Oct 25 2019
05:32 AM
- last edited on
Nov 30 2021
10:04 AM
by
TechCommunityAP
Oct 25 2019
05:32 AM
- last edited on
Nov 30 2021
10:04 AM
by
TechCommunityAP
Hi Azure ATP Tech Community,
I have a few questions in relation to the update process for the sensor and am hoping you can help?
1) Do all updates (minor and major revisions) require a reboot of the DC?
2) If the answer to the above is no - what determines if a reboot is required? (IE only major revisions require reboots, or does it vary depending on what the update contains?)
3) If you check the box not to allow automatic DC reboots as part of the update process, is a health alert generated in the portal, post update to advise sec ops analysts that a reboot is pending on a particular DC?
4) If a post update reboot is pending on a DC, what state does that leave the sensor in on that DC?
For example, does it work at all? does it work with the same functionality as it had pre-update but post update enhancements don't work until post reboot, or does it simply not report to the ATP service at all (therefore making sure reboots take place are highly critical to the function of the service overall)?
Thanks
Paul
Oct 27 2019 02:29 AM
Solution
1) No
2) For now (unless changed at some point) only major. a reboot might be required if the .net framework is not in required min version, or if a cumulative update that is needed is not installed.
3) no health alert, but it will appear as pending update in the sensor list config page
4) it depends. in general we try to keep it so it will be functional without the new features (for a few days). It's best to upgrade ASAP.
Oct 28 2019 12:34 AM
Thanks @EliOfek - just the info I needed
Oct 28 2019 12:53 AM
Oct 27 2019 02:29 AM
Solution
1) No
2) For now (unless changed at some point) only major. a reboot might be required if the .net framework is not in required min version, or if a cumulative update that is needed is not installed.
3) no health alert, but it will appear as pending update in the sensor list config page
4) it depends. in general we try to keep it so it will be functional without the new features (for a few days). It's best to upgrade ASAP.