Endpoint Protection

 View Only
  • 1.  SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 12:45 AM

    Dear All,

    Recently we have started using SEPM 12.1 in our environment. During testing i found that when we boot a machine in Safe Mode then all services of Syamntec are Disabled !!! Is this supposed to be like this?

    Earlier i had used McAfee and at least the Anti Virus service remains active even in safe mode...

    Firewall getting disabled in safe mode is understandable but why even AV?



  • 2.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 01:04 AM

    yes,the services are disabled in safe mode.



  • 3.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 02:29 AM

    Dear Harsh,

    In safe mode all the services of sep are disabled...but if you want to scan in safe mode you can run the sep manualy from START--> All programs, it will ask to start the services but choose NO....SEP console will open after choosing NO and then you can run a full scan from console.......



  • 4.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 03:34 AM

      

    Dear Pawan,

    Thanks for the reply however the behaviour of SEP is different in my case.

    [1] In safe mode - from all programs menu if i try to start SEP -

    "SEP cannot be started, make sure required services are runnng"

    [2] From services.msc if i try to start SEP services -

    "Error 1084: This service cannot be started in safe mode"

    [3] If i try to right click a file and - scan for threats -

    "SEP cannot perform a right click scan. Make sure SEP service is started."

     

    I think Symantec forgot to keep security in safe mode. If an attacker wants to steal data this would be a good option. Nothing scans so nothing logged in turn nothing reported.... :(

    I would be really glad if someone from this forum can suggest a solution or a workaround at least.

    Anyone from Symantec side.....???



  • 5.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 04:47 AM

    Harsh....

    Is your sep working fine in normal mode?



  • 6.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 04:49 AM

    Yes Pawan, it works fine in normal mode.



  • 7.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Broadcom Employee
    Posted Jan 27, 2012 04:49 AM

    you can open SEP in "safe mode with networking" mode



  • 8.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 05:39 AM

    We are also facing same issue in our environment, i cann't protect our data & file in safe mode. but you can disabling/enable safemode option by entering below command.

    For Disable: bcdedit.exe /set {bootmgr} displaybootmenu no

    For Enable: bcdedit.exe /set {bootmgr} displaybootmenu yes

    Regards, Chandan

     



  • 9.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 06:56 AM

    Hi Harsh,

    I tested in lab that sep 12.1 work in safe mode with networking....

    Run the machine in safe mode with networking it will work....



  • 10.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Posted Jan 27, 2012 07:04 AM

    harsh,

    (I think Symantec forgot to keep security in safe mode. If an attacker wants to steal data this would be a good option. Nothing scans so nothing logged in turn nothing reported.... :(

    I would be really glad if someone from this forum can suggest a solution or a workaround at least.)

     

    Your this question also will be solved when you start machine in safe mode with networking....coz sep work in safe mode with networking...

    And we do not have attacker tension in sfe mode without networking...coz no one can attack on ur machine without networking....



  • 11.  RE: SEPM 12.1 - All Services disabled in Safe Mode !!!

    Trusted Advisor
    Posted Jan 30, 2012 08:40 AM

    Hello,

    The dependent service of Symantec Endpoint Protection is Symantec Management Client.

    Now, since Symantec Management Client service remains disabled, the SEP service would not start as well.

    However, You can surely scan in Safe mode.

     

    You may face a difficulties when booted into Safe Mode and launching the Symantec Endpoint Protection client to perform a scan an error dialog with the following text:

    "It appears that the Symantec Management Client service is not running. You will not be able to to manage network protection settings through the main user inferface until it is running. Do you want to start the service now?"
    Solution
    Click "No" to let the Symantec Endpoint Protection client launch and perform scans of the system while booted in safe mode. The Symantec Management Client service is not required and cannot be started while in Safe Mode.
     
    Reference: 
     
    You can also run a Full scan in Safe mode with command prompt, check this Article:
     
     
    Hope this helps!!!