<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy and Group change in AMP for Endpoints in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3338858#M4635</link>
    <description>&lt;P&gt;David,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this mean that changing a computer from one policy to another occurs when a heartbeat happens? If so, is there any way to force a computer to change to the new policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Garrett&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2018 15:50:19 GMT</pubDate>
    <dc:creator>Garrett_N</dc:creator>
    <dc:date>2018-02-27T15:50:19Z</dc:date>
    <item>
      <title>Policy and Group change in AMP for Endpoints</title>
      <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3309225#M4632</link>
      <description>&lt;P&gt;I deployed AMP for endpoint to a test machine following Cisco's &lt;A title="AMP for Endpoints Deployment Strategy" href="https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20Deployment%20Strategy.pdf" target="_self"&gt;Deployment Strategy guide for AMP for endpoint&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This guide recomends creating an Audit Only, Protect, Triage, Server and Domain Controller policy and the same for groups. It also recomends all the workstations to initially belong to the "Audit Only" group (with the Audit Only policy) and then move them to the Protect group (with Protect policy) after making sure you root out any false positive.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this point, I downloaded the connector from the "Audit Only Group" with the "Audit Only" policy and installed it in my VM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="connector down.png" style="width: 481px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6101i387AA1FE97445BFF/image-size/large?v=v2&amp;amp;px=999" role="button" title="connector down.png" alt="connector down.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CiscoAMP Connector.png" style="width: 297px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6102i00A616B05A39FB29/image-size/large?v=v2&amp;amp;px=999" role="button" title="CiscoAMP Connector.png" alt="CiscoAMP Connector.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, I went ahead and moved the computer from the "Audit Only Group" to the "Protect Group" but the Protect Policy is not reflected in the console nor in the connector. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PGroup.png" style="width: 939px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6103i5C61B85341E1ACA1/image-size/large?v=v2&amp;amp;px=999" role="button" title="PGroup.png" alt="PGroup.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;- How do I properly move this Computer from the "Audit Only" to the "Protect" policy?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Doing a "Sync Policy" at the connector only updates any changes done to the "Audit Only" policy. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Rebooting the machine and/or restarting the services don't update the policy.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:46:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3309225#M4632</guid>
      <dc:creator>Andres Villarroel</dc:creator>
      <dc:date>2019-03-09T01:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Policy and Group change in AMP for Endpoints</title>
      <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3309989#M4633</link>
      <description>&lt;P&gt;It looks like ~24h after the changes. The client and the console updated automatically.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ProConsole.png" style="width: 941px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6167i542731DD9754C0E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="ProConsole.png" alt="ProConsole.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ProPolicy.png" style="width: 295px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6168i03B0AB79C7CC369C/image-size/large?v=v2&amp;amp;px=999" role="button" title="ProPolicy.png" alt="ProPolicy.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Checking at the console events, the agent fecthed the policies on 01/10 and 01/11 but only the one from today (01/11) made the change.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Events.png" style="width: 647px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/6171i84EB488078415B92/image-size/large?v=v2&amp;amp;px=999" role="button" title="Events.png" alt="Events.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2018 19:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3309989#M4633</guid>
      <dc:creator>Andres Villarroel</dc:creator>
      <dc:date>2018-01-11T19:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Policy and Group change in AMP for Endpoints</title>
      <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3314383#M4634</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;every agent checks periodically based on a heartbeat interval against cloud.&lt;/P&gt;
&lt;P&gt;This time is specified per policy, as you see it in the screenshot.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 10:53:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3314383#M4634</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2018-01-19T10:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Policy and Group change in AMP for Endpoints</title>
      <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3338858#M4635</link>
      <description>&lt;P&gt;David,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this mean that changing a computer from one policy to another occurs when a heartbeat happens? If so, is there any way to force a computer to change to the new policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Garrett&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2018 15:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3338858#M4635</guid>
      <dc:creator>Garrett_N</dc:creator>
      <dc:date>2018-02-27T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Policy and Group change in AMP for Endpoints</title>
      <link>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3340203#M4636</link>
      <description>&lt;P&gt;Hello&amp;nbsp;Garrett&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you make any kind of changes in the policy including changing the connectors from one group to another , it will take effect only after the heartbeat interval . You can set the heartbeat interval starting from 15 minutes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 07:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/policy-and-group-change-in-amp-for-endpoints/m-p/3340203#M4636</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-03-01T07:14:46Z</dc:date>
    </item>
  </channel>
</rss>

