Kaspersky Endpoint Security for Windows

Kaspersky Endpoint Security for Windows (hereinafter also referred to as “the application” or as “Kaspersky Endpoint Security”) gives corporate users all-in-one protection against known digital threats.

WHAT'S NEW IN KASPERSKY ENDPOINT SECURITY

Kaspersky Endpoint Security 11.6.0 for Windows offers the following features and improvements:

  1. Support for Windows 10 21H1. For details about support for the Microsoft Windows 10 operating system, please refer to the Technical Support Knowledge Base.
  2. The Managed Detection and Response component was added. This component facilitates interaction with the solution known as Kaspersky Managed Detection and Response. Kaspersky Managed Detection and Response (MDR) provides round-the-clock protection from a growing number of threats capable of bypassing automated protection mechanisms for organizations that are having a difficult time finding highly qualified experts or who have limited internal resources. For detailed information about how the solution works, please refer to the Kaspersky Managed Detection and Response Help Guide.
  3. Kaspersky Endpoint Agent, which is included in the distribution kit, has been updated to version 3.10. Kaspersky Endpoint Agent 3.10 provides new features, resolves some previous issues, and has improved stability. For more details about the application, please refer to the documentation of Kaspersky solutions that support Kaspersky Endpoint Agent.
  4. It now provides the capability to manage protection against attacks such as Network Flooding and Port Scanning in Network Threat Protection settings.
  5. Added new method of creating network rules for Firewall. You can add packet rules and application rules for connections that are displayed in the Network Monitor window. However, network rule connection settings will be configured automatically.
  6. Network Monitor interface is now improved. Added the information about network activity: process ID, that initiate network activity; network type (local network or the Internet); local ports. By default, the information about network type is hidden.
  7. There is now the capability to automatically create Authentication Agent accounts for new Windows users. The Agent allows a user to complete authentication for access to drives that were encrypted using Kaspersky Disk Encryption technology, and to load the operating system. The application checks information about Windows user accounts on the computer. If Kaspersky Endpoint Security detects a Windows user account that has no Authentication Agent account, the application will create a new account for accessing encrypted drives. Therefore, you do not need to manually add Authentication Agent accounts for computers with already encrypted drives.
  8. There is now the capability to monitor the disk encryption process in the application interface on users' computers (Kaspersky Disk Encryption and BitLocker). You can run the Encryption Monitor tool from the main application window.
  9. An issue in the operation of the Kaspersky Disk Encryption (FDE) technology has been fixed. For details about an issue, please refer to the Technical Support Knowledge Base.

MINIMUM HARDWARE AND SOFTWARE REQUIREMENTS

To ensure proper operation of Kaspersky Endpoint Security, your computer must meet the following requirements:

Minimum general requirements:

Supported operating systems for workstations:

The SHA-1 module signature algorithm is deprecated by Microsoft. Update KB4474419 is required for successful installation of Kaspersky Endpoint Security on a computer running the Microsoft Windows 7 operating system. For more details about this update, visit the Microsoft technical support website.

For details about support for the Microsoft Windows 10 operating system, please refer to the Technical Support Knowledge Base.

Supported operating systems for servers:

The SHA-1 module signature algorithm is deprecated by Microsoft. Update KB4474419 is required for successful installation of Kaspersky Endpoint Security on a computer running the Microsoft Windows Server 2008 R2 operating system. For more details about this update, visit the Microsoft technical support website.

For details about support for the Microsoft Windows Server 2016 and Microsoft Windows Server 2019 operating systems, please refer to the Technical Support Knowledge Base.

Supported virtual platforms:

Server platform support limitations:

The limitations on support for virtual platforms are presented in the user documentation.

APPLICATION COMPATIBILITY WITH THE KASPERSKY SECURITY CENTER REMOTE ADMINISTRATION SYSTEM

Kaspersky Endpoint Security supports operation with the following versions of Kaspersky Security Center:

The administration web plug-in for Kaspersky Endpoint Security for Windows version 11.6.0 is compatible with Kaspersky Security Center Web Console version 12.

To manage the application remotely via Kaspersky Security Center:

  1. Install Network Agent on the computer.

    For more details about installing the Network Agent, please refer to the Kaspersky Security Center 12 Help.

  2. Install the Management Plug-in for Kaspersky Endpoint Security for Windows in the Kaspersky Security Center Administration Console.

    The installation package for the Kaspersky Endpoint Security Management Plug-in is included in the distribution package.

    The web plug-in installation package is available for download on the website and in the plug-in management window of Kaspersky Security Center Web Console. To install the web plug-in version 11.6.0, you should first remove the previous version of the web plug-in.

The Kaspersky Endpoint Security for Windows Management Plug-in for version 11.6.0 is installed over the Kaspersky Endpoint Security for Windows Management Plug-in for versions 11.X.X. To continue using the previous version of Management Plug-in, you should first remove the Management Plug-in version 11.6.0.

Limitations on compatibility with Kaspersky Security Center:

INSTALLATION

To install the application locally, run the setup_kes.exe file from the full distribution package and follow the Setup Wizard instructions. You can read more about how to install the application in the user documentation.

During installation, Kaspersky Endpoint Security for Windows detects applications on the computer that, when used together, could potentially reduce computer performance or lead to other compatibility problems (even resulting in complete inoperability). The full list of incompatible software is available in the user documentation.

You can upgrade the following applications to Kaspersky Endpoint Security for Windows version 11.6.0 when installing from the full distribution package:

The following considerations should be taken into account when upgrading Kaspersky Endpoint Security for Windows version 10 Service Pack 2 or later:

UPDATING VIA THE KASPERSKY UPDATE SERVICE

Kaspersky Endpoint Security 11.6.0 for Windows can be installed via the Kaspersky update service.

Through the Kaspersky update service, you can update the following applications:

If Kaspersky Endpoint Security version 11.3.0 or later is deployed in the infrastructure along with older versions of the application, Kaspersky Security Center will be able to install two updates of Kaspersky Endpoint Security to version 11.6.0: one for updating Kaspersky Endpoint Security versions 11.0.1–11.2.0 CF1, and the second for updating version 11.3.0 or later.

Upgrading Kaspersky Endpoint Security for Windows from beta versions to version 11.6.0 is not supported.

The following special considerations should be taken into account when updating through the Kaspersky update service:

APPLICATION COMPATIBILITY WITH AES ENCRYPTION MODULES AND DETAILS ON UPDATING DATA ENCRYPTION COMPONENTS

Starting with Kaspersky Endpoint Security 10 Service Pack 2, the AES Encryption Module is included in the application distribution package. Therefore, installation of a separate encryption module is not required.

All libraries required for data encryption will be automatically installed in the following cases:

  1. During installation of the application, provided that the Full Disk Encryption (FDE) or File Level Encryption (FLE) components are selected.
  2. When upgrading Kaspersky Endpoint Security for Windows version 10 Service Pack 2 or later, provided that the upgrade is performed using an application distribution package with the appropriate key length and that the Full Disk Encryption (FDE) or File Level Encryption (FLE) components are selected.
  3. When upgrading Kaspersky Endpoint Security for Windows version 10 Service Pack 1 Maintenance Release 3 with AES Encryption Module version 1.1.0.73 installed, provided that the upgrade is performed using the application distribution package with the appropriate key length.
  4. When upgrading Kaspersky Endpoint Security for Windows version 10 Service Pack 1 Maintenance Release 4 with AES Encryption Module version 1.1.0.73 installed, provided that the upgrade is performed using the application distribution package with the appropriate key length.

Other configurations of Kaspersky Endpoint Security and AES encryption modules are not supported.

Before updating Kaspersky Endpoint Security, you must remove the AES Encryption Module or update the module to version 1.1.0.73. Before removing or updating the AES Encryption Module, you must decrypt all hard drives that have been encrypted using Kaspersky Disk Encryption technology. After removing the AES Encryption Module, access to encrypted files will be blocked.

If you want to switch from your encryption method to encryption with a different key length, prior to updating the application to version 11.6.0 you must decrypt all encrypted objects and remove the AES Encryption Module that was used. After switching to encryption with a different key length, access to encrypted files will be blocked.

COMPATIBILITY WITH KASPERSKY ENDPOINT AGENT

Kaspersky Endpoint Security is compatible with the following versions of Kaspersky Endpoint Agent: 3.7, 3.8 and 3.9.

The Kaspersky Endpoint Agent 3.9 distribution package is included in the Kaspersky Endpoint Security for Windows version 11.6.0 distribution kit. Kaspersky Endpoint Agent will be automatically installed if the Endpoint Agent component is selected during Kaspersky Endpoint Security installation.

If you selected the Endpoint Sensor component when installing Kaspersky Endpoint Security and Kaspersky Endpoint Agent version 3.7 or 3.8 is installed on the computer, the application will be automatically updated to version 3.9.

LIST OF BUGS FIXED AND PRIVATE PATCHES INCLUDED IN THE RELEASE

The list of fixed issues and private patches included in the release is available on the Technical Support website.

MAIN KNOWN ISSUES

The list of limitations and known issues is available in the user documentation.

© 2021 AO Kaspersky Lab

Page top