Manage updates for the Aurora Protect Desktop and Aurora Focus agents
You can use update rules to manage updates of the Aurora Protect Desktop and Aurora Focus agents on devices. Update rules allow you to configure Aurora Endpoint Security to automatically push updates to a specific version or the latest available version, or you can turn off automatic updates so that you can manage the software distribution using your organization’s preferred method.
Zones are associated with update rules, so that devices and users that are part of those zones receive updates accordingly (also known as zone-based updating). By default, the Test, Pilot, and Production update rules are available but you can also add additional update rules to manage agent updates based on your organization's needs.
The agent version on the device is updated to the version that is specified in the update rule only if it is compatible with the device and is part of the supported upgrade path. For devices running an agent version earlier than 3.4.1000, you can use update rules to install an earlier version of an agent, even if the device is already using a newer version. After a successful upgrade to version 3.4.1000 or later, you cannot use update rules to install an earlier version of the agent.
If the Linux driver on a device was previously updated manually on a device, the driver is not automatically updated as part of the agent update. This is to prevent the automated system from overwriting an action taken by an administrator.
- Review the Upgrade paths for the Aurora Protect Desktop 3.x agent and the OS compatibility matrix for the Aurora Protect Desktop agent.
- Create zones that you want to assign to an update rule. For example, you can create zones with devices reserved for testing agent updates. You should associate these zones with the Test and Pilot update rules to test them. You can also create your own update rules for testing or for production deployment. For more information about creating zones, see Add and configure a zone.
- If you added update rules, click the arrows next to the rules to set the ranking. Rules at the top of the list take priority over rules lower on the list. The Test, Pilot, and Production rules are always at the bottom of the list and you cannot change their ranking. The Production update rule is applied to devices that aren't in any zone with an update rule, and devices in zones where none of the rules have a specified an update to the agent.
- To trigger an update of the Aurora Protect Desktop agent on a device before the hourly interval, on the device, right-click the Aurora Protect Desktop icon in the system tray and click Check for Updates, restart the Cylance service, or run this command from the Cylance directory:
CODE
CylanceUI.exe –update - If memory protection, script control, or device control are enabled in the device policy, a reboot of the device after the agent installation or upgrade is recommended, but not strictly required. A reboot makes sure that any new policy settings take full effect.
- If the assigned version of the agent cannot be installed on the device because it does not meet the system requirements or if the update does not use the supported upgrade path, then an indicator (
) appears in the Target Protect Version field when you view device details. To display the field in the legacy device grid, click
on the right side, and then select it. Verify the target agent version with the OS version and the upgrade path.