Kaspersky Endpoint Agent

Enabling and disabling Threat Response actions

November 17, 2023

ID 193082

To enable or disable the execution of Kaspersky Endpoint Agent response actions to threats detected by Kaspersky Sandbox:

  1. Expand the Managed devices node in the Kaspersky Security Center Administration Console tree.
  2. Select the administration group for which you want to configure application settings.
  3. Perform one of the following actions in the details pane of the selected administration group:
    • To configure application settings for a group of protected devices, select the Policies tab and open the Properties: <Policy name> window.
    • To configure the settings of a task or application for an individual protected device, select the Devices tab and go to the settings of a local task or the application settings.
  4. In the Kaspersky Sandbox integration section select the Threat Response subsection.
  5. In the Actions group of settings:
    • Select the Take response actions on threats detected by Kaspersky Sandbox check box to enable Threat Response actions.
    • Clear the Take response actions on threats detected by Kaspersky Sandbox check box to disable Threat Response actions.
  6. In the upper right corner of the settings group, change the switch from Policy not enforced to Under policy.
  7. Click Apply and OK.

See also

Adding Threat Response actions to the action list of the current policy

Configuring authentication on the Administration Server for Autonomous IOC Scan tasks

Device protection from legitimate applications that can be used by cybercriminals

Configuring start of Autonomous IOC Scan tasks

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.