Kaspersky Anti Targeted Attack Platform

Functional limitations after the license expiration

When the license expires, the following limitations arise in the operation of Kaspersky Endpoint Agent functional components:

  • Execution of the jobs received from the Central Node component and the sending the results to the Central Node component is stopped.

    The application sends a message to the Central Node component that the activation status of Kaspersky Endpoint Agent is changed.

    Connection with the Central Node component is not broken. Kaspersky Endpoint Agent continues to accept jobs for creating tasks and changing settings from the Central Node component, but it does not start these tasks and does not enable network isolation and Execution prevention.

  • Telemetry is not sent.
  • Network isolation cannot be enabled.

    If network isolation was enabled when the license expired, the application disables network isolation in accordance with the specified settings for automatic disabling of network isolation.

  • Execution prevention cannot be enabled.

    If Execution prevention was enabled when the license expired, the application stops blocking objects that fall under the specified Execution prevention rules.

  • The following tasks stop and cannot be started: Get file, Run process, Terminate process, Delete file.
  • The Standard IOC Scan tasks stop and cannot be started.
  • KSN/KPSN usage terminates.

When you try to use the listed application functional components after the license expires, the application creates the critical LicenseViolation event in the Windows event log and in Kaspersky Security Center Administration Server log. When working through the command line, the application returns code 8 (AccessDenied).

See also

Managing Kaspersky Endpoint Agent activation

Viewing information about the current license