not modify or delete.
Write permissions allow users to either modify respective objects and/or duplicate them.
Certain types of permissions (listed below) control a process, not an object. That is why they work on a global level, so it does not matter which static group is the permission applied on, it will work regardless. If the process is allowed to a user he can use it only over objects for which he has sufficient permissions. For example, the Export
report to file permission enables the exporting functionality, however data contained in the report are determined by other permissions.
Example
Read our Knowledgebase article with example tasks and permission sets that user needs to successfully perform the tasks.
Users can be assigned permissions for the following processes:
• Agent Deployment
• Reports and Dashboard (only the functionality of the Dashboard will be available, the usable report templates are still dependent on accessible static groups)
• Send Email
• Export report to file
Functionality types:
Groups & Computers
Read - List computers, groups and computers within a group.
Use - Use a computer/group as a target for a policy or task.
Write - Create, modify and remove computers. This also includes renaming a computer or a group.
Permission Sets
Read - Read the list of permission sets and the list of access rights within them.
Use - Assign/remove existing permission sets for users.
Write - Create, modify and remove permission sets.
Important
When assigning (or un-assigning) a permission set to a user, Use permission is required for
Permission Sets and Native Users.
246
Stored Installers
Read - List stored installers.
Use - Export stored installer.
Write - Create/modify/remove stored installers.
Server Tasks & Triggers
Read - Read the list of tasks and their settings (except of sensitive fields like passwords).
Use - Execute an existing task with Run Now (as the user currently logged to the Web Console).
Write - Create, modify and remove server tasks.
Categories can be expanded by clicking the sign and single or multiple types of server tasks can be selected.
Client Tasks
Read - Read the list of tasks and their settings (except of sensitive fields like passwords).
Use - Schedule execution of existing Client Tasks or cancel their execution. Note that for assignment of tasks (or assignment cancellation) to targets (computers or groups) additional Use access is required for the affected targets.
Write - Create, modify or remove existing Client Tasks. Note that for assignment of tasks (or assignment cancellation) to targets (computers or groups) additional Use access is required for the affected target objects.
Categories can be expanded by clicking the sign and single or multiple types of Client Tasks can be selected.
Dynamic Groups Templates
Read - Read the list of Dynamic Groups templates.
Use - Use existing templates for dynamic groups.
Write - Create, modify and remove Dynamic Group templates.
Encryption recovery
Read
Use
Reports and Dashboard
Read - List report templates and their categories. Generate reports based on report templates. Read your own dashboards based on default dashboards.
247
Use - Modify your own dashboards with available report templates.
Write - Create, modify, remove existing report templates and their categories. Modify default dashboards.
Policies
Read - Read the list of policies and configuration within them.
Use - Assign existing policies to targets (or cancel their assignment). Note, that for the affected targets additional
Use access is necessary.
Write - Create, modify and remove policies.
Send Email
Use - Send emails. (Useful for Notifications and Generate Report server tasks.)
Licenses
Read - Read the list of licenses and their usage statistics.
Use - Use the license for activation.
Write - Add and remove licenses. (The user must have home group set to All. By default only the Administrator can do it.)
Notifications
Read - Read the list of notifications and their settings.
Write - Create, modify, remove notifications.
Audit log
Read - View
Audit Log
When a user performs an action in the ESET PROTECT Cloud Web Console, the action is logged. Audit logs are created if a ESET PROTECT Cloud Web Console object (for example, computer, policy, detection, etc.) is created or modified.
Audit Log is a new screen available in the ESET PROTECT Cloud. Audit Log contains the same information as the
, but it allows convenient filtering of the displayed data. You can also directly view the filtered audit log for various Web Console objects by clicking the Web Console object and selecting Audit Log.
Audit Log allows the Administrator to inspect the activities performed in the ESET PROTECT Cloud Web Console, especially if there are more Web Console users.
248
Important
To view the Audit log, the Web Console user must have a permission set with the
Click a line in Audit Log and you can perform the following actions:
Show Object Details
Show User Details
Audit Log
Audit Log for selected user
Show the details of the audited object.
Show details of the user who performed the action on the object.
Show the Audit Log for the selected object.
Show the Audit Log for the selected user.
Time window for selected object Show the Audit Log for the selected object with an activated filter of time occurrence.
Click Add Filter to filter the table view by various criteria:
• <= Occurred - Set the date and time before which the action occurred.
• >= Occurred - Set the date and time after which the action occurred.
• Action - Select the performed action.
• Audit Domain - Select the modified Web Console object.
• Audit User - Select the Web Console user who performed the action.
• Result - Select the action result.
Settings
249
The Settings section enables the administrator to adjust the delivery properties of Syslog information to your
Syslog server and specify the data retention policy for Cloud console logs.
Syslog
Enable the ESET PROTECT Cloud to send notifications and event messages to your
Syslog server . Also, export logs
from a client computer's ESET product and send them to the Syslog server.
Data Retention
Specify the cleanup period for specific types of logs stored in the Cloud console. Indicate the number of days/weeks/months/years the logs will be stored on the server for each category. You can set the cleaning interval for each of these types of logs:
Log type Example of log type
250
Detection logs Detection logs with high severity.
See the list of logs.
Incident logs
ActiveThreats
BlockedFiles
EESEvent_
EnterpriseInspectorAlert
Firewall_
FirewallAgregated
Functionality_Computer
Functionality_ProblemsDetails
Functionality_Product
Functionality_Products
Hips_
Quarantine_UploadedFile
Scan
Spam_
SubmittedFiles
SysInspector_SysInspector
Threat
ThreatsFlag
ThreatsMute
ThreatsMute2
WebControl_Link
251
Management logs Data about Quality of Service.
See the list of logs.
Management logs
AppliedPoliciesList
Apps_Installed
Computer_Connected
Computer_Lost
ComputerCloningTicketCreated
ComputerIdentityRecovered
DeviceLocation_GPS
DynamicGroups_Content
DynamicGroupsMembership
EnrollmentTokenGenerated
EnrollmentTokenRevoked
ExportedConfiguration
Identifiers_List
LocalUserEnrolled
LocalUserEnrollmentFailed
Managed_Products_Partial
Network_IpAddresses
Network_IpDnsServers
Network_IpGateways
Network_IpWinsServers
NewComputerEnrolled
OSInformation_Edition
Performance_Server
PowerSupply_Indicator
Qos_Database
Qos_Network
Repository_Agent
Repository_Epi
Repository_Server
Repository_Software
ServerSeatChanged
Storage_Capacity
Storage_List
Task_Client
Task_Client_Trigger_Notification
ThreatsMuteEIToERA
ThreatsMuteERAToEI
Audit logs Audit log reports.
See the list of logs
Audit logs
Audit
252
Monitoring logs Web Control logs, Device control logs, HIPS logs with low severity.
See the list of logs.
Monitoring logs
DeviceControl_Device
FilteredWebsites
HipsAgregated
LoggedUsers_List
WebControlAgregated
Diagnostic logs are cleaned every day. The user cannot change the cleaning interval. See the list of logs.
Diagnostics logs
Diagnostics_DeviceControl_Device
Diagnostics_DiagnosticZip
Diagnostics_Firewall
Diagnostics_Hips
Diagnostics_Spam
Diagnostics_WebControl_Link
Performance_DiskIO
Performance_Machine
Performance_Memory
Performance_NetworkIO
Performance_Processor
Performance_User
Syslog security restrictions and limits
Due to the security requirements for Syslog server connection, the following settings are fixed and cannot be changed:
• Transport protocol: TLS
• TCP port: 6514
For the same reasons there are additional requirements on the receiving Syslog server:
• IP address: Globally routable IPv4 address
• IDN names : Must use ASCII representation ("xn--")
• FQDN: Must translate to a single fixed IPv4 address.
Note
Using FQDN: If your Syslog server operates under multiple machines / IP addresses (CDN), there is no guarantee when and how often the FQDN is re-resolved. It is, however, guaranteed that the first
FQDN resolution is completed within a 10-minute window after the server's start as long as the
Syslog export is enabled and correctly configured.
CA root certificate validation of TLS connection: When TLS verification is enabled, the following requirements must be met to verify your server certificate:
• Certificate validation must be enabled
• The whole certificate chain in PEM format is uploaded and saved in the Syslog export configuration (this includes root CA, as there are no built-in trusted certificates)
• Your Syslog server's certificate provides a Subject Alternative Name extension (DNS=/IP=), in which at least
253
one record corresponds to the FQDN/IP hostname configuration.
Note
Additional security settings:
Administrators should configure their Syslog server's firewall to allow incoming Syslog Export events only from the following IP ranges:
• Outgoing IP addresses from ESET PROTECT Cloud in the Europe region: 51.136.106.164/30
• Outgoing IP addresses from ESET PROTECT Cloud in the USA region: 40.81.8.148/30
Export logs to Syslog
ESET PROTECT Cloud is able to export certain logs/events and send them to your
Syslog server . Events from the
following log categories are being exported to Syslog server: Detection, Firewall, HIPS, Audit and Enterprise
Inspector. Events are generated on any managed client computer running an ESET product (for example, ESET
Endpoint Security). These events can be processed by any Security Information and Event Management (SIEM) solution capable of importing events from a Syslog server. Events are written to the Syslog server by ESET
PROTECT Cloud.
1.
, click More > Settings > Syslog > Enable Syslog Sending.
2. Choose one of the following formats for event messages: a.
JSON (JavaScript Object Notation)
LEEF (Log Event Extended Format) - format used by IBM's application QRadar.
Syslog server
If you have a Syslog server running in your network, you can configure ESET PROTECT Cloud Server to send
to your Syslog server. You can also enable
in order to receive certain events
(Detection Event, Firewall Aggregated Event, HIPS Aggregated Event, etc.) from client computers running ESET
Endpoint Security, for example.
To enable the Syslog server:
1. Click More > Settings > Syslog and click the slider bar next to Enable Syslog sending.
2. Specify the following mandatory settings: a.
Format of payload:
or
b.
Format of envelope of the log: BSD ( specification ), Syslog ( specification ) c.
Minimal log level: Warning, Error or Critical d.
Event type of logs: Select which type of logs you want to include e.
Host: IPv4 address or hostname of the destination for Syslog messages f.
Validate CA Root certificate of TLS connection: Click the slider if you want to enable the certificate validation for the connection between your Syslog server and ESET PROTECT Cloud. After the validation is enabled a new text field will be displayed where you can copy and paste the required certificate chain.
After making the applicable changes, click Apply settings.
Note
The regular application log file is constantly being written to. Syslog only serves as a medium to export certain asynchronous events, such as notifications or various client computer events.
Events exported to LEEF format
LEEF format is a customized event format for IBM® Security QRadar®. Events have standard and custom attributes. ESET PROTECT Cloud uses some of standard attributes described in official IBM documentation . Custom attributes are the same as in JSON format. There are five categories of events:
254
• Detection
• Firewall
• HIPS
• Audit
• Enterprise Inspector Alerts
Note
More information about Log Event Extended Format (LEEF) can be found at official IBM website .
Events exported to JSON format
JSON is a lightweight format for data exchange. It is built on collection of name / value pairs and an ordered list of values.
Exported events
This section contains details on the format and meaning of attributes of all exported events. The event message is in the form of a JSON object with some mandatory and some optional keys. Each one exported event will contain the following key:
event_type string ipv4 ipv6
Type of exported events: Threat_Event, FirewallAggregated_Event,
HipsAggregated_Event, Audit_Event, EnterpriseInspectorAlert_Event,
BlockedFiles_Event, FilteredWebsites_Event.
string optional IPv4 address of the computer generating the event.
string optional IPv6 address of the computer generating the event.
source_uuid string occurred string severity string
UUID of the computer generating the event.
UTC time of occurrence of the event. Format is %d-%b-%Y %H:%M:%S
Severity of the event. Possible values (form least severe to most severe) are:
Information Notice Warning Error CriticalFatal
Custom keys according to event_type:
1. ThreatEvent
All Detection events generated by managed endpoints will be forwarded to Syslog. Detection event specific key: threat_type string optional Type of detection threat_name string optional Name of detection threat_flags scanner_id string optional Detection related flags string optional Scanner ID scan_id string optional Scan ID
engine_version string optional Version of the scanning engine object_type object_uri string optional Type of object related to this event string optional Object URI action_taken string optional Action taken by the Endpoint action_error string optional Error message in case the "action" was not successful
threat_handled bool optional Indicates whether or not the detection was handled need_restart bool optional Whether or not the restart is needed username string optional Name of the user account associated with the event processname string optional Name of the process associated with the event
circumstances string optional Short description of what caused the event
255
threat_type hash firstseen string optional Type of detection string optional SHA1 hash of the (detection) data stream.
string optional Time and date when the detection was found for the first time at that machine.
ESET PROTECT Cloud employs different date-time formats for the firstseen attribute (and any other date-time attribute) depending on log output format
(JSON or LEEF):
• JSON format: "%d-%b-%Y %H:%M:%S"
• LEEF format: "%b %d %Y %H:%M:%S"
2. FirewallAggregated_Event
Event logs generated by ESET Personal Firewall are aggregated by the managing ESET Management Agent to avoid wasting bandwidth during ESET Management Agent/ ESET PROTECT Cloud Server replication. Firewall event specific key: event source_address string optional Event name string optional Address of the event source
source_address_type string optional Type of address of the event source source_port number optional Port of the event source target_address string optional Address of the event destination
target_address_type string optional Type of address of the event destination target_port protocol number optional Port of the event destination string optional Protocol account process_name rule_name rule_id inbound threat_name aggregate_count string optional Name of the user account associated with the event string optional Name of the process associated with the event string optional Rule name string optional Rule ID bool optional Whether or not the connection was inbound string optional Name of the detection number optional How many exact same messages were generated by the endpoint between two consecutive replications between ESET PROTECT Cloud
Server and managing ESET Management Agent
3. HIPSAggregated_Event
Events from Host-based Intrusion Prevention System are filtered on severity before they are sent further as Syslog messages. Only events with severity levels Error, Critical and Fatal are sent to Syslog. HIPS specific attributes are as follows: application operation target action string optional Application name string optional Operation string optional Target string optional Action rule_name rule_id string optional Rule name string optional Rule ID
aggregate_count number optional How many exact same messages were generated by the endpoint between two consecutive replications between ESET PROTECT Cloud Server and managing ESET Management Agent
4. Audit_Event
ESET PROTECT Cloud forwards Server's internal audit log messages to Syslog. Specific attributes are as follows:
domain string optional Audit log domain
action string optional Action taking place
target string optional Target action is operating on
256
domain string optional Audit log domain
detail string optional Detailed description of the action user string optional Security user involved
result string optional Result of the action
5. FilteredWebsites_Event
ESET PROTECT Cloud forwards the filtered websites (Web Protection detections) to Syslog. Specific attributes are as follows: hostname processname username resolved hash event rule_id string optional Hostname of the computer with the event string optional Name of the process associated with the event string optional Name of the user account associated with the event bool optional Indicates whether or not the event was handled string optional SHA1 hash of the filtered object string optional Event type string optional Rule ID action_taken scanner_id object_uri target_address string optional Action taken string optional Scanner ID string optional Object URI string optional Address of the event destination
target_address_type string optional Type of address of the event destination (25769803777 = IPv4;
25769803778 = IPv6)
ESET PROTECT Cloud for Managed Service
Providers
Who is an MSP
The abbreviation MSP stands for "Managed Service Provider". MSP users usually provide IT services to their customers, for example, the management of security products (e. g. ESET Endpoint Antivirus). MSP users have
medium-sized business) users. See the recommended
. For more information about the ESET MSP program, contact your local ESET partner or visit the ESET Managed Service Provider Program page.
The structure of entities in the MSP
257
• Distributor - A distributor is an ESET partner and an MSP or MSP Manager partner.
• MSP Manager - Manages multiple MSP companies. An MSP Manager can also have direct customers.
• MSP - The target audience for this guide. An MSP provides services to its customers. For example, MSPs: remotely manages customers' computers, installs, and manages ESET products.
• Managed MSP - Similar to MSP, however, Managed MSP is managed by an MSP Manager.
• Customer - The end-user for ESET product licenses. The customer should not interact with ESET products.
MSP environment specifics
The MSP business model uses a different infrastructure setup than an enterprise or SMB. In the MSP environment, customers are typically located outside of MSP company network. ESET Management Agents installed on customers' computers need to have connectivity to the ESET PROTECT Cloud over the public internet. Make sure to open
certain ports to make the ESET PROTECT Cloud visible.
The standard MSP setup has the following structure:
258
ESET PROTECT Cloud deployed from a mixed account
A mixed account uses the same credentials to access ESET Business Account and ESET MSP Administrator. In that case, you can create the ESET PROTECT Cloud from each of them. After the instance is created, you can access the same instance from both services (EMA 2 and EBA). The right to remove the ESET PROTECT Cloud instance is reserved for the service that created the instance.
Features of ESET PROTECT Cloud for MSP users
ESET PROTECT Cloud offers a set of features focused on MSP users. MSP features are available for users who deployed the ESET PROTECT Cloud instance from:
• ESET MSP Administrator (EMA 2) account
• ESET Business Account (EBA) while having an EMA 2 account under the same credentials
Customer Setup Wizard
The key MSP feature in the ESET PROTECT Cloud is the MSP customer setup
. This feature helps you create a customized ESET Management Agent
for your customer.
MSP Tree
After importing the EMA 2 account, ESET PROTECT Cloud synchronizes with ESET MSP Portal
(EMA 2) and creates the MSP Tree. The MSP Tree is a structure in the
represents the structure of companies in your EMA 2 account. Items in the MSP Tree uses different icons than standard ESET PROTECT Cloud devices and groups. You cannot modify the
MSP Tree structure in the Web Console. Only after you remove the EMA 2 account from the
License Management can you start editing and removing customers from the tree. Suspending a company in EMA 2 does not remove the company from the MSP Tree in ESET PROTECT Cloud.
Shared Objects Group
After the synchronization of the MSP account, ESET PROTECT Cloud creates the MSP tree. There is one Shared
Objects static group for each MSP and MSP manager. MSPs can share objects like policies and tasks via the
Shared Objects group.
Each MSP user created using the
has read and use access to all Shared Objects groups
can access only upstream Shared Object groups, not groups from parallel MSP managers.
259
MSP in the Status Overview
You get the access to the new MSP tile in the
Status Overview after importing the EMA 2 account. The MSP tile
displays basic information about your account.
Having multiple instances of ESET PROTECT Cloud in MSP structure
If you use the Cloud instance deployed from an MSP account, it is separated from other MSP instances. The instance of your MSP Manager is not interconnected. They use the same company structure (MSP tree), but they do not share any computers or other objects like tasks or policies. The licenses are the only exception. They are shared hierarchically, same as ESET MSP Administrator. The MSP Manager can access their MSPs' licenses inside the Web Console and assign them to machines.
See the example below:
The MSP user does not have access to computers in the instance of the MSP Manager, even if those computers are in the static group of the MSP's customers. This is because the cloud instances are separated.
Create a new ESET PROTECT Cloud user in ESET MSP Administrator
To create a new user for ESET PROTECT Cloud Console, this user must first be created in ESET MSP Administrator
(EMA 2). See the EMA 2 Online help for a step-by-step guide on adding a user. You can add the new user during the
MSP customer setup or by following the steps below.
• See how the user permissions work in EMA 2 and ESET PROTECT Cloud in EMA 2 Online help.
• See the step-by-step guide how to create the ESET PROTECT Cloud instance.
1. Open the Web Console.
2. Navigate to Users.
260
261
3. Click Select next to Account identifier field and select the user you want to enable in ESET PROTECT
Cloud.
4. You can add tags, new or existing, to the user.
5. Click Select next to the Home group field. The home group is the static group where objects created by the user are stored by default.
6. Click Permission Sets.
7. Select a permission set for the new user. A permission set determines the
of the user. Each permission set gives the user rights over a certain static group(s). The groups are defined in each permission set. A user can be assigned to one or multiple sets. You can either select one of the offered permission sets or
.
Permission set for home group
Add permission sets to the home group you selected for the user. Without the access rights to the home group, the user cannot access or create any objects in the home group.
8. Click Finish to save the changes.
The new user can now log in to ESET PROTECT Cloud Console using their EMA 2 credentials.
Deployment process for MSP
Complete the MSP Customer Setup
. When prompted, select the Agent only installer.
1. Distribute and install the ESET Management Agent installer
2. Install ESET security products and set up policies
.
The scheme below is a high-level description of the MSP customer enrollment process.
262
Local deployment of Agent
Local deployment of Agent-only installer
The Agent-only installer ( .exe
for Windows or .sh
for Linux) contains all necessary information for a client machine to download and install the ESET Management Agent. Make sure the Linux machine meets the
.
You can run the installer locally or from removable media (a USB flash drive, for example).
Important
• The client machine needs to have an internet connection to download the Agent installation package.
• Make sure that the client machine has an internet connection and can connect to the ESET
PROTECT Cloud Server.
users.
Local deployment of All-in-one installer
Agent installer. Make sure that the client machine has an internet connection and can connect to the ESET
PROTECT Cloud Server.
See the installer manual for detailed instructions.
Remote deployment of Agent
Remote deployment of Agent-only installer
The Agent-only installer ( .exe
for Windows or .sh
for Linux) contains all necessary information for a client machine to download and install the ESET Management Agent. Make sure the Linux machine meets the
. You can distribute the installer via email and let the user deploy it. If available, use a third-party remote management tool to distribute and execute the installer.
Important
• The client machine needs to have an internet connection to download the Agent installation package.
• Make sure that the client machine has an internet connection and can connect to the ESET
PROTECT Cloud Server.
Remote deployment of All-in-one installer
the
ESET Remote Deployment Tool documentation for detailed instructions.
MSP Licenses
263
Information on licenses and companies
• Licenses imported from your MSP account are
with the company name. If the company is renamed later, the tags are not renamed automatically. You can edit them manually.
•
All licenses are imported in a way compatible with the ESET PROTECT Cloud security model
. Each user created using the
MSP Customer setup can only see and use its licenses.
• If there is a company in your MSP structure which has no licenses by the time of synchronization, that
• If you add a new company in ESET MSP Administrator 2, ESET PROTECT Cloud adds the company to the MSP tree after the next license synchronization.
• When you import an MSP account, all licenses are stored in one license pool. You cannot move a license out of the pool. You can move the whole license pool. To move the pool, select the pool > Actions > Access
Group > Move and select the new access group. If you synchronize the MSP account afterwards, any new licenses appear in the pool's actual location.
• You can find company names and sites in the License User column in the
. You can use the License User data when creating a
.
• If you have licenses both in ESET Business Account and ESET MSP Administrator 2 under the same credentials, ESET PROTECT Cloud synchronizes all licenses from both accounts. All ESET Business Account
for each company.
• When removing any license pool, you automatically remove all other license pools associated with the same account. Read more about how to
.
On-demand synchronization
The ESET PROTECT Cloud Server synchronizes with the license servers once a day. If you have made changes in your MSP account and you want to update the license screen and MSP tree, navigate to License Management >
Actions and click Synchronize Licenses.
264
Start MSP customer setup
can start setting up companies. The MSP customer setup creates:
• A custom ESET Management or bundled Agent and ESET security product installer. The MSP customer setup does not support creating ESET Full Disk Encryption installers.
You can also
, but we recommend that you complete the MSP setup.
Important
You can setup only a company with at least 1 valid license seat .
1. In the Computers window, click the gear icon next to the company you want to set up and select Start MSP
customer setup.
265
2. If you want to save this configuration as default setup, select the check box under Remember settings.
Click Continue.
3. If you want to create a custom installer during the setup (recommended), select the check box under Create
installer.
266
4. You can create two types of installers:
• Agent-only installer (Windows, Linux).
• All-in-one installer (Windows, macOS) - The installer consists of ESET Management Agent and selected
ESET Business security product.
All-in-one installer (Windows, macOS)
Product - Select an ESET security product that will be installed together with ESET Management Agent. By default, the latest product version is selected. To select an older version, click the gear icon next to product name and click Select previous version.
Language - Select the language version of the ESET security product installer.
Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
To save the installer in Installers
for future use, select the check box next to Save installer in installers section.
Enable HTTP Proxy settings
Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address of the machine where the
HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a different
port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT
Cloud Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
5. Click Continue to move to the User section.
6. You can select a user from your EMA 2 and let the user co-manage the ESET PROTECT Cloud.
a) Select the check box next to the Create permission set.
b) The user can log in to the Web Console and manage the company devices. Select Read or Write access rights level.
c) Click Select account and select one of the available accounts.
Problems creating a user?
Make sure you have the necessary permissions
.
267
Click Finish to prepare the installer. You can also re-download the installer from the
selected to save the installer. You can deploy your installer locally in two ways: a) After you select Show download link you can Copy the download link, distribute it to users and let them download and install the ESET PROTECT Live Installer package. You can also Download the ESET PROTECT
Live Installer package and distribute it personally or upload it to a shared location for the users to access.
b) After you select Send installer link to users you can use ESET PROTECT Cloud SMTP server to deliver an email message to a specified users containing the installer download link. You can specify the users by filling in the Email Address field (and optionally a name). To add multiple users at once, click Add user (add
address of the user from the Computer Users ), or Import CSV (
Import a custom list of addresses from a
CSV file structured with delimiters).
Read how to deploy the ESET Management Agent
Skip MSP customer setup
You can Skip the MSP customer setup if you do not want to set it up. Optionally, you can create an
later. We do not recommend to skip the setup.
After skipping the setup, the icon of the company is changed as if it has been set up:
Warning
If you skip the setup, you cannot run the setup wizard
for the company again on the same ESET
PROTECT Cloud instance.
Create custom installer
1. In the ESMC Web Console navigate to the Computers menu.
268
2. Click the gear icon next to the company you want to create the installer for and select Download
installer.
3. You can create two types of installers:
• Agent-only installer (Windows, Linux).
• All-in-one installer (Windows, macOS) - The installer consists of ESET Management Agent and selected
ESET Business security product.
All-in-one installer (Windows, macOS)
Product - Select an ESET security product that will be installed together with ESET Management Agent. By default, the latest product version is selected. To select an older version, click the gear icon next to product name and click Select previous version.
Language - Select the language version of the ESET security product installer.
Select the check box I accept the terms of the application End User License Agreement and
acknowledge the Privacy Policy.
To save the installer in Installers
for future use, select the check box next to Save installer in installers section.
Enable HTTP Proxy settings
269
270
Select the check box Enable HTTP Proxy settings and specify the Proxy settings (Host, Port, Username and Password) to set ESET Management Agent connection to Proxy to enable communication forwarding between ESET Management Agent and ESET PROTECT Cloud Server. The Host field is the address of the machine where the
HTTP Proxy is running. HTTP Proxy uses the port 3128 by default. You can set a different
port if needed. Make sure to set the same port also in the HTTP Proxy configuration.
Important
The communication protocol between Agent and ESET PROTECT Cloud Server does not support authentication. Any proxy solution used for forwarding Agent communication to ESET PROTECT
Cloud Server that requires authentication will not work.
Enable Use direct connection if HTTP proxy is not available if you want to allow this fallback option.
4. Click Create to create the installer.
5. Click the link and download the installer you need.
MSP Users
During the
, you can add an existing user from EMA2 or EBA to ESET PROTECT Cloud. To review and edit the user navigate to More >
>
Necessary permissions
To create the new user in the MSP customer setup
, you need the access rights to the company you set up and
Shared Objects groups.
Detailed permission schema
271
Set up a single company
Access rights necessary to create a user during the Company A setup:
• Use access for all Shared objects groups.
• Write access for the group of the MSP customer.
Set up all companies of one MSP
Access rights necessary to create users for all companies belonging to MSP provider:
• Use access for all Shared objects groups.
• Write access for the group of the MSP provider.
To have access rights means the current (acting) user has
assigned with access over the groups as mentioned above. If you do not have the required access rights, the MSP customer setup ends with an error.
272
MSP User features
• They can log in to the ESET PROTECT Cloud Web Console and manage devices and other objects they have access rights for.
ESET PROTECT Cloud has the following settings for each new MSP user:
• Description - Native user created via the MSP customer setup wizard
• Tags - The user is tagged with the company name
• Home group - Static group of the company
• Autologout - 15 minutes
• The account is enabled and password change is not required
• Permission sets - each MSP User has 2 permission sets. One for its home group and one for Shared
Objects groups.
Tagging of MSP objects
If you use the ESET PROTECT Cloud with an EMA 2 account, you enable automatic tagging of MSP objects. The following objects are tagged automatically:
• Licenses imported via MSP account
• Installers
and their Permission Sets created using the
is a form of label used to improve the filtering of objects. The automatic tag name is the same as the
License User (Company name in EMA 2, except characters , " which ESET PROTECT Cloud drops from the tag). If you rename the Customer in EMA 2 after synchronization, tags are not updated. You can add more custom tags to any object if you want to. You can remove the tags without affecting the tagged objects.
Click the expand icon to view the Tags tab.
MSP Status overview
section provides complex information about your ESET PROTECT Cloud status. If you create your ESET PROTECT Cloud instance using an EMA 2 or mixed (EMA 2 and EBA) account, there is an MSP tile available with MSP-related information.
MSP statuses
273
Account synchronized
Your account is synchronized and no action is needed.
Ongoing synchronization
There is ongoing synchronization of MSP account running in the background. The synchronization can take up to several hours for large accounts. The tile turns white after the synchronization.
Disconnected account
There are some MSP groups (parts of MSP tree) in your
, but there is no corresponding MSP
account imported. This can occur if you remove your MSP account from License Management .
Available actions
Click the MSP tile to see more details.
• Check for new MSP customers - Run on-demand license synchronization (update the MSP tree).
274
• New clients - If you have some not set companies, you can click them and follow the customer setup wizard.
• Skip setup for all new MSP customers - Skip setup wizards for all companies that are not set.
Removing a company
The MSP tree is synchronized with the MSP account. You need to remove the MSP account from the License
Management to unlock the MSP tree. Once you remove the account, all companies managed by that account are unlinked from the MSP tree.
Important
•
If you stop managing a company, remove
ESET Management Agents from that company computers. You cannot remove the company from the MSP tree without removing the whole MSP account from your license management.
• The MSP static group is persistent. Once you synchronize the MSP tree, you can never remove the
MSP root group, only its child groups.
Removing the MSP account and companies from the MSP tree
1. Log in to ESET PROTECT Cloud Web Console and navigate to More > License Management.
2. Click the license you want to remove > Remove Licenses. Keep in mind, that if you remove any license linked to an MSP account, the whole account and its linked licenses are removed from ESET PROTECT Cloud.
275
3. Confirm your choice to remove (unlink) the listed licenses from the License Management.
Warning
When removing any license pool, you automatically remove all other license pools associated with the same account.
For example, Company X licenses were imported using credentials of [email protected]
from EMA 2. If a user removes licenses of the Company X, all the licenses imported from [email protected]
EBA and EMA 2 accounts get removed from the License Management.
276
4. Wait a few moments after the action and navigate to the Computers menu.
5. Now you can click and Delete any company that was previously a part of the MSP Tree. You can only remove a company (its static group) if it is empty.
Note
After you remove the MSP account from the License Management, you get the MSP Administrator
is not connected status in the
Status Overview . You need to remove all groups from your former
MSP tree (in the Computers menu) to turn off that status.
Cloud Mobile Device Management
ESET Cloud Mobile Device Management (Cloud MDM) is an add-on feature native to the ESET remote management console. ESET Cloud MDM provides Android mobile device management and mobile security administration. ESET
Cloud MDM provides an agent-less solution where the management Agent is not running directly on the mobile device (to save battery and performance of the mobile device). Instead, the management agent for the mobile device is virtualized in the ESET cloud. Also, security and connection certificate management is managed by ESET, so the administrator does not have to worry about the certificate renewal process or if the certificates are up to the latest security standards.
ESET Cloud MDM can only manage Android mobile devices running ESET Endpoint for Android. Verify that your
Android device
OS version is supported for Cloud MDM management and that you meet the
The mobile device management process consists of two parts:
•
•
Mobile device security management
CMDM Enrollment
To manage a mobile device, enroll the device in the cloud management console. To do so, click Computers > Add
new > Mobile Device.
Basic
Select an enrollment type:
• Android - Standard enrollment procedure for Android device.
• Android Device Owner - Take full control of the managed Android device.
License: Select the appropriate license for mobile security product activation.
Parent group: Select the initial parent group that the mobile device will be assigned to after the enrollment.
Initial Configuration: Select the configuration policy that will be applied to the mobile device right after the enrollment process is finished.
277
Initial administrator password: Create a new Administrator password that will lock the advanced settings of the application on the enrolled Android device.
End-user license agreement and Privacy policy: Check the check-box if you accept the EULA and Privacy
Policy.
Distribution
The Distribution section enables you to choose the appropriate enrollment link delivery method for the Android devices based on their accessibility and number of devices.
Enrollment via email: Mass enrollment of mobile devices via email. This option is best suited if you need to enroll a large number of mobile devices or if you have existing mobile devices that you do not have physical access to.
Using this option requires active participation from the user/owner of the mobile device.
Enrollment via QR code: single mobile device enrollment. You will be able to enroll one mobile device at a time and will need to repeat the same process for each device. We recommend that you use this option only when you have a smaller number of mobile devices to enroll. This option is suitable if you do not want users/mobile device owners to do anything and must perform all enrollment tasks yourself. Also, you can use this option if you have new mobile devices that will be handed over to users after the devices are set up.
List
Specify mobile devices for enrollment, you can use the following functions to add mobile devices:
• Add: Single entry, you must manually type a device name and an email address associated with the mobile device.(In case of email delivery, enrollment email will be sent to this address). If you assign a user to the mobile device by clicking Pair with existing user and selecting the user, the email address is overwritten with the one specified in More >
screen. If you want to add another mobile device, click Add again and submit the required information.
• More: o
o Import CSV: A method that makes it easy to add a large number of mobile devices. Upload a . csv file
containing a list of devices to add, see
for more details.
o Paste from clipboard: Import a custom list of addresses separated with custom delimiters (this feature works similarly to CSV import).
Note
• We recommend that you specify a Device name in each entry when using the Import CSV method. This is the device name shown in the Computers section. If you leave the Device name field empty, email address will be used instead and appear as Device name in Computers and
Groups. This may cause some confusion, especially in the event you use the same email address to enroll multiple devices. This email address will appear multiple times and prevent you from being able to distinguish between the devices.
ENROLLMENT
You can review the all the parameters of the enrollment process in this section.
Email enrollment: View the list of the devices with their respective email addresses. Click Email preview to see the email template that will be delivered to each of the email addresses in the list. Click Send to send the email to
278
the specified email addresses.
QR code enrollment: Veiw the list of the Android devices for enrollment. On the right side of the screen you can see the specific QR code for the selected device in the list.
CMDM Management
After the successful enrollment of your Android mobile devices you can start to manage them.
several features available only for mobile device management.
: These are tasks available for managed mobile devices only, such as Find, Lock and Wipe.
These enable administrator to remotely locate the mobile device, Lock it and if the situation requires, wipe the mobile device.
Remote application installation: With the ESET Endpoint for Android (2+) policy, you can remotely force the mobile device to install required application by adding them to the list in the policy.
To do so, navigate to your existing applied ESET Endpoint for Android (2+) policy (or create a new one for this purpose). Under Application control, enable the Enable Application control setting. Click List of
applications and add the application you want to remotely install on the mobile device. These applications will be remotely installed on the mobile device after the policy is applied.
ESET PROTECT Cloud Migration scenarios
Migration scenarios for migrating to ESET PROTECT Cloud.
In this section we will review migration scenarios for transitioning from other ESET products to ESET PROTECT
Cloud. Click the link below that best describes your scenario.
1.
2.
I currently manage my network with ESMC 7 / ESET PROTECT 8 and I want to migrate to ESET PROTECT
Important
Before any migration, decrypt all workstations encrypted with ESET Full Disk Encryption. You can encrypt them once the migration is finished.
I have unmanaged ESET Endpoint products in my network and I want to start managing them with ESET PROTECT Cloud.
Note
It is not possible to upgrade version 4.5 or earlier ESET server products with ESET PROTECT Live
Installer. You must have ESET version 6 or later products installed to upgrade to ESET PROTECT
Cloud.
Follow the steps below to find and add unmanaged products in ESET PROTECT Cloud:
279
1. Create your
2. Create a new Installer and select the product to install based on which Endpoint products are currently present in your network.
3. Policy and group settings for clients can be defined in the installer. If no policy is selected as a part of the installer and no policy is applied to any group in ESET PROTECT Cloud, the current configuration of your
Endpoint products will not be overwritten and can later be exported and converted into a policy.
4. Deploy the installers to your network. ESET PROTECT Live Installer will install ESET Management Agent, and upgrade your existing Endpoint products.
Note
ESET PROTECT Live Installer requires a direct internet connection to download the required components. After the installation is complete, you can switch the connection to be forwarded via proxy.
5. After the installation is completed successfully and the devices are connecting to ESET PROTECT Cloud, you can start managing them with your ESET PROTECT Cloud.
6. If no policy was part of the installer or applied to any group in ESET PROTECT Cloud, you can now export the configuration of your Endpoint Products.
7.
To do so, navigate to Tasks and create a new Export Managed Products Configuration Task.
8. In the Settings part select Product: All and as a Target select all devices from which you want to export the configuration.
9. Wait until the task is executed on all selected devices.
10.
Navigate to the specific device's Show Details > Configuration and open specific Endpoint product
configuration.
11. Here you can review the exported settings and if you are satisfied, select Convert to Policy.
12. Policy wizard will open, in which you can edit the Name for the policy review and adjust some of the settings if required and click Finish to save it.
13. Repeat this procedure for each Endpoint product.
14. After all products configurations are converted you can now continue by applying the policy to the respective client devices so the setting will be locked and the user of the device will not be able to change them.
Partial Migration from ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud
Important
You cannot migrate ERA 6.x Agents to ESET PROTECT Cloud. If you have ERA 6.x Server or if you have ERA 6.x Agents in your infrastructure, upgrade your server to ESMC 7 or ESET PROTECT 8 and upgrade ERA 6.x Agent on all managed computers to ESET Management Agent (version 7 or 8) before migrating to ESET PROTECT Cloud.
It is not possible to migrate database from ESMC 7 / ESET PROTECT 8 server to ESET PROTECT Cloud.
Partial migration includes the migration of:
• ESET Management Agents (managed computers)
• Policies
Other ESMC 7 / ESET PROTECT 8 database data (dynamic groups, reports, detections, notifications, tasks, installers) are not migrated.
ESET PROTECT Cloud does not support ESET Enterprise Inspector. If you migrate from ESET PROTECT to ESET PROTECT Cloud, you will not be able to manage ESET Enterprise Inspector from ESET
PROTECT Cloud.
280
Follow the steps below to migrate from ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud:
I. Create a new ESET PROTECT Cloud instance
II. Migrate Policies from the on-premise ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud
III. Migrate ESET Management Agents (managed computers) from the on-premise ESMC 7 / ESET PROTECT 8 to
ESET PROTECT Cloud with Migration Policy
IV. Set up ESET PROTECT Cloud users in ESET Business Account and add them to ESET PROTECT Cloud Web
Note
If you have an MSP account, you can synchronize your MSP account with ESET PROTECT Cloud Web
Console.
I. Create a new ESET PROTECT Cloud instance
Prerequisites
• A Superuser account in ESET Business Account .
• An eligible license for ESET PROTECT Cloud.
Important
• If your EBA and EMA2 accounts are registered to the same email address, the ESET PROTECT Cloud can be activated only from one account. The account (EBA or EMA2) you choose to create the ESET
PROTECT Cloud instance from will be the only one you can use to activate or delete the instance.
Create a new ESET PROTECT Cloud instance
1. Open the ESET Business Account and log in (or create a new account ).
2. Click Licenses > Enter License Key.
281
3. In the Add License pop-up window, enter your ESET PROTECT Cloud License key and click Add License.
282
4. You will receive a verification email. Click Verify license.
5. In the Dashboard, click Activate under ESET PROTECT Cloud.
Warning
Check the language setting of your ESET Business Account. Some ESET PROTECT Cloud main program window elements are defined the first time you set the language in your ESET Business
Account language settings, and cannot be changed later.
6. An Activate ESET PROTECT Cloud window will open. Read the Terms of Use and select the check box if you agree.
7. Select a data center location for your ESET PROTECT Cloud instance that is the closest to the location of your managed network and click Continue.
Warning
After selected, you will not able to change the data center location of your ESET PROTECT Cloud instance.
8. Your ESET PROTECT Cloud instance will be created. You can wait for a few minutes until it is created or you can log out and you will be notified by email when the ESET PROTECT Cloud instance is available.
9. Click Continue. Alternatively, click Dashboard, click Open in the ESET PROTECT Cloud tile to open a new
tab with ESET PROTECT Cloud Web Console
.
II. Migrate Policies from the on-premise ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud
Note
Steps below show the migration from ESMC 7.
283
1. Log in to your on-premise ESMC 7 / ESET PROTECT 8.
2. In your on-premise ESMC 7 / ESET PROTECT 8, select Policies > All > select the check box in the table header (or select the check boxes next to policies you want to export) and then click Actions > Export.
Important
Do not export the ESET Management Agent policies that contain connection parameters (for example, server hostname, connection certificate, etc.). This is handled in part III.
284
3. Save the .dat
file with the list of Policies.
4. In ESET PROTECT Cloud, click Policies > Actions > Import and select the .dat
file with the list of policies exported from ESMC 7 / ESET PROTECT 8 in step 6 and then click Import to import them to ESET PROTECT
Cloud.
5. Imported policies will appear under Custom Policies. After the migration of computers from ESMC 7 / ESET
PROTECT 8 to ESET PROTECT Cloud, policies that were assigned to computers in ESMC 7 / ESET PROTECT 8 are not preserved. After importing Policies to ESET PROTECT Cloud, you can assign them to imported computers in
ESET PROTECT Cloud.
Warning
Be careful when applying policies to computers: a) In your on-premise ESMC 7 / ESET PROTECT 8: Make the list of applied policies and their order for each managed computer.
b) In ESET PROTECT Cloud: Apply policies to each computer based on the policy setup from the onpremise ESMC 7 / ESET PROTECT 8.
III. Migrate ESET Management Agents (managed computers) from the on-premise ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud with Migration policy
1. In ESET PROTECT Cloud Web Console, click Quick Links > Download Migration Policy and save the .dat
file.
285
2. In your on-premise ESMC 7 / ESET PROTECT 8, select Policies > Import. Select the downloade .dat file from the previous step and click Import.
286
3. Navigate to Custom policies and select your imported migration policy.
287
4. Click Assign groups
5. Select the All Static Group and click OK.
Warning
Apply the migration policy to the All Static Group to ensure that you migrate managed computers.
288
6. Click Finish to apply the policy.
7. Log in to your ESET PROTECT Cloud Web Console. In Computers, you will see the computers migrated from
ESMC 7 / ESET PROTECT 8. You may need to wait a few minutes until all computers from ESMC 7 / ESET
PROTECT 8 start connecting to ESET PROTECT Cloud.
8. After you migrate computers from ESMC 7 / ESET PROTECT 8 to ESET PROTECT Cloud, you need to reactivate ESET security products on these computers: a.
In ESET PROTECT Cloud Web Console, click Dashboard > Computers tab > click the red area of the Top
computer problems graph and select Activate Product.
b.
Select the ESET security product license in Settings, review the target computers in Target and click
Finish.
Important
If the computers run various ESET security products (e.g. both endpoint and server products), you need to repeat the activation steps and select the appropriate license for each ESET security product category.
c.
Wait a few minutes until the ESET security products are activated.
IV. Set up ESET PROTECT Cloud users in ESET Business Account and add them to ESET PROTECT Cloud Web Console
1. Log in to your ESET Business Account account.
2. Select User Management > New User.
289
3. Fill in the required fields (read more in the ESET Business Account Online Help ):
I.
General - Provide basic information about the user
II.
Access Rights: a) Company Access - Select user's level of company access: Write, Read, Access only to selected
sites.
b) User Management Access - Select the check box to allow user to manage other users in ESET
Business Account.
c) ESET PROTECT Cloud Access:
• Write - User has full access to ESET PROTECT Cloud.
• Read - User can only view the data in ESET PROTECT Cloud.
• Custom - You can define user access later in ESET PROTECT Cloud in Permission Sets.
• No access - User has no access to ESET PROTECT Cloud.
Important
To access ESET PROTECT Cloud, a user must have Write or Read access rights to at least one company with eligible (active) ESET PROTECT Cloud license.
III.
Preferences - Set user's language for ESET Business Account and ESET PROTECT Cloud and set the time zone.
IV.
Security - Adjust security settings for the user (password expiration, idle session timeout, two-factor verification).
Click Create to create the user.
290
4. The new user appears in the User Management with the Waiting for activation label.
291
5. The user will receive an activation email (to the email address you specified when creating the user). The user must click Activate your account.
6. The user needs to adjust the user settings and type the password twice (Create password and Confirm
password), select the check box I agree to the ESET Terms of Use and click Activate the account.
292
7. Log in to your ESET Business Account account. Use the account from step 1; do not use the newly created user account yet.
8. Open the ESET PROTECT Cloud Web Console. Click More > Users > select Mapped ESET Business
Accounts > click the Add New button.
9. Click Select under ESET Business Account identifier.
293
10. Select the user you created in the previous steps and click OK.
11. Select the user's Home group and click Continue.
12. In Permission Sets, you can see the permissions level that you assigned to the user in step 3. If you selected Custom ESET PROTECT Cloud Access in step 3, you need to assign a permission set to the user (an existing one or you can
). Click Finish.
294
13. Users that were granted the access to ESET PROTECT Cloud will see the option to open ESET PROTECT Cloud in their ESET Business Account.
Stop using ESET PROTECT Cloud
There are two correct ways to stop managing your network with ESET PROTECT Cloud: a) Completely remove all ESET security products and ESET Management Agents and then decommission the ESET
PROTECT Cloud instance.
b) Continue to use ESET security products, but remove ESET Management Agent and ESET PROTECT Cloud instance. (In this scenario, skip to
Remove ESET Management Agent below).
Remove ESET security products from your network
1. Reset to default or unlock client settings in policies.
a.
Delete all Custom policies currently applied to clients.
b.
For all Built-in Policies select the policy and click the Clients tab to see if any of these policies are assigned to computers in your network.
2. Change the password setting on clients to the default value.
a.
Create a new policy and navigate to Security product policy > User Interface > Access Setup.
b.
Leave the Password protected settings disabled and use Force next to the Set password setting.
c.
Assign this policy to all devices in your network. This will remove the password protection for the advanced settings on your Endpoint Security products.
3. Decrypt any workstations encrypted with ESET Full Disk Encryption.
295
Warning
If any workstation is still encrypted after the ESET PROTECT Cloud instance is deleted there is no other way to decrypt the workstation (if you do not have the encryption recovery data downloaded before). Not even ESET can help in this case.
4. Remove the security product from client devices if desired. You can leave security products installed, and they will continue to provide production even if they are not managed.
To uninstall all security products in your network use the Software Uninstall Task.
a.
Navigate to Tasks > New.
b.
In the Task creation wizard in the Basic section, fill in the Name and Description and select Software
uninstall from the Task drop-down menu.
c.
In the Settings section, select the application to uninstall from the Uninstall drop-down menu. Under
Package name click <Select package to uninstall>, select the security product you want to uninstall and click OK.
d.
Under Package version click Uninstall all versions of package to prevent problems when uninstalling different versions of security products on client computers in your network.
e.
Select the check box next to Automatic reboot when needed to ensure that the uninstallation process is completely finished and then click Finish to create the task.
f.
Click Create trigger to select a Target for the task. Click Add Groups and select the All group as the target. Select the appropriate trigger and click Finish to execute.
Verify that the task was successfully executed on all devices and repeat the process for each type of security product in your network.
Remove ESET Management Agent from your network
For the most efficient removal of all ESET Management Agents in your network, verify that all affected devices are powered on and connecting to ESET PROTECT Cloud.
1. Revert the password-protected setup setting (Windows only).
a.
Create a new policy for ESET Management Agent.
b.
Navigate to Advanced Settings and under Setup, set a Force flag next to the Password Protected
Setup setting.
c.
Assign the policy to the All group and click Finish to apply.
2. Verify that the policy is applied. After the policy is successfully applied to all clients, remove ESET
Management Agent from the computers in your network. You can use the Stop Managing (Uninstall ESET
Management Agent) task to do so. Assign the task to all computers in your network.
3. Wait until the task is executed on all devices in your network.
4.
Remove all devices in the Computers section of ESET PROTECT Cloud.
If none of the devices re-appear in the console for the next 10 minutes, you have successfully removed all ESET
Management Agents from your network.
Delete ESET PROTECT Cloud instance
1. Open your ESET Business Account account.
2. In the main Dashboard section, navigate to the ESET PROTECT Cloud tile.
296
3. Click the gear icon in the ESET PROTECT Cloud tile and select Delete ESET PROTECT Cloud.
4. Enter your password and click Delete. Your ESET PROTECT Cloud instance will be deleted.
Last ESET PROTECT Cloud license expiration
This topic describes the following license-related scenarios:
•
•
What happens after the last ESET PROTECT Cloudeligible license
is removed from ESET Business Account.
What happens to an ESET PROTECT Cloud instance before and after the last ESET PROTECT Cloud-
When your license is close to expiring, an alert will be displayed in the ESET Business Account interface. If the expiration date passes and you have not renewed your license or activated a new license, the license expired alert
be suspended in 14 days will be displayed in ESET Business Account, and you will receive an email at the address specified in your administrator account.
You have a 14-day grace period to renew after your license expires. You will be notified in ESET Business Account and by email halfway through the grace period. After 14 days, your ESET PROTECT Cloud use will be suspended.
The instance will become inaccessible and non-functional. A suspended ESET PROTECT Cloud instance will be stored, and can be accessed again by adding a new ESET PROTECT Cloud-eligible license to ESET Business
Account. Your ESET PROTECT Cloud instance can remain in a suspended state for up to 30 days, after
which it will be deleted permanently.
If your instance enters a suspended state, you will be notified in ESET Business Account and by email when there are 14 days left before your instance is deleted. You must activate a new, ESET PROTECT Cloud-eligible license to restore access to your ESET PROTECT Cloud instance.
What happens after the last ESET PROTECT Cloud-
is removed from ESET Business
Account?
If no ESET PROTECT Cloud-
are present in ESET Business Account, your ESET PROTECT Cloud instance will be suspended.
The instance will become inaccessible and non-functional. A suspended ESET PROTECT Cloud instance will be stored, and can be accessed again by adding a new ESET PROTECT Cloud-eligible license to ESET Business
Account. Your ESET PROTECT Cloud instance can remain in a suspended state for up to 30 days, after
which it will be deleted permanently.
If your instance enters a suspended state, you will be notified in ESET Business Account and by email when there are 14 days left before your instance is deleted. You must activate a new, ESET PROTECT Cloud-eligible license to restore access to your ESET PROTECT Cloud instance.
About ESET PROTECT Cloud
To open the About window, navigate to Help > About. This window provides details about the version of ESET
PROTECT Cloud. The top of the window contains information about the number of connecting client devices and number of active licenses.
297
Note
If you are contacting ESET Support, identify your ESET PROTECT Cloud instance by providing the
UUID number of your ESET PROTECT Cloud instance. The UUID number of your instance can be found in the ESET Business Account portal under Help > About > ESET PROTECT Cloud ID.
ESET PROTECT Cloud Security
1 Introduction
The purpose of this document is to summarize the security practices and security controls applied within ESET
PROTECT Cloud. Security practices and controls are designed to protect the confidentiality, integrity, and availability of customer information. Please note that security practices and controls may change.
2 Scope
The scope of this document is to summarize security practices and security controls for ESET PROTECT Cloud infrastructure, ESET Business account (hereinafter referred to as “EBA”), and ESET MSP Administrator (hereinafter referred to as "EMA") infrastructure, organization, personnel, and operational processes. Security practices and controls include:
• Information security policies
• Organization of information security
• Human resource security
• Asset management
• Access control
• Cryptography
• Physical and environmental security
• Operations security
• Communications security
• System acquisition, development, and maintenance
• Supplier relationship
• Information security incident management
• Information security aspects of business continuity management
• Compliance
3 Terms and abbreviations
Term or abbreviation Explanation
EBA
EMA
ESET Business Account
ESET MSP Administrator
4 Security concept
ESET s.r.o. company is ISO 27001:2013 certified with integrated management system scope explicitly covering
298
ESET PROTECT Cloud, EMA, and EBA services. Therefore, the concept of information security uses the ISO 27001 framework to implement a layered defense security strategy when applying security controls on the layer of the network, operating systems, databases, applications, personnel, and operating processes. Applied security controls and security practices are intended to overlap and complement each other.
5 Security controls
5.1 Information security policies
ESET uses information security policies to cover all aspects of the ISO 27001 standard, including information security governance and security controls and practices. Policies are reviewed annually and updated upon significant change to ensure their continuing suitability, adequacy, and effectiveness.
ESET performs annual reviews of this policy and internal security checks to ensure consistency with this policy.
Non-compliance with information security policies is subject to disciplinary actions for ESET employees or contractual penalties up to contract termination for suppliers.
5.2 Organization of information security
The organization of information security for ESET PROTECT Cloud consists of multiple teams and individuals involved in information security and IT, including:
• ESET executive management
• ESET Internal security teams
• Business applications IT teams
• Other supporting teams
Information security responsibilities are allocated in-line with information security policies in place. Internal processes are identified and assessed for any risk of unauthorized or unintentional modification or misuse of ESET assets. Risky or sensitive activities of internal processes adopt the segregation of duties principle to mitigate the risk.
The ESET legal team is responsible for contacts with authorities including, Slovak regulators on cybersecurity and personal data protection. The ESET Internal Security team is responsible for contact with special interest groups like ISACA. The ESET Research lab team is responsible for contact with other security companies and the greater cyber security community.
Information security is accounted for in project management using the applied project management framework from conception to completion of a project.
Remote work and telecommuting are covered through the use of a policy implemented on mobile devices that include the use of strong cryptographic data protection on mobile devices while traveling through untrusted networks. Security controls on mobile devices are designed to work independently of ESET internal networks and internal systems.
5.3 Human resource security
ESET uses standard human resource practices, including policies designed to uphold information security. These practices cover the whole employee life-cycle, and they apply to all teams that access the ESET PROTECT Cloud environment.
5.4 Asset management
299
The ESET PROTECT Cloud infrastructure is included in ESET asset inventories with strict ownership and rules applied according to asset type and sensitivity. ESET has an internal classification scheme defined. All ESET
PROTECT Cloud data and ESET PROTECT Cloud configurations are classified as confidential.
5.5 Access control
All access in ESET PROTECT Cloud is governed by ESET's Access control policy. Access control is set on the infrastructure, network services, operating system, database, and application level. Whole user access management on the application level is autonomous. ESET PROTECT Cloud and EBA single sign-on is governed by a central identity provider, which ensures that a user can access the authorized tenant only. The application uses standard ESET Protect permissions to enforce role-based access control for the tenant.
ESET backend access is strictly limited to authorized individuals and roles. Standard ESET processes for user
(de)registration, (de)provisioning, privilege management, and review of user access rights are used to manage
ESET employee access to ESET PROTECT Cloud and EBA infrastructure and networks. Strong authentication is used to protect access to all ESET PROTECT Cloud data.
5.6 Cryptography
To protect ESET PROTECT Cloud data, strong cryptography is used to encrypt data at rest and in transit. Generally trusted certificate authority is used to issue certificates for public services. Internal ESET public key infrastructure is used to manage keys within the ESET PROTECT Cloud infrastructure. Data stored in the database is protected by cloud-generated encryption keys. All backup data are protected by ESET managed keys.
5.7 Physical and environmental security
Because ESET PROTECT Cloud and EBA are cloud-based, we rely on Microsoft Azure for physical and environmental security. Azure uses certified data centers with robust physical security measures. The physical location of the data center depends on customer region choice. Strong cryptography is used to protect customer data during transport off-site from the cloud environment (for example, in transit to a physical backup data storage).
5.8 Operations security
The ESET PROTECT Cloud service is operated via automated means based on strict operational procedures and configuration templates. All changes, including configuration changes and new package deployment, are approved and tested in a dedicated testing environment before deployment to production. Development, test, and production environments are segregated from each other. ESET PROTECT Cloud data is located only in the production environment.
The ESET PROTECT Cloud environment is supervised using operational monitoring to swiftly identify problems and provide sufficient capacity to all services on the network and host levels.
All configuration data is stored in our regularly backed-up repositories to allow for automated recovery of an environment’s configuration. ESET PROTECT Cloud data backups are stored both on-site and offsite. Backups are encrypted and regularly tested for recoverability as a part of business continuity testing.
Auditing on systems is performed according to internal standards and guidelines. Logs and events from the infrastructure, operating system, database, application servers, and security controls are collected on a continuous basis. The logs are further processed by IT and internal security teams to identify operational and security anomalies and information security incidents.
ESET uses a general technical vulnerability management process to handle the occurrence of vulnerabilities in
ESET infrastructure, including ESET PROTECT Cloud and other ESET products. This process includes proactive vulnerability scanning of infrastructure and repeated penetration testing of infrastructure, products, and applications.
ESET states internal guidelines for the security of internal infrastructure, networks, operating systems, databases, application servers, and applications. These guidelines are checked via technical compliance monitoring and our internal information security audit program.
300
5.9 Communications security
The ESET PROTECT Cloud environment is segmented via native cloud segmentation with network access limited only to necessary services among network segments. The availability of network services is achieved via native cloud controls like availability zones, load-balancing, and redundancy. Dedicated load-balancing components are deployed to provide specific endpoints for ESET PROTECT Cloud instance routing that enforce authorization of traffic and load-balancing. Network traffic is continuously monitored for operational and security anomalies.
Potential attacks can be resolved through the use of native cloud controls or deployed security solutions. All network communication is encrypted via generally available techniques, including IPsec and TLS.
5.10 System acquisition, development, and maintenance
Development of ESET PROTECT Cloud systems is performed in accordance with the ESET secure software development policy. Internal security teams are included in the ESET PROTECT Cloud development project from the initial phase and overlook all development and maintenance activities. The internal security team defines and checks the fulfillment of security requirements in various stages of software development. The security of all services, including newly developed ones, is tested starting upon release on a continuous basis.
5.11 Supplier relationship
A relevant supplier relationship is covered according to valid ESET guidelines, which cover whole relationship management and contractual requirements from the point of information security and privacy. The quality and security of services provided by the critical service provider are assessed regularly. Furthermore, ESET utilizes the principle of portability for ESET PROTECT Cloud to avoid supplier lockout.
5.12 Information security incident management
Information security incident management in ESET PROTECT Cloud is performed in the same way as for any other part of ESET infrastructure and relies on defined incident response procedures. Roles within incident response are defined and allocated across multiple teams, including IT, security, legal, human resources, public relations, and executive management. The incident response team for an incident is established based on incident triage by the internal security team. That team will provide further coordination of other teams handling the incident. The internal security team is also responsible for evidence collection and lessons learned. Incident occurrence and resolution are communicated to affected parties. ESET legal team is responsible to notify regulatory bodies if needed according to the General Data Protection Regulation (GDPR) and Cybersecurity Act transposing Network and information security directive (NIS).
5.13 Information security aspects of business continuity management
Business continuity of the ESET PROTECT Cloud service is coded in the robust architecture used to maximize the availability of the provided services. Full restoration from offsite backup and configuration data is possible in the event of a catastrophic failure of all redundant nodes for ESET PROTECT Cloud components or the ESET PROTECT
Cloud service. The restoration process is regularly tested.
5.14 Compliance
Compliance with the regulatory and contractual requirements of ESET PROTECT Cloud is regularly assessed and reviewed similarly to other infrastructure and processes of ESET, and necessary steps are taken to provide compliance on a continuous basis. ESET is registered as a digital service provider for Cloud Computing digital service covering multiple ESET services, including ESET PROTECT Cloud. Please note that ESET compliance activities do not necessarily mean that the overall compliance requirements of customers are satisfied as such.
Terms of Use
These Terms of Use ("Terms") constitute a special agreement between ESET, spol. s r. o., having its registered office at Einsteinova 24, 851 01 Bratislava, Slovak Republic, registered in the Commercial Register administered by
Bratislava I District Court, Section Sro, Entry No 3586/B, Business Registration Number: 31 333 535 ("ESET" or
"Provider") and you, a natural person or legal entity ("You" or "User”) who accesses an account for administration,
301
ESET PROTECT Cloud and who uses online services owned and provided by ESET ("Account") which are all specified in the applicable documentation accessible via ESET Online Help ("documentation"). If You use the Account on behalf of an organization, then You agree to these Terms for that organization and guarantee that You have the authority to bind that organization to these Terms. In that case, You and User will refer to that organization. Read these Terms carefully. They also relate to services provided by ESET through or in relation to the Account. The specific conditions for using individual services beyond these Terms are stated with each service, with their acceptance being part of the service activation process.
Security and Data Protection
The Account renders access to products and services provided by ESET. The user's full name, company name, country, valid email address, phone number, licensing data and statistic are required for registration and use of the
Account and for the purpose of provision and maintenance of services accessed via Account. You hereby agree to data being collected and transferred to Provider's servers or those of its partners, the purpose of which is to ensure functionality of and authorization to use the Software and protection of the Provider’s rights. Following conclusion of these Terms, the Provider or its partners shall be entitled to transfer, process and store essential data identifying You for support purposes, and for the purpose of performance of these Terms. You are authorized to use the Account solely for the purposes and manner for which it is intended under these Terms, individual service terms and documentation.
You are responsible for the security of your Account and credentials required for logging in. ESET shall not be liable for any loss or damage resulting from your failure to comply with this obligation to maintain security. The User is also responsible for any activity related to the use of the Account, authorized or not. If the Account is compromised, you should notify the Provider immediately.
In order to provide administration service of Account, the collection of data concerning managed devices is required together with administration information (hereinafter referred to as "Data"). Data are provided by You to
ESET solely for the purpose of provision of administration service of Account. Data will be processed and stored in compliance with security policies and practices of ESET as well as in compliance with Privacy Policy.
Data as well as other Account-related logs shall be stored in accordance with Logs Retention Policy .
Details about privacy, personal data protection and rights as a data subject can be found in Privacy
Policy .
Fair Use Policy
You are obliged to comply with technical limitations stipulated in documentation. You agree that You will only use the Account and its functions in a way which does not limit the possibilities of other Users to access these services.
The Provider reserves the right to limit the scope of services provided to individual Users, to enable use of the services by the highest possible number of Users. Limiting the scope of services shall also mean complete termination of the possibility to use any of the functions of the Account and deletion of data and information.
The Provider also reserves the right to limit the number of devices managed under the Account. You are allowed to add and manage up to 10 000 endpoint devices.
Limitation of Use
The usage of Account is strictly limited to the managing of products with Cloud Eligible Licenses . However, the number of ESET Full Disk Encryption licenses managed by Account shall not exceed the number of product installations with other Cloud Eligible Licenses in compliance with the total number of 10 000 managed endpoint devices required by Fair Use Policy. The Provider also reserves the right to limit the number of products managed under the Account in case of your non-compliance with this limitation.
Location
Provider may allow You to choose from available hosting locations for Account, including recommended location chosen by Provider. You acknowledge that by choosing of other than recommended location, your user experience may be affected. Based on the chosen location Data Protection Agreement included in the Annex no. 2 of this
Agreement and Standard Contractual Clauses included in the Annex no. 3 of this Agreement may apply. ESET
302
reserves the right to change specific location at any time without prior notice for the purpose of improvement of services provided by ESET in compliance with your location preferences (e.g. European Union).
Software
ESET or its respective suppliers own or may exercise copyright to all software available on the Account websites
(hereinafter referred to as "Software"). The Software can be used only in accordance with the End User License
Agreement (hereinafter referred to as "EULA"). EULA is supplied together with the Software, or comprises part of it.
Software supplied with the EULA cannot be installed without the User's consent to the EULA. Other information regarding licensing, copyright, documentation and trademarks are stipulated in the Legal Information .
Restrictions
You may not copy, distribute, extract components or make derivative works of the Account. When using the
Account You are required to comply with the following restrictions:
(a) You may not use, modify, translate or reproduce the Account or transfer rights to use the Account or its components in any manner other than as provided for in these Terms.
(b) You may not sell, sub-license, lease or rent or borrow the Account or use the Account for the provision of commercial services.
(c) You may not reverse engineer, reverse compile or disassemble the Account or otherwise attempt to discover the source code of the Account, except to the extent that this restriction is expressly prohibited by law.
(d) You agree that You will only use the Account in a manner that complies with all applicable laws in the jurisdiction in which You use the Account, including, but not limited to, applicable restrictions concerning copyright and other intellectual property rights.
Disclaimers
AS THE USER, YOU HEREBY ACKNOWLEDGE THAT THE ACCOUNT IS PROVIDED "AS IS", WITHOUT WARRANTY OF
ANY KIND, EXPRESS OR IMPLIED, AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW. NEITHER THE
PROVIDER, ITS LICENSORS OR AFFILIATES, NOR THE COPYRIGHT HOLDERS MAKE ANY REPRESENTATIONS OR
WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY OR
FITNESS FOR A PARTICULAR PURPOSE OR THAT ACCOUNT WILL NOT INFRINGE ANY THIRD PARTY'S PATENTS,
COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS. THE PROVIDER OR ANY OTHER PARTY MAKE NO GUARANTEE THAT
THE FUNCTIONS CONTAINED IN ACCOUNT WILL MEET YOUR REQUIREMENTS OR THAT THE OPERATION OF
ACCOUNT WILL BE UNINTERRUPTED OR ERROR-FREE. YOU ASSUME ALL RESPONSIBILITY AND RISK FOR THE
SELECTION AND USE OF ACCOUNT TO ACHIEVE YOUR INTENDED RESULTS AND FOR THE RESULTS OBTAINED FROM
IT.
No other obligations. These Terms create no obligations on the part of the Provider and its licensors other than as specifically set forth herein.
Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL THE PROVIDER, ITS EMPLOYEES
OR LICENSORS BE LIABLE FOR ANY LOST PROFITS, REVENUE, SALES, DATA OR COSTS OF PROCUREMENT OF
SUBSTITUTE GOODS OR SERVICES, PROPERTY DAMAGE, PERSONAL INJURY, INTERRUPTION OF BUSINESS, LOSS OF
BUSINESS INFORMATION OR FOR ANY SPECIAL, DIRECT, INDIRECT, INCIDENTAL, ECONOMIC, COVER, PUNITIVE,
SPECIAL OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND WHETHER ARISING UNDER CONTRACT, TORT,
NEGLIGENCE OR OTHER THEORY OF LIABILITY, ARISING OUT OF THE USE OF OR INABILITY TO USE THE ACCOUNT,
EVEN IF THE PROVIDER OR ITS LICENSORS OR AFFILIATES ARE ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
BECAUSE SOME COUNTRIES AND JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF LIABILITY, BUT MAY ALLOW
LIABILITY TO BE LIMITED, IN SUCH CASES THE LIABILITY OF THE PROVIDER, ITS EMPLOYEES OR LICENSORS OR
AFFILIATES SHALL BE LIMITED TO THE SUM THAT YOU PAID TO PROVIDER.
Trade control compliance
303
(a) You will not, directly or indirectly, export, re-export, transfer or otherwise make available the Software to any person, or use it in any manner, or be involved in any act, that could result in ESET or its holding companies, its subsidiaries, and the subsidiaries of any of its holding companies, as well as entities controlled by its holding companies (hereinafter referred to as "Affiliates") being in violation of, or being subject to negative consequences under, Trade Control Laws which includes i. any laws that control, restrict, or impose licensing requirements on export, re-export or transfer of goods, software, technology, or services, issued or adopted by any government, state or regulatory authority of the United
States of America, Singapore, the United Kingdom, the European Union or any of its Member States, or any country in which obligations under these Terms are to be performed, or in which ESET or any of its Affiliates are incorporated or operate (hereinafter referred to as "Export Control Laws") and ii. any economic, financial, trade or other, sanction, restriction, embargo, import or export ban, prohibition on transfer of funds or assets or on performing services, or equivalent measure imposed by any government, state or regulatory authority of the United States of America, Singapore, the United Kingdom, the European Union or any of its Member States, or any country in which obligations under these Terms are to be performed, or in which ESET or any of its Affiliates are incorporated or operate (hereinafter referred to as "Sanction Laws").
(b) ESET shall have the right to suspend its obligations under, or terminate, these Terms with immediate effect in the event that: i. ESET determines that, in its reasonable opinion, the User has breached or is likely to breach provision of section
(a) of this Trade control compliance clause of these Terms; or ii. the End User and/or the Software become subject to Trade Control Laws and, as a result, ESET determines that, in its reasonable opinion, the continued performance of its obligations under these Terms could result in ESET or its
Affiliates being in violation of, or being subject to negative consequences under, Trade Control Laws.
(c) Nothing in these Terms is intended, and nothing should be interpreted or construed, to induce or require either party to act or refrain from acting (or to agree to act or refrain from acting) in any manner which is inconsistent with, penalized, or prohibited under any applicable Trade Control Laws.
Governing Law and Language
These Terms shall be governed by and construed in accordance with Slovak law. The End User and the Provider agree that conflict provisions of the governing law and United Nations Convention on Contracts for the
International Sale of Goods shall not apply. You expressly agree that exclusive jurisdiction for any claim or dispute with the Provider or relating in any way to your use of the Software resides in District Court Bratislava I, Slovakia and You further agree and expressly consent to the exercise of the personal jurisdiction in the District Court
Bratislava I in connection with any such dispute or claim.
In the case of discrepancies between the language versions the English version shall always prevail as the English version is deemed original.
General provisions
ESET reserves the right to revise these Terms and documentation or any portion thereof at any time by updating the relevant document to reflect changes to the law or changes to Account. You will be notified about any revision of these Terms by way of Account. If You disagree with the changes to these Terms, You may cancel your Account.
Unless You cancel your Account after being notified about the changes, You are bound by any amendments or revisions of these Terms. You are encouraged to periodically visit this page to review the current Terms that apply to your use of Account.
Notices
All notices must be delivered to: ESET, spol. s r. o., Einsteinova 24, 851 01 Bratislava, Slovak Republic.
Annex no. 1
304
Annex no. 2
Annex no. 3
ESET Management Agent EULA
IMPORTANT: Please read the terms and conditions of product application set out below carefully prior to download, installation, copy or use. THROUGH DOWNLOADING, INSTALLING, COPYING OR USING THE
SOFTWARE YOU ARE EXPRESSING YOUR CONSENT TO THESE TERMS AND CONDITIONS AND YOU
.
End User License Agreement
Under the terms of this End User License Agreement (hereinafter referred to as "the Agreement") executed by and between ESET, spol. s r. o., having its registered office at Einsteinova 24, 851 01 Bratislava, Slovak Republic, registered in the Commercial Register administered by Bratislava I District Court, Section Sro, Entry No 3586/B,
Business Registration Number: 31 333 535 (hereinafter referred to as "ESET" or "the Provider") and you, a physical person or legal entity (hereinafter referred to as "You" or "the End User"), You are entitled to use the Software defined in Article 1 of this Agreement. The Software defined in Article 1 of this Agreement can be stored on a data carrier, sent via electronic mail, downloaded from the Internet, downloaded from the Provider's servers or obtained from other sources, subject to the terms and conditions specified below.
THIS IS AN AGREEMENT ON END USER RIGHTS AND NOT AN AGREEMENT FOR SALE. The Provider continues to own the copy of the Software and the physical media contained in the sales package and any other copies that the End
User is authorized to make pursuant to this Agreement.
By clicking on "I Accept" or "I Accept…" while installing, downloading, copying or using the Software, You agree to the terms and conditions of this Agreement. If You do not agree to all of the terms and conditions of this
Agreement, immediately click on the canceling option, cancel the installation or download, or destroy or return the
Software, installation media, accompanying documentation and sales receipt to the Provider or the outlet from which You acquired the Software.
YOU AGREE THAT YOUR USE OF THE SOFTWARE ACKNOWLEDGES THAT YOU HAVE READ THIS AGREEMENT,
UNDERSTAND IT AND AGREE TO BE BOUND BY ITS TERMS AND CONDITIONS.
1. Software. As used in this Agreement the term "Software" means: (i) computer program accompanied by this
Agreement and all components thereof; (ii) all the contents of the disks, CD-ROMs, DVDs, e-mails and any attachments, or other media with which this Agreement is provided, including the object code form of the Software supplied on a data carrier, via electronic mail or downloaded via the Internet; (iii) any related explanatory written materials and any other possible documentation related to the Software, above all any description of the Software, its specifications, any description of the Software properties or operation, any description of the operating environment in which the Software is used, instructions for use or installation of the Software or any description of how to use the Software (hereinafter referred to as " Documentation "); (iv) copies of the Software, patches for possible errors in the Software, additions to the Software, extensions to the Software, modified versions of the
Software and updates of Software components, if any, licensed to You by the Provider pursuant to Article 3 of this
Agreement. The Software shall be provided exclusively in the form of executable object code.
2. Installation, Computer and a License key. Software supplied on a data carrier, sent via electronic mail, downloaded from the Internet, downloaded from the Provider's servers or obtained from other sources requires installation. You must install the Software on a correctly configured Computer, complying at least with requirements set out in the Documentation. The installation methodology is described in the Documentation. No computer programs or hardware which could have an adverse effect on the Software may be installed on the
Computer on which You install the Software. Computer means hardware, including but not limited to personal computers, laptops, workstations, palmtop computers, smart phones, hand-held electronic devices, or other
305
electronic devices for which the Software is designed, on which it will be installed and/or used. License key means the unique sequence of symbols, letters, numbers or special signs provided to the End User in order to allow the legal use of the Software, its specific version or extension of the term of the License in compliance with this
Agreement.
3. License. Subject to the condition that You have agreed to the terms of this Agreement and You comply with all the terms and conditions stipulated herein, the Provider shall grant You the following rights (hereinafter referred to as "License"): a) Installation and use. You shall have the non-exclusive, non-transferable right to install the Software on the hard disk of a Computer or other permanent medium for data storage, installation and storage of the Software in the memory of a computer system and to implement, store and display the Software.
b) Stipulation of the number of licenses. The right to use the Software shall be bound by the number of End
Users. One End User shall be taken to refer to the following: (i) installation of the Software on one computer system; or (ii) if the extent of a license is bound to the number of mail boxes, then one End User shall be taken to refer to a computer user who accepts electronic mail via a Mail User Agent (hereinafter referred to as "MUA"). If
MUA accepts electronic mail and subsequently distributes it automatically to several users, then the number of End
Users shall be determined according to the actual number of users for whom the electronic mail is distributed. If a mail server performs the function of a mail gate, the number of End Users shall equal the number of mail server users for which the said gate provides services. If an unspecified number of electronic mail addresses are directed to and accepted by one user (e.g., through aliases) and messages are not automatically distributed by the client to a larger number of users, a License for one computer shall be required. You must not use the same License at the same time on more than one Computer. The End User is entitled to enter the License key to the Software only to the extent in which has the right to use the Software in accordance the limitation arising from the number of
Licenses granted by Provider. The License key is deemed confidential, You must not share the License with third parties or allow third parties to use the License key unless permitted by this Agreement or Provider. If your License key is compromised, notify Provider immediately.
c) Business Edition. A Business Edition version of the Software must be obtained to use the Software on mail servers, mail relays, mail gateways or Internet gateways.
d) Term of the License. Your right to use the Software shall be time-limited.
e) OEM Software. OEM Software shall be limited to the Computer You obtained it with. It cannot be transferred to a different Computer.
f) NFR, TRIAL Software. Software classified as "Not-for-resale", NFR or TRIAL cannot be assigned for payment and must only be used for demonstration or testing the Software's features.
g) Termination of the License. The License shall terminate automatically at the end of the period for which granted. If You fail to comply with any of the provisions of this Agreement, the Provider shall be entitled to withdraw from the Agreement, without prejudice to any entitlement or legal remedy open to the Provider in such eventualities. In the event of cancellation of the License, You must immediately delete, destroy or return at your own cost, the Software and all backup copies to ESET or to the outlet from which You obtained the Software. Upon termination of the License, the Provider shall be also entitled to cancel the End User's entitlement to use the functions of the Software, which require connection to the Provider's servers or third-party servers.
4. Functions with data collection and internet connection requirements. To operate correctly the Software requires connection to the Internet and must connect at regular intervals to the Provider's servers or third-party servers and applicable data collection in compliance with Privacy Policy. Connection to the Internet and applicable data collection is necessary for the following functions of the Software: a) Updates to the Software. The Provider shall be entitled from time to issue updates to the Software
("Updates"), but shall not be obliged to provide Updates. This function is enabled under the Software's standard settings and Updates are therefore installed automatically, unless the End User has disabled automatic installation of Updates. For the purpose of provisioning of Updates, License authenticity verification is required including information about Computer and/or the platform on which the Software is installed in compliance with Privacy
Policy.
306
b) Communication and Managing Data. The Software contains a function, which enables transfer of information between Computer and remote management software. Information, which are subject to transfer contains management data such as hardware and software information of managed computer and managing instructions from the remote management software. Other content of data transferred from Computer shall be determined by the settings of software installed on Computer. The content of instructions from management software shall be determined by settings of remote management software.
For the purpose of this Agreement, it is necessary to collect, process and store data enabling the Provider to identify You in compliance with Privacy Policy. You hereby acknowledge that the Provider checks using its own means whether You are using the Software in accordance with the provisions of this Agreement. You hereby acknowledge that for the purpose of this Agreement it is necessary for your data to be transferred, during communication between the Software and the Provider's computer systems or those of its business partners as part of Provider’s distribution and support network to ensure functionality of Software and authorization to use the
Software and to protection of the Provider’s rights.
Following conclusion of this Agreement, the Provider or any of its business partners as part of Provider’s distribution and support network shall be entitled to transfer, process and store essential data identifying You for billing purposes, performance of this Agreement and transmitting notifications on your Computer. You hereby agree to receive notification and messages including but not limited to marketing information.
Details about privacy, personal data protection and Your rights as a data subject can be found in
Privacy Policy which is available on Provider’s website and accessible directly from the installation process. You can also visit it from Software’s help section.
5. Exercising End User rights. You must exercise End User rights in person or via your employees. You are only entitled to use the Software to safeguard your operations and protect those Computers or computers systems for which You have obtained a License.
6. Restrictions to rights. You may not copy, distribute, extract components or make derivative works of the
Software. When using the Software, You are required to comply with the following restrictions: a) You may make one copy of the Software on a permanent storage medium as an archival back-up copy, provided your archival back-up copy is not installed or used on any Computer. Any other copies You make of the Software shall constitute breach of this Agreement.
b) You may not use, modify, translate or reproduce the Software or transfer rights to use the Software or copies of the Software in any manner other than as provided for in this Agreement.
c) You may not sell, sub-license, lease or rent or borrow the Software or use the Software for the provision of commercial services.
d) You may not reverse engineer, reverse compile or disassemble the Software or otherwise attempt to discover the source code of the Software, except to the extent that this restriction is expressly prohibited by law.
e) You agree that You will only use the Software in a manner that complies with all applicable laws in the jurisdiction in which You use the Software, including, but not limited to, applicable restrictions concerning copyright and other intellectual property rights.
f) You agree that You will only use the Software and its functions in a way which does not limit the possibilities of other End Users to access these services. The Provider reserves the right to limit the scope of services provided to individual End Users, to enable use of the services by the highest possible number of End Users. Limiting the scope of services shall also mean complete termination of the possibility to use any of the functions of the Software and deletion of Data and information on the Provider's servers or third-party servers relating to a specific function of the Software.
g) You agree not exercise any activities involving use the License key, contrary to the terms of this Agreement or leading to provide License key to any person who is not entitled to use the Software, such as the transfer of used or unused License key in any form, as well as the unauthorized reproduction, or distribution of duplicated or generated License keys or using the Software as a result of the use of a License key obtained from the source
307
other than the Provider.
7. Copyright. The Software and all rights, without limitation including proprietary rights and intellectual property rights thereto are owned by ESET and/or its licensors. They are protected by international treaty provisions and by all other applicable national laws of the country in which the Software is being used. The structure, organization and code of the Software are the valuable trade secrets and confidential information of ESET and/or its licensors.
You must not copy the Software, except as set forth in Article 6(a). Any copies which You are permitted to make pursuant to this Agreement must contain the same copyright and other proprietary notices that appear on the
Software. If You reverse engineer, reverse compile, disassemble or otherwise attempt to discover the source code of the Software, in breach of the provisions of this Agreement, You hereby agree that any information thereby obtained shall automatically and irrevocably be deemed to be transferred to and owned by the Provider in full, from the moment such information comes into being, notwithstanding the Provider's rights in relation to breach of this Agreement.
8. Reservation of rights. The Provider hereby reserves all rights to the Software, with the exception of rights expressly granted under the terms of this Agreement to You as the End User of the Software.
9. Multiple language versions, dual media software, multiple copies. In the event that the Software supports multiple platforms or languages, or if You receive multiple copies of the Software, You may only use the
Software for the number of computer systems and for the versions for which You obtained a License. You may not sell, rent, lease, sub-license, lend or transfer versions or copies of the Software which You do not use.
10. Commencement and termination of the Agreement. This Agreement shall be effective from the date You agree to the terms of this Agreement. You may terminate this Agreement at any time by permanently uninstalling, destroying and returning, at your own cost, the Software, all back-up copies and all related materials provided by the Provider or its business partners. Irrespective of the manner of termination of this Agreement, the provisions of
Articles 7, 8, 11, 13, 19 and 21 shall continue to apply for an unlimited time.
11. END USER DECLARATIONS. AS THE END USER YOU ACKNOWLEDGE THAT THE SOFTWARE IS PROVIDED "AS
IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, AND TO THE MAXIMUM EXTENT PERMITTED BY
APPLICABLE LAW. NEITHER THE PROVIDER, ITS LICENSORS OR AFFILIATES, NOR THE COPYRIGHT HOLDERS MAKE
ANY REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE OR THAT THE SOFTWARE WILL NOT
INFRINGE ANY THIRD-PARTY PATENTS, COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS. THERE IS NO WARRANTY BY
THE PROVIDER OR BY ANY OTHER PARTY THAT THE FUNCTIONS CONTAINED IN THE SOFTWARE WILL MEET YOUR
REQUIREMENTS OR THAT THE OPERATION OF THE SOFTWARE WILL BE UNINTERRUPTED OR ERROR-FREE. YOU
ASSUME ALL RESPONSIBILITY AND RISK FOR THE SELECTION OF THE SOFTWARE TO ACHIEVE YOUR INTENDED
RESULTS AND FOR THE INSTALLATION, USE AND RESULTS OBTAINED FROM IT.
12. No other obligations. This Agreement creates no obligations on the part of the Provider and its licensors other than as specifically set forth herein.
13. LIMITATION OF LIABILITY. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL
THE PROVIDER, ITS EMPLOYEES OR LICENSORS BE LIABLE FOR ANY LOST PROFITS, REVENUE, SALES, DATA OR
COSTS OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, PROPERTY DAMAGE, PERSONAL INJURY,
INTERRUPTION OF BUSINESS, LOSS OF BUSINESS INFORMATION OR FOR ANY SPECIAL, DIRECT, INDIRECT,
INCIDENTAL, ECONOMIC, COVER, PUNITIVE, SPECIAL OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED AND
WHETHER ARISING UNDER CONTRACT, TORT, NEGLIGENCE OR OTHER THEORY OF LIABILITY, ARISING OUT OF THE
USE OF OR INABILITY TO USE THE SOFTWARE, EVEN IF THE PROVIDER OR ITS LICENSORS OR AFFILIATES ARE
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. BECAUSE SOME COUNTRIES AND JURISDICTIONS DO NOT
ALLOW THE EXCLUSION OF LIABILITY, BUT MAY ALLOW LIABILITY TO BE LIMITED, IN SUCH CASES, THE LIABILITY OF
THE PROVIDER, ITS EMPLOYEES OR LICENSORS OR AFFILIATES SHALL BE LIMITED TO THE SUM THAT YOU PAID FOR
THE LICENSE.
14. Nothing contained in this Agreement shall prejudice the statutory rights of any party dealing as a consumer if running contrary thereto.
15. Technical support. ESET or third parties commissioned by ESET shall provide technical support at their own discretion, without any guarantees or declarations. The End User shall be required to back up all existing data,
308
software and program facilities prior to the provision of technical support. ESET and/or third parties commissioned by ESET cannot accept liability for damage or loss of data, property, software or hardware or loss of profits due to the provision of technical support. ESET and/or third parties commissioned by ESET reserve the right to decide that resolving the problem is beyond the scope of technical support. ESET reserves the right to refuse, suspend or terminate the provision of technical support at its own discretion. License information, Information and other data in compliance with Privacy Policy may be required for the purpose of technical support provision.
16. Transfer of the License. The Software can be transferred from one Computer to another, unless contrary to the terms of the Agreement. If not contrary to the terms of the Agreement, the End User shall only be entitled to permanently transfer the License and all rights ensuing from this Agreement to another End User with the
Provider's consent, subject to the condition that (i) the original End User does not retain any copies of the
Software; (ii) the transfer of rights must be direct, i.e. from the original End User to the new End User; (iii) the new
End User must assume all the rights and obligations incumbent on the original End User under the terms of this
Agreement; (iv) the original End User has to provide the new End User with documentation enabling verification of the genuineness of the Software as specified under Article 17.
17. Verification of the genuineness of the Software. The End User may demonstrate entitlement to use the
Software in one of the following ways: (i) through a license certificate issued by the Provider or a third party appointed by the Provider; (ii) through a written license agreement, if such an agreement was concluded; (iii) through the submission of an e-mail sent by the Provider containing licensing details (user name and password).
License information and End User identification data in compliance with Privacy Policy may be required for the purpose of Software genuineness verification.
18. Licensing for public authorities and the US Government. The Software shall be provided to public authorities, including the United States Government, with the license rights and restrictions described in this
Agreement.
19. Trade control compliance.
a) You will not, directly or indirectly, export, re-export, transfer or otherwise make available the Software to any person, or use it in any manner, or be involved in any act, that could result in ESET or its holding companies, its subsidiaries, and the subsidiaries of any of its holding companies, as well as entities controlled by its holding companies (hereinafter referred to as "Affiliates") being in violation of, or being subject to negative consequences under, Trade Control Laws which includes i. any laws that control, restrict, or impose licensing requirements on export, re-export or transfer of goods, software, technology, or services, issued or adopted by any government, state or regulatory authority of the United
States of America, Singapore, the United Kingdom, the European Union or any of its Member States, or any country in which obligations under the Agreement are to be performed, or in which ESET or any of its Affiliates are incorporated or operate (hereinafter referred to as "Export Control Laws") and ii. any economic, financial, trade or other, sanction, restriction, embargo, import or export ban, prohibition on transfer of funds or assets or on performing services, or equivalent measure imposed by any government, state or regulatory authority of the United States of America, Singapore, the United Kingdom, the European Union or any of its Member States, or any country in which obligations under the Agreement are to be performed, or in which ESET or any of its Affiliates are incorporated or operate (hereinafter referred to as "Sanction Laws").
b) ESET shall have the right to suspend its obligations under, or terminate, these Terms with immediate effect in the event that: i. ESET determines that, in its reasonable opinion, the User has breached or is likely to breach provision of Article
19.a of the Agreement; or ii. the End User and/or the Software become subject to Trade Control Laws and, as a result, ESET determines that, in its reasonable opinion, the continued performance of its obligations under the Agreement could result in ESET or its Affiliates being in violation of, or being subject to negative consequences under, Trade Control Laws.
c) Nothing in the Agreement is intended, and nothing should be interpreted or construed, to induce or require either party to act or refrain from acting (or to agree to act or refrain from acting) in any manner which is
309
inconsistent with, penalized, or prohibited under any applicable Trade Control Laws.
20. Notices. All notices and return of the Software and Documentation must be delivered to: ESET, spol. s r. o.,
Einsteinova 24, 851 01 Bratislava, Slovak Republic.
21. Applicable law. This Agreement shall be governed by and construed in accordance with the laws of the Slovak
Republic. The End User and the Provider hereby agree that the principles of the conflict of laws and the United
Nations Convention on Contracts for the International Sale of Goods shall not apply. You expressly agree that any disputes or claims ensuing from this Agreement with respect to the Provider or any disputes or claims relating to use of the Software shall be settled by Bratislava I District Court and You expressly agree to the said court exercising jurisdiction.
22. General provisions. Should any of the provisions of this Agreement be invalid or unenforceable, this shall not affect the validity of the other provisions of the Agreement, which shall remain valid and enforceable under the conditions stipulated therein. In case of a discrepancy between language versions of this Agreement, the English version shall prevail. This Agreement may only be modified in written form, signed by an authorized representative of the Provider, or a person expressly authorized to act in this capacity under the terms of a power of attorney.
This is the entire Agreement between the Provider and You relating to the Software and it supersedes any prior representations, discussions, undertakings, communications or advertising relating to the Software.
EULA ID: BUS-ESMC-AGENT-20-01
Data Processing Agreement
According to the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27
April 2016 on the Protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter referred to as the "GDPR"), Provider (hereinafter referred to as the "Processor") and You (hereinafter referred to as the "Controller") are entering into the data processing contractual relationship in order to define the terms and conditions for the processing of personal data, the manner of its protection, as well as to define other rights and obligations of the both parties in the processing of personal data of data subjects on behalf of the Controller during the course of performing the subject matter of these Terms as the main contract.
1. Personal Data Processing. The services provided in compliance with these Terms may include processing of information relating to an identified or identifiable natural person listed in Privacy Policy of service available on help.eset.com website (hereinafter referred to as the "Personal data").
2. Authorization. The Controller authorizes the Processor to process Personal Data, including
(i) “Purpose of processing” shall mean provision of services in compliance with these Terms,
(ii) processing period shall mean period from entering mutual cooperation under these Terms to termination of services,
(iii) scope and categories of Personal data shall include general personal data, excluding any and all special categories of personal data,
(iv) “Data subject” shall mean natural person as authorized user of Controller’s devices,
(v) processing operations shall mean every and all operations necessary for the purpose of processing,
(vi) “Documented instructions” shall mean instructions described in these Terms, its Annexes, Privacy Policy and documentation of service.
3. Obligations of Processor. The Processor shall be obliged to:
(i) process Personal Data only on the grounds of Documented instructions,
310
(ii) ensure that persons authorized to process the Personal data have committed themselves to confidentiality,
(iii) take all measures described in these Terms, its Annexes, Privacy Policy and documentation of service,
(iv) assist the Controller with responding to requests for exercising the Data subject's rights, security of processing as described in par. iii of this article and notification of personal data breach to the supervisory authority and Data
Subject,
(v) delete or return all the Personal data to the Controller after the end of the provision of services relating to processing,
(vi) keep an up-to-date register of all the categories of processing activities that it has carried out on behalf of
Controller,
(vii) make available to the Controller all information necessary to demonstrate compliance as part of these Terms, its Annexes, Privacy Policy and documentation of service.
4. Engaging Another Processor. The Processor is entitled to engage another processor for carrying out specific processing activities such as provision of cloud storage and infrastructure for the service in compliance with these
Terms, this Annex, Privacy Policy and documentation of service. Even in this case, the Processor shall remain the only point of contact and the party responsible for compliance.
5. Territory of Processing. The Processor ensures that processing takes place in the European Economic Area or a country designated as safe by decision of European Commission based on the decision of Controller. Standard
Contractual Clauses shall apply in case of transfers and processing located outside of European Economic Area or a country designated as safe by decision of European Commission.
6. Security. The Processor is ISO 27001:2013 certified and uses the ISO 27001 framework to implement a layered defense security strategy when applying security controls on the layer of network, operating systems, databases, applications, personnel and operating processes. Compliance with the regulatory and contractual requirements is regularly assessed and reviewed similarly to other infrastructure and processes of Processor, and necessary steps are taken to provide compliance on a continuous basis. The Processor has organized the security of the data using
ISMS, on the basis of ISO 27001. The security documentation includes mainly policy documents for information security, physical security and security of equipment, incident management, handling of data leaks and security incidents, etc.
7. Processor’s Contact Information. All notifications, requests, demands and other communication concerning personal data protection shall be addressed to ESET, spol. s.r.o., attention of: Data Protection Officer, Einsteinova
24, 85101 Bratislava, Slovak Republic, email: [email protected].
Standard Contractual Clauses
For the purposes of Article 26(2) of Directive 95/46/EC for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection the Controller specified in the Annex no. 2 Data Processing Agreement (the "data exporter") and the Processor specified in the Annex no. 2 Data Processing Agreement (the "data importer") each a 'party'; together 'the parties',
HAVE AGREED on the following Contractual Clauses (the Clauses) in order to adduce adequate safeguards with respect to the protection of privacy and fundamental rights and freedoms of individuals for the transfer by the data exporter to the data importer of the personal data specified in Appendix 1 which forms an integral part of the
Clauses (the "Appendix 1").
311
Clause 1 Definitions
For the purposes of the Clauses:
(a) 'the data exporter' means the controller who transfers the personal data in its own name and on behalf of its affiliates;
(b) 'the data importer' means the processor who agrees to receive from the data exporter personal data intended for processing on his behalf after the transfer in accordance with his instructions and the terms of the Clauses and who is not subject to a third country's system ensuring adequate protection;
(c) 'the subprocessor' means any processor engaged by the data importer or by any other subprocessor of the data importer who agrees to receive from the data importer or from any other subprocessor of the data importer personal data exclusively intended for processing activities to be carried out on behalf of the data exporter after the transfer in accordance with his instructions, the terms of the Clauses and the terms of the written subcontract;
(d) 'the applicable data protection law' means the legislation protecting the fundamental rights and freedoms of individuals and, in particular, their right to privacy with respect to the processing of personal data applicable to a data controller in the Member State in which the data exporter is established;
(e) 'technical and organisational security measures' means those measures aimed at protecting personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing specified in Appendix 2 which forms an integral part of the Clauses.
Clause 2 Details of the transfer
The details of the transfer and in particular the special categories of personal data where applicable are specified in Appendix 1.
Clause 3 Third-party beneficiary clause
1. The data subject can enforce against the data exporter this Clause, Clause 4(b) to (i), Clause 5(a) to (e), and (g) to (j), Clause 6(1) and (2), Clause 7, Clause 8(2), and Clauses 9 to 12 as third-party beneficiary.
2. The data subject can enforce against the data importer this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause
7, Clause 8(2), and Clauses 9 to 12, in cases where the data exporter has factually disappeared or has ceased to exist in law unless any successor entity has assumed the entire legal obligations of the data exporter by contract or by operation of law, as a result of which it takes on the rights and obligations of the data exporter, in which case the data subject can enforce them against such entity.
3. The data subject can enforce against the subprocessor this Clause, Clause 5(a) to (e) and (g), Clause 6, Clause 7,
Clause 8(2), and Clauses 9 to 12, in cases where both the data exporter and the data importer have factually disappeared or ceased to exist in law or have become insolvent, unless any successor entity has assumed the entire legal obligations of the data exporter by contract or by operation of law as a result of which it takes on the rights and obligations of the data exporter, in which case the data subject can enforce them against such entity.
Such third-party liability of the subprocessor shall be limited to its own processing operations under the Clauses.
4. The parties do not object to a data subject being represented by an association or other body if the data subject so expressly wishes and if permitted by national law.
Clause 4 Obligations of the data exporter
The data exporter agrees and warrants:
(a) that the processing, including the transfer itself, of the personal data has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law (and, where applicable, has been notified to the relevant authorities of the Member State where the data exporter is established) and does not violate the relevant provisions of that State;
312
(b) that it has instructed and throughout the duration of the personal data processing services will instruct the data importer to process the personal data transferred only on the data exporter's behalf and in accordance with the applicable data protection law and the Clauses;
(c) that the data importer will provide sufficient guarantees in respect of the technical and organisational security measures specified in Appendix 2;
(d) that after assessment of the requirements of the applicable data protection law, the security measures are appropriate to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing, and that these measures ensure a level of security appropriate to the risks presented by the processing and the nature of the data to be protected having regard to the state of the art and the cost of their implementation;
(e) that it will ensure compliance with the security measures;
(f) that, if the transfer involves special categories of data, the data subject has been informed or will be informed before, or as soon as possible after, the transfer that its data could be transmitted to a third country not providing adequate protection;
(g) to forward any notification received from the data importer or any subprocessor pursuant to Clause 5(b) and
Clause 8(3) to the data protection supervisory authority if the data exporter decides to continue the transfer or to lift the suspension;
(h) to make available to the data subjects upon request a copy of the Clauses, with the exception of Appendix 2, and a summary description of the security measures, as well as a copy of any contract for subprocessing services which has to be made in accordance with the Clauses, unless the Clauses or the contract contain commercial information, in which case it may remove such commercial information;
(i) that, in the event of subprocessing, the processing activity is carried out in accordance with Clause 11 by a subprocessor providing at least the same level of protection for the personal data and the rights of data subject as the data importer under the Clauses; and
(j) that it will ensure compliance with Clause 4(a) to (i).
Clause 5 Obligations of the data importer
The data importer agrees and warrants:
(a) to process the personal data only on behalf of the data exporter and in compliance with its instructions and the
Clauses; if it cannot provide such compliance for whatever reasons, it agrees to inform promptly the data exporter of its inability to comply, in which case the data exporter is entitled to suspend the transfer of data and/or terminate the contract;
(b) that it has no reason to believe that the legislation applicable to it prevents it from fulfilling the instructions received from the data exporter and its obligations under the contract and that in the event of a change in this legislation which is likely to have a substantial adverse effect on the warranties and obligations provided by the
Clauses, it will promptly notify the change to the data exporter as soon as it is aware, in which case the data exporter is entitled to suspend the transfer of data and/or terminate the contract;
(c) that it has implemented the technical and organisational security measures specified in Appendix 2 before processing the personal data transferred;
(d) that it will promptly notify the data exporter about:
(i) any legally binding request for disclosure of the personal data by a law enforcement authority unless otherwise prohibited, such as a prohibition under criminal law to preserve the confidentiality of a law enforcement investigation,
(ii) any accidental or unauthorised access, and
313
(iii) any request received directly from the data subjects without responding to that request, unless it has been otherwise authorised to do so;
(e) to deal promptly and properly with all inquiries from the data exporter relating to its processing of the personal data subject to the transfer and to abide by the advice of the supervisory authority with regard to the processing of the data transferred;
(f) at the request of the data exporter to submit its data processing facilities for audit of the processing activities covered by the Clauses which shall be carried out by the data exporter or an inspection body composed of independent members and in possession of the required professional qualifications bound by a duty of confidentiality, selected by the data exporter, where applicable, in agreement with the supervisory authority;
(g) to make available to the data subject upon request a copy of the Clauses, or any existing contract for subprocessing, unless the Clauses or contract contain commercial information, in which case it may remove such commercial information, with the exception of Appendix 2 which shall be replaced by a summary description of the security measures in those cases where the data subject is unable to obtain a copy from the data exporter;
(h) that, in the event of subprocessing, it has previously informed the data exporter and obtained its prior written consent;
(i) that the processing services by the subprocessor will be carried out in accordance with Clause 11;
(j) to send promptly a copy of any subprocessor agreement it concludes under the Clauses to the data exporter.
Clause 6 Liability
1. The parties agree that any data subject, who has suffered damage as a result of any breach of the obligations referred to in Clause 3 or in Clause 11 by any party or subprocessor is entitled to receive compensation from the data exporter for the damage suffered.
2. If a data subject is not able to bring a claim for compensation in accordance with paragraph 1 against the data exporter, arising out of a breach by the data importer or his subprocessor of any of their obligations referred to in
Clause 3 or in Clause 11, because the data exporter has factually disappeared or ceased to exist in law or has become insolvent, the data importer agrees that the data subject may issue a claim against the data importer as if it were the data exporter, unless any successor entity has assumed the entire legal obligations of the data exporter by contract of by operation of law, in which case the data subject can enforce its rights against such entity.
3. The data importer may not rely on a breach by a subprocessor of its obligations in order to avoid its own liabilities.
4. If a data subject is not able to bring a claim against the data exporter or the data importer referred to in paragraphs 1 and 2, arising out of a breach by the subprocessor of any of their obligations referred to in Clause 3 or in Clause 11 because both the data exporter and the data importer have factually disappeared or ceased to exist in law or have become insolvent, the subprocessor agrees that the data subject may issue a claim against the data subprocessor with regard to its own processing operations under the Clauses as if it were the data exporter or the data importer, unless any successor entity has assumed the entire legal obligations of the data exporter or data importer by contract or by operation of law, in which case the data subject can enforce its rights against such entity. The liability of the subprocessor shall be limited to its own processing operations under the Clauses.
Clause 7 Mediation and jurisdiction
1. The data importer agrees that if the data subject invokes against it third-party beneficiary rights and/or claims compensation for damages under the Clauses, the data importer will accept the decision of the data subject:
(a) to refer the dispute to mediation, by an independent person or, where applicable, by the supervisory authority;
(b) to refer the dispute to the courts in the Member State in which the data exporter is established.
2. The parties agree that the choice made by the data subject will not prejudice its substantive or procedural rights to seek remedies in accordance with other provisions of national or international law.
314
Clause 8 Cooperation with supervisory authorities
1. The data exporter agrees to deposit a copy of this contract with the supervisory authority if it so requests or if such deposit is required under the applicable data protection law.
2. The parties agree that the supervisory authority has the right to conduct an audit of the data importer, and of any subprocessor, which has the same scope and is subject to the same conditions as would apply to an audit of the data exporter under the applicable data protection law.
3. The data importer shall promptly inform the data exporter about the existence of legislation applicable to it or any subprocessor preventing the conduct of an audit of the data importer, or any subprocessor, pursuant to paragraph 2. In such a case the data exporter shall be entitled to take the measures foreseen in Clause 5 (b).
Clause 9 Governing Law
The Clauses shall be governed by the law of the Member State in which the data exporter is established.
Clause 10 Variation of the contract
The parties undertake not to vary or modify the Clauses. This does not preclude the parties from adding clauses on business related issues where required as long as they do not contradict the Clause.
Clause 11 Subprocessing
1. The data importer shall not subcontract any of its processing operations performed on behalf of the data exporter under the Clauses without the prior written consent of the data exporter. Where the data importer subcontracts its obligations under the Clauses, with the consent of the data exporter, it shall do so only by way of a written agreement with the subprocessor which imposes the same obligations on the subprocessor as are imposed on the data importer under the Clauses. Where the subprocessor fails to fulfil its data protection obligations under such written agreement the data importer shall remain fully liable to the data exporter for the performance of the subprocessor's obligations under such agreement.
2. The prior written contract between the data importer and the subprocessor shall also provide for a third-party beneficiary clause as laid down in Clause 3 for cases where the data subject is not able to bring the claim for compensation referred to in paragraph 1 of Clause 6 against the data exporter or the data importer because they have factually disappeared or have ceased to exist in law or have become insolvent and no successor entity has assumed the entire legal obligations of the data exporter or data importer by contract or by operation of law. Such third-party liability of the subprocessor shall be limited to its own processing operations under the Clauses.
3. The provisions relating to data protection aspects for subprocessing of the contract referred to in paragraph 1 shall be governed by the law of the Member State in which the data exporter is established.
4. The data exporter shall keep a list of subprocessing agreements concluded under the Clauses and notified by the data importer pursuant to Clause 5 (j), which shall be updated at least once a year. The list shall be available to the data exporter's data protection supervisory authority.
Clause 12 Obligation after the termination of personal data processing services
1. The parties agree that on the termination of the provision of data processing services, the data importer and the subprocessor shall, at the choice of the data exporter, return all the personal data transferred and the copies thereof to the data exporter or shall destroy all the personal data and certify to the data exporter that it has done so, unless legislation imposed upon the data importer prevents it from returning or destroying all or part of the personal data transferred. In that case, the data importer warrants that it will guarantee the confidentiality of the personal data transferred and will not actively process the personal data transferred anymore.
2. The data importer and the subprocessor warrant that upon request of the data exporter and/or of the supervisory authority, it will submit its data processing facilities for an audit of the measures referred to in paragraph 1.
Appendix no. 1 to Annex no. 3: Standard Contractual Clauses
315
Data Exporter
The Controller specified in the Annex no. 2 Data Processing Agreement of these Terms.
Data Importer
The Processor specified in the Annex no. 2 Data Processing Agreement of these Terms.
Data Subjects
Employees, customers, business partners, etc. of Data Exporter according to its sole decision.
Categories of Data
Any data according to sole decision of Data Exporter.
Special Categories of Data
The processing of special categories of data is solely based on the decision of Data Exporter.
Processing operations
As described in these Terms, its Annexes and Privacy Policy.
Appendix no. 2 to Annex no. 3: Standard Contractual Clauses
Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) as described in these Terms, its Annexes and Privacy Policy.
Privacy policy
ESET, spol. s r. o., having its registered office at Einsteinova 24, 851 01 Bratislava, Slovak Republic, registered in the Commercial Register administered by Bratislava I District Court, Section Sro, Entry No 3586/B, Business
Registration Number: 31 333 535 as a Data Controller ("ESET" or "We") would like to be transparent when it comes to processing of personal data and privacy of our customers. To achieve this goal, We are publishing this Privacy
Policy with the sole purpose of informing our customer ("End User" or "You") about following topics:
• Processing of Personal Data,
• Data Confidentiality,
• Data Subject's Rights.
Processing of Personal Data
Services provided by ESET implemented in our web-based product are provided under the Terms of Use (“Terms”), but some of them might require specific attention. We would like to provide You with more details on data processing connected with the provision of our products and services. We render various services described in the
ToU and documentation. To make it all work, We need to collect the following information:
• Management of ESET security products requires seat ID and name, product name, license information, activation and expiration information, hardware and software information concerning managed devices with
ESET security product installed. Logs concerning activities of managed ESET security products and devices are collected and available in order to facilitate managing and supervising features and services.
• Other processed information may include information concerning installation process, including platform on which our product is installed and information about the operations and functionality of our products or managed
316
devices, such as hardware fingerprint, installation IDs, license IDs, IP address, MAC address, used email addresses, GPS coordinates of a mobile device or configuration settings of product.
• For the security of infrastructure and reporting purposes, telemetry information need to be processed including numbers of users, policies, logins, tasks, notifications, managed devices, threats, etc. as well as HTTP headers.
• Licensing information such as license ID and personal data such as name, surname, address, email address is required for billing purposes, license genuineness verification and provision of our services.
• Contact information and data contained in your support requests may be required for service of support. Based on the channel You choose to contact us, We may collect your email address, phone number, license information, product details and description of your support case. You may be asked to provide us with other information to facilitate service of support such as generated log files.
• Data concerning usage of our service are completely anonymous by the end of session. No personally identifiable information is stored after the session ends.
• Customer feedback may be provided by You via web form and for the purpose of follow-up your email may be requested as well as licensing information and number of managed devices.
Data Confidentiality
ESET is a company operating worldwide via affiliated entities or partners as part of our distribution, service, and support network. Information processed by ESET may be transferred to and from affiliated entities or partners for the performance of the Terms, such as the provision of services, support, or billing. Based on your location and service You choose to use, We might be required to transfer your data to a country with the absence of an adequacy decision issued by the European Commission. Even in this case, every transfer of information is subject to the regulation of data protection legislation and takes place only if required. Standard Contractual Clauses,
Binding Corporate Rules, or another appropriate safeguard must be established without any exception.
We are doing our best to prevent data from being stored longer than necessary while providing services under the
Terms. Our retention period might be longer than the validity of your license just to give You time for easy and comfortable renewal. Minimized and pseudonymized statistics and anonymized data may be further processed for statistical purposes.
ESET implements appropriate technical and organizational measures to ensure a level of security which is appropriate to potential risks. We are doing our best to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and Services. However, in case of data breach resulting in a risk to your rights and freedoms, We are ready to notify supervisory authority as well as data subjects. Data Subject has a right to lodge a complaint with a supervisory authority.
Data Subject’s Rights
ESET is subject to regulation of Slovak laws and We are bound by data protection legislation as part of European
Union. Subject to conditions laid down by applicable data protection laws, You are entitled to following rights as a data subject:
• right to request access to your personal data from ESET,
• right to rectification of your personal data if inaccurate (You also have the right to have the incomplete personal data completed),
• right to request erasure of your personal data,
• right to request restriction of processing your personal data,
• right to object to processing,
• right to lodge a complaint as well as,
• right to data portability.
317
We believe that every information we process is valuable and necessary for the purpose of our legitimate interest which is provision of services and products to our customers.
If You would like to exercise your right as a data subject or You have a question or concern, send us a message at:
ESET, spol. s r.o.
Data Protection Officer
Einsteinova 24
85101 Bratislava
Slovak Republic [email protected]
Cloud Eligible Licenses
Cloud eligible licenses are licenses that can be used with ESET PROTECT Cloud.
See the table below, which licenses can be used to create ESET PROTECT Cloud instance and which license bundles are used only to activate specific product features.
License bundle name
ESET Endpoint Protection Standard Cloud
ESET PROTECT Entry
(old name: ESET Endpoint Protection Advanced Cloud)
ESET Secure Business Cloud
ESET PROTECT Advanced
(old name: ESET Remote Workforce Offer)
ESET PROTECT Complete
ESET PROTECT Enterprise
ESET PROTECT Mail Plus
ESET Security for Microsoft SharePoint Server (Per Server)
ESET Dynamic Threat Defence
ESET Dynamic Threat Defence for Endpoint Security + File
Security
ESET Dynamic Threat Defence for Mail Security
ESET Full Disk Encryption for ECA
Preview features
✔
✔
✔
✔
✔
✔
Eligible to create
ESET PROTECT
Cloud instance in
ESET Business
Account
✔
✔ ✔
Eligible to create ESET
PROTECT Cloud instance in ESET MSP
Administrator
✔
✔
✔
Preview features allow user to try individual new upcoming features in the ESET PROTECT Cloud.
You can access the Preview Features menu from the Quick Links drop-down.
318
In the preview features menu, the administrator can find all available preview features with a short description of each preview feature functionality. The administrator can then Activate or Deactivate each of the preview features and also Submit Feedback for each of the available preview features.
319
After activation, the preview feature is instantly available in the management console.
The latest preview features available in your management console are:
•
iOS/iPad Mobile Device Management functionality
•
Computer preview pop-up window
iOS management
Management of iOS devices preview feature allows the CloudMDM functionality to also enroll and manage iOS devices in ESET PROTECT Cloud.
Note
Apple Business Management is not currently supported by this feature.
By enabling this feature you will:
• add an option in mobile enrollment menu to enroll iOS devices
• add ESET MDM for iOS /iPadOS policy
• add iOS-related options in Anti-Theft Actions Client task.
iOS enrollment:
Once activated, navigate to Computers section -> Add new -> Mobile devices. Here you can follow the
for Android devices. The iOS enrollment will be available under Select type: Android
or iOS /iPadOS option.
Important
Known Issue: iOS enrollment email describes enrollment for Android devices. To enroll an iOS device, open the enrollment link in the email or scan the QR code.
iOS management:
After the successful enrollment of your iOS mobile devices you can start to manage them.
several features available only for mobile device management.
: These are tasks available for managed mobile devices only, such as Find, Lock and Wipe.
These enable administrator to remotely locate the mobile device, Lock it and if the situation requires, wipe the mobile device.
Assign the ESET MDM for iOS /iPadOS policy, where you can customize each of the available iOS management settings.
Computer preview
Computer preview functionality is accessible from the Computers menu.
After the user left-clicks on a computer name the Computer preview window will be displayed on the right side of the Computers menu. Computer preview window contains the most important information about the selected computer.
Computer preview manipulation
320
•
Show details - open the Computer Details menu
• Next - opens the Computers preview window on the next device
• Previous - opens the Computers preview window on the previous device
• Manage content for Computer Details - In this window, the user can manage which of the sections of the Computer preview window is displayed and in what order.
• Close - closes the Computers preview window
321
Download
Advertisement
Key features
Cloud-based management
Endpoint security management
Remote deployment options
Policy-based configuration
Detailed reporting
Mobile Device Management
Licence management
VDI and cloning support
Frequently asked questions
You can create a new ESET PROTECT Cloud instance using ESET Business Account.
The ESET PROTECT Cloud console is web-based, while the on-premise console needs to be installed locally.
Endpoint products can be managed through the ESET Management Agent.
The agent can be deployed locally, remotely using various methods like RD Sensor, or using tools like GPO, SCCM, and the ESET Remote Deployment Tool.
It is used to enable instant replication of the ESET Management Agent on a client machine.