Deployment recommendations and guidelines
Follow these recommendations and guidelines to successfully deploy in Observe mode.
Task Recommendation Description
Identify and place the
endpoints in Observe
mode to analyze
product impact on the
endpoints and identify
and define the
required rules.
Number of
endpoints
For effective deployment in a large setup, begin with an
initial batch of 10,000 endpoints.
Selecting endpoints
Select any 10,000 endpoints from your setup and place
them in Observe mode. If your existing groups consist
of similar endpoints, this allows you to analyze product
impact on the endpoints, discover policy groups, and
validate the policies to apply to each group.
To reduce deployment time and quickly identify
relevant rules, you can instead select or create a
group that more accurately represents the
enterprise. If you have multiple types of endpoints in
your setup, create a subgroup within each existing
group. For example, the HR subgroup within HR
Department group. Use a combination of all
subgroups, such as HR, Finance, Engineering, IT, and
Admin to identify 10,000 endpoints for initial
deployment. Because you select endpoints from
varied groups, you effectively choose a set of
endpoints with different operating systems, across
different locations, used for different purposes and
with varying usage. This type of selection effectively
represents each type of system in the enterprise and
allows you to quickly identify and define the required
rules. After you identify the rules for this
representative set, you can reduce deployment time
by directly placing the remaining endpoints (within
each group) in Enabled mode.
Pre-deployment
tasks
Complete these activities for your endpoints:
• Run an on-demand scan.
• Patch applications and operating system.
• Scan and pull applications in enterprise.
• Run GetClean to classify the gray applications.
• Block unwanted applications.
Place a batch in
Observe mode by
running the SC: Enable
client task.
For details, see Place
endpoints in Observe
mode in McAfee
Change Control and
McAfee Application
Control Product
Guide.
Pulling inventory Pull an inventory for endpoints when placing endpoints
in Observe mode. Select Pull Inventory when placing the
endpoints in Observe mode.
Verifying placement Run the Application Control Agent Status query to verify that
selected endpoints are placed in Observe mode. For
more information, see McAfee Change Control and
McAfee Application Control Product Guide.
Number of
endpoints
At any time, there should be 10,000–20,000 endpoints
running in Observe mode. At any point, only 2 batches
can simultaneously run in Observe mode.
Deploying Application Control in Observe mode
Deployment recommendations and guidelines
3
McAfee Application Control 7.0.0 Best Practices Guide
19