Online criminals hate us. We protect you from attacks that antivirus can't block.

Dashboard Features: Group Policy Overview

This article sets the guidelines for navigating the Group Policy interface.

The article will be structured in 5 segments, which illustrate and explain each feature:

  1. Group & Misc Settings
  2. Traffic Scanning
  3. Patching System
  4. Malware Engine

 

Group & MISC SETTINGS

This feature allows the user to add this GP to a specific AD Group.

The AD Local Security Group is the AD Group where all the machines are. This way, whenever that machine comes online only the policy will be applied.

The AD User Group is the AD Group where the all the users are. This way, whenever that user logs onto a computer, the policy begins to be applied.

This feature is designed to offer the possibility to deploy Heimdal Security without GUI (Graphical User Interface) or to deploy the Beta version/RC of Heimdal Security.

Note: We recommend everyone running Heimdal on Terminal Servers or Citrix servers to make sure that "Do not show GUI" is checked before the entire policy (Heimdal Security installation included) is set to be deployed.

This feature also checks if the policy is applied correctly on the machines. This option is designed to push the policy on all the computers an interval set previously. This way, the policy will also be applied on the machines that were offline when a change was made in the dashboard.

In order for all the changes made to take effect, remember to click on the Update button in the Bottom left side.

Traffic Scanning

This section of the Group Policy is designed to administrate the Traffic Filtering engine embedded in Heimdal Security.

By enabling the Traffic Filtering, Heimdal Security will add the DNS 127.0.0.1 on the network adapter’s IPv4. This is basically the network filter that will protect the computer from getting infected.

Check Interval - by using this feature, you can adjust the time for Heimdal Security to initiate a network scan.

Automatically Disable - If Heimdal can’t connect to the cloud servers from your location, Traffic Filtering won’t work properly. This may disconnect your PC from the Internet. To avoid this, you can choose to automatically disable Traffic Filtering. Heimdal will re-enable the feature when it can reconnect to the cloud servers.

Enable domains whitelist – This feature allows the user to whitelist a domain that Heimdal Security blocks the access to it due to being suspicious. The domain can be added in the field that appears once the feature is ticked and press adds to whitelist it.

You also have the possibility to upload a CVS file with multiple domains (divided by "," comma).

Example:

facebook.com, youtube.com, amazon.com . That way these domains will be accessible by all machines that are part of the Group Policy. 

The domain can be removed from the whitelist by clicking on the red X next to it.  It will automatically become blacklisted again once this is done.

Enable domains blacklist - This feature allows the user to blacklist a domain that Heimdal Security does not consider a threat. Perhaps you want to prohibit access to a specific domain in your environment. You can use this option to block it. You can add the domain in the field that appears once your tick the feature. Just click on “add” to blacklist it.

 

You also have the possibility to upload a CVS file with multiple domains (divided by "," comma).

Example:

facebook.com, youtube.com, amazon.com . That way these domains will be not accessible by all machines that are part of the Group Policy. 

You can remove the domain from the blacklist by clicking on the red X next to it.  It will automatically become whitelisted again once this is done.

 

Enable proxy settings – This feature is designed to install Heimdal Security if the user uses a specific proxy server by adding the needed information in the fields displayed. For more information how to set it up please click HERE.

Patching System

By enabling the Patching system, it will allow the user to install or update on all the computers that are added to the Group Policy a specific software from the list.

In order for all the changes made to take effect, you have to click the Update button in the Bottom left side.

The patching system offers the following actions:

  • The user can select to install and update a specific software on the computers from the GPO
  • The user can select to install a specific version of the software if it's required by the system.
  • The user can select to only update a specific software on the computers from the GPO. This implies that the software selected is already installed on the machines.
  • The user can select to only install a specific software on the computers from the GPO. This will only install the latest version of the selected software but will not update it if a new version of it will be released.

Another feature that the patching system offers is the Uninstall Applications.

This feature allows the user to:

  1. Uninstall a specific application by writing its name in the field and pressing Add or Enter.

For example, maybe you need to remove Classic Shell from all the machines.

In this case, you need to add the full name of the application in the field and press Add or Enter.

Important notes:

  • If the “Starts with” option is selected before pressing Add, Heimdal will uninstall everything from the computer that begins with the word “Classic”. That is why you should know exactly what software needs removing. An example will be Classic Shell x32. That way, you can ensure that Heimdal will only remove the software Classic Shell 32 bits.
  • If you need to remove a software app from the Patching system from all the computers, then you need to make sure that the option to ”Install” or “Update” are not selected in order for it to work.

For example: If you have to remove Adobe Reader from all the machines and by adding the name Adobe Reader in the Uninstall Application  field and pressing Add/Enter gives the following error:

Then that happens because, in the patching system, Adobe Reader is still selected to perform one of the following actions: Install or Update. Removing these actions will allow the software to be uninstalled.

        2. This feature allows uninstalling software that is not on the Patching System list. It can be any other software from the computer. As mentioned previously, you have to write the full name of the software (as it appears in Control panel) before pressing Add.

 For more information about this feature please click HERE.

In order for all the changes made to take effect, remember to click on the Update button in the bottom left side.

 

 

 

Malware Scanning

This feature is designed to periodically scan the system for malware. For more information regarding this feature and what it does, please download and read the latest whitepaper that can be found HERE

In order for all the changes made to take effect, remember to click on the Update button in the Bottom left side.

 

 

 

Was this article helpful?
1 out of 1 found this helpful
Have more questions? Submit a request

0 Comments

Article is closed for comments.