Security software exclusions
Security software can mistake the Overseer agent for a threat and block it. This page explains why that happens, how to recognise it, and the kinds of exclusion that let the agent work.
Why security software and the agent collide
The Overseer agent is the lightweight service Overseer installs on each computer. To do its work it behaves in ways that security software is built to distrust:
- it runs as a Windows service with system rights;
- it keeps a long-lived outbound connection to your Overseer instance;
- it receives PowerShell over that connection and runs it;
- it downloads installers and runs them without anyone at the keyboard.
Security software judges programs by what they do. Unless you tell it that the agent is expected, it may block the agent outright, block it some of the time, or cut its connection.
Signs that security software is in the way
- A computer has the agent installed but stays waiting to be identified.
- A computer shows as offline although it is switched on and connected.
- Actions fail as a script starts, on some computers and not on others, or on some days and not on others.
- Sessions stop working straight after the agent is updated, because the new files are unfamiliar to the security software.
- The agent's own log on the computer shows a connection that closes as soon as it opens, or a script that starts and then goes quiet.
A quick test is to pause the security software on one affected computer and press Deployment detection. Detection is read-only. If it now completes, add exclusions and switch the protection back on.
What to exclude
Add the narrowest exclusion your security software supports, in this order of preference.
- By publisher. Where the security software can trust programs by the publisher that signed them, trust the publisher of the Overseer agent. This covers later agent versions without further changes.
- Folders. Exclude the Overseer agent's install folder and the folder the agent runs scripts from.
- Processes. Exclude the agent's processes, including any helper process the agent starts to run scripts.
- Script activity. Allow PowerShell that the agent's processes start. If a strict script-scanning mode blocks scripts now and then, exempt the agent's script folder from that mode.
Some security software needs the folder and the process exclusions together. With only the folder excluded, a newly installed or newly updated agent can be unable to fetch what it needs to run scripts, and the computer stalls at identification or at the start of a session.
Network filtering and inspection
The agent has to reach the address of your Overseer instance and hold the connection open.
- Inspection of encrypted traffic. A firewall or security agent that opens encrypted traffic breaks the agent's long-lived connection. Exempt the address of your Overseer instance from inspection. The agent detects inspection and reports it to Overseer, so you can see which computers are affected.
- Inspection certificates. Where a site inspects traffic as a rule, deploy the site's inspection certificate with a task so that Windows trusts it. Place that deployment first in deployment ordering, so later items can download.
- DNS filtering. A DNS filter can fail to resolve an address without listing it as blocked. The effect is the same: the agent cannot connect. Add the address of your Overseer instance to the filter's allow list.
- Firewalls. Allow outbound connections from the computer to the address of your Overseer instance.
PowerShell policy
Tasks and scripts in Overseer are PowerShell, so a rule that forbids PowerShell scripts stops every one of them. If your directory sets the PowerShell execution policy, script execution must be allowed for both the computer and the user. A policy of RemoteSigned lets Overseer's scripts run.
To see the policy in effect on a computer, run:
Get-ExecutionPolicy -List
Confirming the exclusions work
- 1Apply the exclusions to one affected computer, or to a small group.
- 2Open the computer and press Deployment detection.
- 3Open the session and confirm that its actions report results.
- 4Press Re-run on a session that failed earlier and confirm that it completes.
- 5Apply the exclusions to the rest of the client's computers.