This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Real time protection disabled on Mac OS endpoint

2 of our Mac OS endpoints are showing the same high severity alert. Both of these were installed by the end-user using an installer and instructions that we provided for them. I'm wondering if they failed to give Sophos the correct security permissions at the end of the install process. Unfortunately is has been hard to get a hold of them. I sent them this link https://support.sophos.com/support/s/article/KB-000039014?language=en_US but never heard back. I have 2 main questions:

1. These alerts are marked as having occurred 8 days or more in the past and everything but the "legacy" services are showing as running.. Does that mean that they are ongoing or that they have been resolved and I should simply acknowledge them? The alert shows up in the device's Status page ( screenshot below ) and the customer's "Alerts" section in Sophos Central Admin. 

2. If this is an ongoing issue what is the best way to resolve it? There is a "Reinstall Endpoint Protection" option available but I'm thinking maybe connecting to the machines via remote control and using the instructions in the link above would be more reliable. 



This thread was automatically locked due to age.
Parents
  • Hi ,

    For question # 1, You can try to acknowledge those alerts. you will be able to verify if this is solved as it will change the status of those missing components to a "running" status. If you observed the same issue after you acknowledge the alerts. You may proceed with applying the below steps to changes the Kext permission on the system.

    Boot into macOS Recovery mode.
    Open Terminal.
    Run the command: /usr/sbin/spctl kext-consent add 2H5GFH3774
    Reboot the affected Mac

    In Addition, may I know if the devices are currently running Big Sur OS?

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi ,

    For question # 1, You can try to acknowledge those alerts. you will be able to verify if this is solved as it will change the status of those missing components to a "running" status. If you observed the same issue after you acknowledge the alerts. You may proceed with applying the below steps to changes the Kext permission on the system.

    Boot into macOS Recovery mode.
    Open Terminal.
    Run the command: /usr/sbin/spctl kext-consent add 2H5GFH3774
    Reboot the affected Mac

    In Addition, may I know if the devices are currently running Big Sur OS?

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
No Data