Configure and test macro detection (Windows only)
Windows
only)There are two options available in a device policy to detect and respond to potentially dangerous macros on
Windows
devices. The Macros option on the Script Control tab applies to Windows
agent 2.1.1578 and earlier. The new Exploitation > Dangerous VBA Macro option on the Memory Actions tab applies to Windows
agent 2.1.1580 and later. When you test your upgrade to agent 3.x, you must check your current configuration for detecting and responding to macros and configure the new Dangerous VBA Macro option accordingly.- In the management console, on the menu bar, clickPolicies > Device Policy.
- Click your production device policy.
- On theScript Controltab, note the current configuration for macros (Alert or Block).
- InPolicies > Device Policy, click the device policy for your test devices.
- On theMemory Actionstab, expandExploitation.
- For theDangerous VBA Macroviolation type, set the appropriate action (Ignore, Alert, Block, or Terminate).
- Save the device policy.
- RunCylancePROTECT Desktop3.x on test devices that use files with macros that are commonly used in your organization. If necessary, add additional memory protection exclusions for safe macros. For instructions and guidance, see Memory Protection in theCylance Endpoint Securitysetup content.