Team: Huntress Managed Endpoint Security Posture Management (ESPM)
Product: ESPM
Environment: Eligible Windows endpoints
Summary: Learn how RMM Guard progresses through Learning Mode and Blocking Preview to safely enable Blocking Mode for your account.
RMM Guard blocking only activates once you enable it for your account, and we are confident it will not disrupt legitimate remote access tools. This article describes the process for enabling blocking mode.
View the requirements for RMM Guard Blocking mode here!
Learning Mode
- When RMM Guard is first enabled, it starts in Learning Mode. It collects data from your endpoints and builds an inventory of every RMM and remote access tool it finds.
- Nothing is blocked or changed during this stage. RMM Guard is only watching and collecting data.
Admin Review
- As tools are discovered, you can review them in the RMM Guard dashboard and mark each one as approved or rejected.
- Approved tools are the ones your team actually uses. Rejected tools are ones you do not want running in your environment – but blocking will not start until explicitly enabled in following steps.
- Tools you have not yet reviewed stay in an unreviewed state until you make a decision.
Blocking Preview
- Once enough data has been collected, your account can move into Blocking Preview. This is a safe rehearsal of blocking: RMM Guard shows you exactly what would have been blocked, but nothing is actually stopped yet.
- This gives you a chance to confirm your approvals and rejections are set up correctly before real enforcement turns on.
- Previously approved tools that are discovered in new locations / file paths will be allowed and new locations will be added to the “allowed” policy.
- Any tool that is brand new to your environment during Blocking Preview will be treated as blocked by default.
Blocking Mode
- When you and your endpoints are ready, you can turn on Blocking Mode from the RMM Guard dashboard.
- Approved tools continue to run without interruption.
- Rejected tools are blocked from running.
- Tools discovered before Blocking Mode is enabled, that have not been reviewed, are generally still allowed to run so you are not caught off guard, unless the tool is running from a location commonly used by attackers (such as a Downloads or Temp folder) or is tied to a tool you rejected (i.e. similar signing cert). In those cases, it will be blocked until you review it.
- Any tool that is brand new to your environment after Blocking Mode is on is blocked by default. You can review and approve it if it turns out to be legitimate.
Adding New Devices/Orgs After Blocking Is Enabled
- When a new device joins an account that already has Blocking Mode turned on, it does not start blocking immediately.
- The new device automatically inherits your existing approvals, so tools you have already approved elsewhere in your environment continue to run right away.
- The device first goes through its own monitoring period to confirm it is healthy and stable (currently 14 days, plus a reboot).
- Once that device meets the same readiness requirements as your other endpoints, it automatically switches over to full blocking. No extra setup is needed on your end.
- New organizations added to the account will go through a similar process as endpoints are confirmed, then blocking is automatically enabled.
How to Enable or Disable RMM Guard
- To enable or disable RMM Guard at the Account or Organization level, visit ESPM → Settings
- You can enable/disable RMM Guard at the Account level, then add manual overrides for each Organization or Endpoint below.