Computers Page: ThreatLocker 6.0
The first improvement you will notice is that the āMonitor Onlyā mode box has been removed. It has been replaced with a quick dropdown āStatusā box which represents the current security status of ThreatLocker and provides a quick way of changing this status.

Enabling Protection
The āEnable Protectionā box ends all maintenance periods and secures all the selected computers. At any time, to end all maintenance periods and re-enable protection, select the box next to the computer you wish to end maintenance on and enable protection on and click the āEnable Protectionā box placing the selected computer into a āSecuredā status.

Disabling Protection
The āDisable Protectionā box allows you to place multiple computers into Monitor Only Mode or Learning Mode at once.

Enabling Monitor Only Mode
To place computers in Monitor Only Mode first, select the checkbox next to the computers you wish to enable Monitor Only Mode on. Then, select the āDisable Protectionā box. From the dropdown menu, select the date and time you wish to re-enable protection, and do not select the box next to āAllow Learning based on Group Settingsā.

You will see the status read āMonitor Onlyā in red. This status means that no execution or Ringfencing policies that donāt have explicit denies will be blocked. Nothing will be learned in āMonitor Onlyā Mode. All actions will be logged in the Unified Audit.

Enabling Learning Mode
To enter āLearning Modeā you need to click the check box next to āAllow Learning Based on Group Settingsā.

After clicking āStartā the status will change to āLearning Modeā.

When computers are first installed, they will stay in āLearning Modeā based on the computer group settings. Navigate to āComputer Groupsā, then the specific group to enter the group management window where you can view or change the default Learning Mode duration setting via the āInitial Learning Mode Duration for New Computersā dropdown menu. This change will take effect on computers that are installed AFTER this setting is changed.

Client Version
The āClient Versionā box allows you to easily select which version of ThreatLocker you want to run on the selected computer. You can choose to āInherit from Groupā, or select a specific version of ThreatLocker.

Maintenance Mode
The āMaintenance Modeā button replaces the āStart Learning Modeā button from earlier versions. It opens up the āMaintenance Scheduleā menu. There are five different types of maintenance you can schedule. Multiple maintenance schedules can run at the same time.

Elevation Mode
To select the āElevation Modeā, you must have the ThreatLocker Elevation product. It allows you to automatically elevate any programs that require elevation for all users or selected users.

To add an elevation period, select a start date and an end date. The default time period is one hour. Then select āAdd Maintenance Scheduleā. If you select the āAllow the user to End the schedule from the Computerā, a popup box will appear on the end userās computer showing that Elevation Mode is enabled and the user can click to end the elevation period when they are done. There is also a countdown timer on the popup showing how much time is remaining.


If the āAllow the user to End the schedule from the Computerā box is not checked, the popup will not appear, and Elevation Mode will run silently on the computer.
Installation Mode
Installation Mode turns off blocking for execution and Ringfencing policies and learns any changes or newly installed files on the system.

Learning Mode
Learning Mode is similar to Installation Mode. It learns what files are being installed on the computer and it learns what files would be denied using the default deny policy. If you have an application already installed and you want to learn what files are required to run it, you can put the computer into āLearning Modeā, select the application from the āApplicationā dropdown menu and click āAdd Maintenance Scheduleā to place the computer in Learning Mode.

There is also an āAutomaticā option in the āApplicationā list. This is the default mode when installing new computers. This automatically learns the application name and creates policies. When you first install, the time period is set to one week. When setting on āAutomaticā it is not recommended to select āAllow the user to End the schedule from the Computerā.

Monitor Only
āMonitor Onlyā mode is similar to the others. You select āMonitor Onlyā and choose the start and end times. You choose which users to apply it to and then select āAdd Maintenance Scheduleā. This will turn off blocking temporarily but it will not learn. If you select the āAllow the user to End the schedule from the Computerā box then the user will receive a popup stating that Monitor Only mode is temporarily enabled.

Tamper Protection Disabled
āTamper Protection Disabledā allows you to disable tamper protection for a period of time. For example, if you need to disable ThreatLocker to diagnose an issue, you can do that. It is recommended to only disable Tamper Protection when working with ThreatLocker Support.

Select āTamper Protection Disabledā and choose the start and end times. āTamper Protection Disabledā must be applied to all users. If you want the end user to receive a popup, select the box next to āAllow the user to End the schedule from the Computerā. Click āAdd Maintenance Scheduleā to start the āTamper Protection Disabledā period. The status will be flagged in red.

Move Computer
āMove Computerā allows you to move multiple computers at once. Choose the computers you wish to move and then click the āMove Computerā button.

Then you will choose the āTarget Organizationā and the āTarget Computer Groupā from the dropdown menus to move computers easily from one organization to another.

It is important to note that the policies applied to those computers do not get carried over to the new organization. For this reason, you may want to click the box next to āEnable Learning and Rescan Baselineā before you click āMoveā. This is not a required step, but if you do not choose this, it may block existing software on the computer.

Rescan Baseline

When you click on āRescan Baselineā you can choose whether or not to āEnable learning based on group settingsā. If you choose not to āEnable learning based on group settingsā, no policies will be created automatically. You will get a list of all the files on that computer in the āUnified Auditā.
