Forum Discussion

wpj's avatar
wpj
Icon for Making Connections rankMaking Connections
2 months ago

Cato Device Posture Profile problems.. What are others using?

We've been working for several weeks to setup our Device Posture Profiles (DPPs) to be used as a way to block/allow access to certain resources.  Our goal was to have the Cato client check to see if the following processes were running:

  • Microsoft Intune MDM (for Windows and Macs)
  • Microsoft Defender ATP (for Windows and Macs)

We've found all sorts of inconsistencies and problems when applying these DPPs.  Many times the Cato client won't realize the process are running (even thought they are).  It will detect one of the processes but not the other sometimes.  Sometimes it will work after users reboot and connect to Cato other times it won't.   We are confused how often the Cato client checks for the postures . We have the "Enable Advance Posture Checks" option set to 5min, but see different behavior when machines come out of Sleep mode, etc.  

So now we are thinking it's asking too much of the Cato client to verify Defender and Intune are actually running , So we may have to settle for verifying if they are simply "installed" on the machine (via registry entry possibly)?   

We would like to hear how other companies are using the Device Posture Profiles/Checks to add security to their user's access.  I'm guessing most companies are just putting a Cert on the machines and looking for that to allow access to Cato?  

Any suggestions would be appreciated. 

 

2 Replies

  • wpj's avatar
    wpj
    Icon for Making Connections rankMaking Connections

    We have opened some tickets on this issue. The most recent one has the most information/details (#864725).   Thank you.

  • michaelsaw's avatar
    michaelsaw
    Icon for Cato Professional Services rankCato Professional Services

    Hi wpj,

    Appreciate your efforts and details on this.
    You mentioned: 'It will detect one of the processes but not the other sometimes."
    Can we check if there is a support ticket submitted on this issue, currently?

    Thank you