Solved

How do I disable Webroot on a single endpoint for testing?

  • 26 October 2020
  • 14 replies
  • 329 views

Userlevel 1

Hello!  New Webroot SecureAnywhere user here.  I recently started at a company that uses this software however I have no experience with it.  Dumb question, but we are troubleshooting some software issues on a PC that has Webroot SecureAnywhere installed on it.  I have access to the Admin console but am unable to disable the software locally.

 

How do I disable this software on a single PC for testing purposes?

icon

Best answer by coscooper 27 October 2020, 00:35

@msmith-442  - you’ll need to create an editable policy. It sounds like you have opened the “Recommended Default” policy, which is NOT editable and shouldn’t be used in production. Rather, we advise to copy this policy, give it a logical name, like “Workstations Default” and then you can edit these policy settings to fit your need.

You may also find this Best Practice Guide helpful.

 

General Guides: https://docs.webroot.com/us/en/business

Admin Console Guide: https://download.webroot.com/ManagementConsole_BestPracticesGuide.pdf

 

Make a custom policy, change the “Shutdown protection” setting and it’ll show up in the System Tray icon. When you right click, you’ll see a menu. The “Shutdown Protection” will show up there.

Hope that helps

View original

14 replies

Userlevel 7
Badge +58

Hello and Welcome to Webroot @msmith-442 

Sorry I do not know that much about Webroot Business Endpoints.

Hopefully this helps?

It is possible to shut down or temporarily disable the Webroot Business Endpoint Protection agent.
 

To do this:

  1. Log into the Webroot console, open the policy applied to the endpoint(s).
  2. Under the Basic Configuration settings:
    • Change the Allow SecureAnywhere to be shut down manually setting to On
  3. Save changes to the policy and apply it to the endpoint(s)**.
  4. Once the updated policy has been applied to the endpoint, right click the system tray icon (W in green circle) and select 'Shut down Protection' to disable the agent.

**NOTE: Policy changes will be applied during the polling interval set for the policy. You can force the endpoints to check in by:

  • Right clicking the system tray icon and selecting ‘Refresh Configuration’
  • Forcing the endpoint to poll by locally or remotely executing a wrsa –poll command:
    • For 32bit Operating Systems: "C:\Program Files\Webroot\WRSA.exe" -poll
    • For 64bit Operating Systems: "C:\Program Files (x86)\Webroot\WRSA.exe" –poll 

For more information on editing policies, please see the user guide. https://download.webroot.com/WSAB_EndpointProtection_AdminGuide.pdf
 

Also please check here for information: https://community.webroot.com/troubleshooting-and-uninstalling-143/how-to-shut-down-or-temporarily-disable-the-webroot-business-endpoint-protection-agent-337541

You can also Submit a Support Ticket and the Support Team will assist you free of charge:

https://www.webroot.com/us/en/business/support

 

Note: When submitting a Support Ticket, Please wait for a response from Support. Putting in another Support Ticket on this problem before Support responses will put your first Support Ticket at the end of the queue. A reply from Support should take from 24 to 48 hours but could take a little longer because of COVID 19 and the Webroot Employees are busy working from home.

 

 

 

Userlevel 1

Hi!  Thanks for replying.  I am a new user, my SysAdmin has recently bumped me up to "GSM Super Admin" permissions.  However I still cannot seem to do what you are describing.


I am able to log into the admin control panel, switch over to the Policies tab, find my default policy (applied to all workstations), but I am unable to change any of the settings on it.  There is no option for me to change any of the settings on that policy:
 


I would think there has to be an easier way though?  I don't want to change the policy for my entire company, just temporarily disable protection on a single workstation to troubleshoot a software conflict…?

Userlevel 7
Badge +58

Hi @msmith-442 

I do apologize and I do understand what you are trying to accomplish but I am not a Webroot Business advisor. Perhaps this link can assist with this issue.

https://docs.webroot.com/us/en/business/wsab_endpointprotection_adminguide/Content/ManagingEndpoints/DeactivatingEndpoints.htm

As I have mentioned please Submit a Support Ticket or/and let me ping someone that knows more then I.  @freydrew can you advise someone in the Business Support to assist here?

Userlevel 1

Hi!  Thanks for the additional link.  I’m able to get to that screen but I do not have the checkboxes shown in step #2.  So I can’t select different endpoints.

 

Additionally the only options I have in the toolbar at the top are “Save changes” and “Undo changes”.  The option for “Move endpoints to another group” is visible but grayed out.  I don’t have any of those other options like “Agent commands” or “Deactivate” shown in step #3.

 

Is this software syncing to my AD, perhaps?  Do I need to make some kind of change in AD?


I submitted a ticket on Friday, hopefully someone in business support will be able to respond to me soon.  Thanks!

Userlevel 6
Badge +26

@msmith-442  - you’ll need to create an editable policy. It sounds like you have opened the “Recommended Default” policy, which is NOT editable and shouldn’t be used in production. Rather, we advise to copy this policy, give it a logical name, like “Workstations Default” and then you can edit these policy settings to fit your need.

You may also find this Best Practice Guide helpful.

 

General Guides: https://docs.webroot.com/us/en/business

Admin Console Guide: https://download.webroot.com/ManagementConsole_BestPracticesGuide.pdf

 

Make a custom policy, change the “Shutdown protection” setting and it’ll show up in the System Tray icon. When you right click, you’ll see a menu. The “Shutdown Protection” will show up there.

Hope that helps

Userlevel 1

@coscooper  Hi!  Thanks for the response.  I looked and we are using the group “Default Group”, not the one labeled “Recommended Defaults”, so I assume what you are suggesting is not the case?  See screenshot:


 



When I double-click on this policy this is what I see:

 



I can’t figure out how to change any of those values.


In any case, is this the only way we can do this?  Seems like a lot of work.  As I said above, I’m a new tech working at a company that has used this product for a while.  I don’t want to make any sweeping changes to our policy, just trying to figure out how to temporarily disable the program on a single workstation to trouble shoot a compatibility issue.

 

When I try to disable the app on the workstation I get this message:

 

 

 

Any other suggestions?  Thanks!
 

Userlevel 6
Badge +26

@msmith-442 - It does look like that redacted site policy may be a custom policy assigned to all of the endpoints, which you should be able to duplicate and modify for single use or what you’re trying to accomplish. However, these screen shots indicate you do not have admin privileges to make a policy or modify a policy at the site level. If you had admin privileges, you’d see the following buttons along the top. See Create/Delte/Rename etc… these are admin options.

 

If you could modify policies at the site level, you’d see the extra column to the right where you could make the respective change.

 

Check with the main console administrator to change your permissions. I noticed at one point you’d mentioned this was a multi-site console, so if you’re log in is established as a GMS admin, check there to see if you have rights at the global level. If not, the administrator can reset them and/or setup your permissions site by site.

Once you have admin privileges to make these changes, you can make as many custom policies as you’d like for specific use or to assign to various endpoints.

If you guys need a full walk through of best practices and help with managing your console, you can private message me here or email me at shanec@opentext.com and I’ll have someone on my team reach out to get that scheduled.

Userlevel 1

Hi @coscooper !  Thanks for replying.  I saw in your reply above where you said "However, these screen shots indicate you do not have admin privileges to make a policy or modify a policy at the site level."

 

I asked my SysAdmin to make me an admin and he made me something called a "GSM Super Admin".  I looked on the “Admin tab” and this is the same permission level he has.  I don't know what that means, but shouldn't "GSM Super Admin" be able to edit everything?

 

Is there something else he needs to change in order to make me be an admin able to edit this specific policy?

Userlevel 7
Badge +29

@msmith-442 

 

You should be set to what’s called a Limited Admin and given permissions only to the site  you require access.

 

If you are only temporarily troubleshooting, you can just set the policy of a single endpoint to “unmanaged” from the group management tab of the console. That way you can then adjust any settings locally on the computer itself including shutting it down. That option then is found under the local GUI by clicking the Advanced settings button. 

 

Just be sure when you are finished to go back to that group management tab and set the endpoint policy back to the default one you previously used.

 

John

Userlevel 1

Hi @jhartnerd123 !  Thanks for responding.  I understand what you are saying that I should be “Limited Admin”, but even as a “GSM Super Admin” I am unable to change a policy, make a policy, or move a computer from one policy to another.

Wow, and I thought this would be an easy question, LOL. 🤣😭

Userlevel 7
Badge +29

You can’t be a super admin or even a limited admin if you are unable to make any sort of adjustment to a policy. You must be set as a view only account. 

Userlevel 1

You can’t be a super admin or even a limited admin if you are unable to make any sort of adjustment to a policy. You must be set as a view only account. 



@jhartnerd123  - This is me:

 

 

Userlevel 1

Omg.  I found the settings.  Needed to change it here.  Worst UI ever.  There goes about two days of my life.  🤣🤣😆😭 
 


Maybe now I can make some progress...
 

Userlevel 6
Badge +26

@msmith-442  - looks like you figured it out. I’ve been heads down all day on another project and didn’t get a chance to jump in earlier. @jhartnerd123  offered good suggestions for using Unmanaged policy over turning on “Shutdown protection”, beyond the ability to modify/admin policies, sites, settings.

The different settings, Admin type (Super vs Limited) are for specific use cases. Then, the site admin view/admin per user, per site is for the same. There are many customers that have different admins for different needs, like helpdesk, NOC techs, administrators, site only admins, specific customer admins, so the UI and settings are for a variety of needs. Super vs Limited show/allow high level sections and if not visible, then that user/tech can’t modify things, like policy and/or overrides at a global level. THEN, that per-mutates down to sites with a hole other set of permissions as we support site only admins for when/if you have a user that JUST needs to manage/see just one site.

As an aside, the entire console is being redesigned to offer streamlined UI for these kinds of settings & needs. Admin privileges has grown over the years to what we have today. There’s a lot more work that needs to be done to make it useful, but to be totally frank, admin privileges are complex due to the variety of needs and the destructive ability if every abused, misused or through ignorance, so it’s not super easy on purpose. 8-)

 

Lastly, as I’ve offered earlier, if you need a training walk through or best practice session, we offer it for your edification and to speed up the process so you’re not posting back and forth in the community and/or spending all this time hunting for a setting. Had we had a 10 minutes BP session online virtually with an expert, we’d have had this fixed in less than 5 minutes. 8-)

 

Now that you have correct admin privileges, there are a lot of other policy settings and suggestions we can offer to streamline your setup. Private message me if you’re interested in setting up some time to review and insure you’re setting things up correctly. Myself or someone on my team will reach out and get that scheduled.

Reply