Get Started with WatchGuard Endpoint Security

(missing or bad snippet)

Each WatchGuard Endpoint Security product includes software installed on endpoints and the Endpoint Security management UI to manage security for the devices and your IT network. To get started with Endpoint Security, complete these high-level steps.

  1. Step 1: Activate an Endpoint Security License
  2. Step 2: Allocate Endpoints (Service Providers Only)
  3. Step 3: Configure Pre-Deployment Settings
  4. Step 4: Deploy the WatchGuard Agent

This information is also described in the Get Started with Endpoint Security video tutorial in the Learning Center.

For information on how to get started with WatchGuard EDR Core (Total Security Suite), go to Quick Start — Set Up WatchGuard EDR Core.

Step 1: Activate an Endpoint Security License

  1. If you do not have a WatchGuard account, create one at https://accountmanager.cloud.watchguard.com/create-account.
  2. Activate your WatchGuard Endpoint Security product license in the WatchGuard website. For more information, go to Activate an Endpoint Security License.

Trial licenses are also available in WatchGuard Cloud. On the Administration > Trials page, you can start a trial of an endpoint product or module. Trial product licenses include up to 250 endpoint licenses for WatchGuard EDR, Endpoint Security Basic, Endpoint Security Prime, Endpoint Security 360, or Endpoint Security Elite. For more information, go to Start a Trial.

Step 2: Allocate Endpoints (Service Providers Only)

  1. Log in to your WatchGuard Cloud account.
  2. Allocate endpoint licenses to your managed accounts.
    For more information, go to Allocate Endpoint Licenses.

Step 3: Configure Pre-Deployment Settings

The Endpoint Security installation process consists of a series of steps that depend on the status of the network at the time of deployment and the number of computers and devices you want to protect. Before you deploy the WatchGuard Agent, we recommend that you complete these steps to plan the installation of Endpoint Security:

  1. Identify Unprotected Devices
  2. Verify Minimum Requirements for Target Devices
  3. Determine Computer Default Settings

Identify Unprotected Devices

(missing or bad snippet)

Verify Minimum Requirements for Target Devices

(missing or bad snippet)

Determine Computer Default Settings

(missing or bad snippet)

Configure the group organization and define settings before you deploy the WatchGuard Agent.

For more information about the different types of groups, and specific instructions, go to Manage Computers and Devices in Groups in Endpoint Security.

(missing or bad snippet)

Endpoint groups can be used to configure deployment behavior for products installed by the WatchGuard Agent in the WatchGuard Cloud user interface. For more information, go to Configure WatchGuard Agent Deployment.

To configure Endpoint Security settings for the endpoints where you want to install the WatchGuard Agent, you must next create settings profiles. For information on available settings, go to:

(missing or bad snippet)

Configure Recommended Settings

You can create as many settings profiles as necessary to manage network security for different types of computers and devices. General settings enable you to review user activity, configure computer and network settings, configure computer maintenance, and schedule email alerts.

In this section, we provide recommendations for these settings profiles:

After you create a settings profile, you assign it to one or more computers or computer groups. You can assign settings profiles manually (directly) or automatically through inheritance from a group to subgroups, computers, and devices. When you assign a settings profile to a group, Endpoint Security applies the security settings immediately to all of the computers and devices in the group. For more information, go to Assign a Settings Profile.

You might also want to switch to Service Provider settings where you can define settings as templates and assign them across multiple accounts. These settings can be standardized and easily applied across all your clients. For information on how to centrally manage settings for multiple accounts, go to Multi-Tenant Management of Settings Profiles.

Workstations and Servers Settings

Configure security settings profiles to define how Endpoint Security protects the workstations and servers on your network against threats, malware, and network attacks.

Alerts

In the General settings of a workstations and servers settings profile, you can configure local alerts to show on Windows, Mac, and Linux computers when Endpoint Security denies content. For example, it could be useful to add contact information for users to follow up. For more information, go to About Alerts and Configure Email Alerts.

Zero-Trust Application Service

In the Zero-Trust Application Service settings of a workstations and servers settings profile, you can configure Endpoint Security to detect and block malicious programs. There are three available operating modes: Learning, Hardening, and Lock.

Initially, you can configure the Zero-Trust Application Service in Hardening mode to start the learning and classification process. After two weeks, you can change the mode to Lock mode. In Lock mode, Endpoint Security does not allow software to start if it is in the process of classification or is already classified as malware. For more information, go to Configure the Zero-Trust Application Service.

Firewall, Device Control, and Web Access Control settings are disabled by default. Review these settings to determine if they are required in your environment.

Per-Computer Settings

(missing or bad snippet)

Automatic Updates

By default, automatic updates for Endpoint Security software is enabled. You can schedule these updates to occur when they will not interfere with other updates or backups. For more information, go to Configure Updates.

Avoid Endpoint Security updates at the same time as Windows updates. Windows updates will take precedence and could cause the Endpoint Security update to fail.

Anti-Tamper Password

Configure security against tampering to make sure that only authorized users can disable or uninstall Endpoint Security with a password. For information on how to set the anti-tamper password, go to Configure Security Against Tampering (Windows and Linux computers).

Shadow Copies

Shadow copies is a technology included in Windows computers that can create a snapshot of computer files, even when they are in use. This is useful to recover previous versions of files, and it can potentially protect Windows computers from ransomware attacks. For more information, go to Configure Shadow Copies.

When enabled in Endpoint Security, Windows creates a shadow copy every 24 hours. Endpoint Security retains up to 7 copies at a given time. You cannot delete a shadow copy created. To restore a backup, you must use the Windows Shadow Copies app on your computer. This feature requires extra disk space. You might want to disable the feature to save disk space.

Endpoint Access Enforcement Settings

Endpoint Access Enforcement monitors connections to computers on your network to reduce threats from unprotected devices (Windows, Mac, and Linux). In an Endpoint Access Enforcement settings profile, you configure settings to specify the conditions that identify a computer at risk and an action to take for inbound connections from computers at risk. By default, Endpoint Access Enforcement monitors inbound connections for SMB and RDP traffic. You can specify additional protocols to monitor for inbound connections.

For information on how to configure Endpoint Access Enforcement settings, go to Configure Endpoint Access Enforcement Settings (Windows Computers).

With Endpoint Security Elite, 360, and WatchGuard EDR, you monitor and block inbound connections from computers at risk. You can review this information on the Endpoint Access Enforcement Dashboard to take action on the at-risk devices.

Step 4: Deploy the WatchGuard Agent

For accounts with more than one WatchGuard product license (for example, an Endpoint Security product license and a FireCloud license), the Configure > Agent Deployment page in WatchGuard Cloud is useful to centrally configure product deployment behavior for endpoint groups and endpoints. For more information, go to Configure WatchGuard Agent Deployment.

(missing or bad snippet)

Related Topics

Endpoint Security Installation Requirements (external link)

Endpoint Security Installation Plan

Microsoft Intune Integration with the WatchGuard Agent

Unmanaged Computers Discovered List

Troubleshoot WatchGuard Endpoint Security

Endpoint Security 360 — Security Dashboard

About Tasks