Find clear, step-by-step solutions to common WithSecure issues across installation, configuration, updates, and product performance.
Issue: Wenn ein WithSecure Endpunkt auf einem Computer oder Server installiert ist, kommt es zu einer hohen CPU- oder Arbeitsspeicherauslastung (RAM) und bei Anwendungen treten Leistungsprobleme auf. Die Konnektivität einiger Anwendungen kann auch langsam sein oder vollständig blockiert werden. Das Problem betrifft alle…
Issue: I would like to register my Policy Manager Server which is not connected to a network (offline), how do I proceed?Resolution: * Contact WithSecure support by opening a support request here. * Provide the following information for WithSecure technical support to create an offline registration file: * Account Name *…
Issue: Beim Anmelden beim Partnerportal wird die Fehlermeldung „Ihre Anmeldung beim WithSecure™-Partnerportal ist fehlgeschlagen. Versuchen Sie es bitte mit einem anderen Browser oder öffnen Sie ein Supportticket unter: https://www.withsecure.com/en/support.“ angezeigt. Resolution: Diese Fehlermeldung erscheint…
Issue: * When trying to register a Policy Manager Server, we are getting this error: The registration cannot be validated. WithSecure Policy Manager Server could not connect to the WithSecure registration server (https://corp-reg.fsapi.com) Resolution: What should I do if registration fails, saying that my customer number…
Issue: How to create or generate a WSDIAG diagnostics file on a Windows computer? Resolution: Follow the steps below to generate a WSDIAG report. Click on the Windows Start button In the list of apps, click on WithSecure Click on WithSecure Support tools Click Run diagnostics Once completed, it generates a file called…
Issue: How to change, transfer or migrate two-factor authentication (2FA) / Multi-factor authenticator (MFA) to a new authenticator device? Resolution: If you still have access to the old authenticator, you can move the authenticator to a new device by logging in with the existing authenticator to the Elements portal.* Log…
Issue: How to configure Device control where all the USB devices are blocked unless white-listed by its hardware ID. Resolution: You can make rules of various USB Classes where you can set the access level to Block and than make a white-list rule to allow the devices by hardware ID. To know various Class please check this…
Issue: EDR Sensor Disabled is shown in Elements Security Center even after uninstall/re-installation.Resolution: Giving following permission to registry in administration right. Registry HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\SystemCertificates\CA Permission “Local Service” and “Network Service” This is most probably…
WithSecure™ Elements Endpoint Detection and Response (EDR) provides advanced capabilities to detect, investigate, contain, and remediate threats in real time. The platform combines automated detection with flexible response actions to help organizations act swiftly and decisively during cyber incidents. Core Response…
Issue: Mit WithSecure Elements Endpoint Detection and Response (EDR) wird eine sichere Anwendung (z. B. eine interne Anwendung) erkannt. Wie kann die Erkennung auf die Whitelist gesetzt werden? Resolution: Sie können die Broad Context Detection (BCD) als „Akzeptiertes Verhalten“ schließen, um eine Unterdrückungsregel zu…
Issue: Collaboration Protection sent URL detection from an mail received over 2 month ago. Why the delay has occurred?Resolution: If the detection found except neither Inbox nor Sent, it might cause when the mail was moved directory. The suspicious emails are automatically scanned depending on the action defined in the…
Issue: Why is spam / bulk / advertising / phishing email getting through even if Elements Collaboration Protection is in use? Shouldn't spam email be filtered by the spam filter? Resolution: Elements Collaboration Protection does not include a spam filter. Microsoft Office 365 has its own anti-spam policies, of which you…
Issue: Protection for OneDrive assets are always Unprotected. If we try to enable it manually, after a short time it will goes back to Unprotected status. This happens a few tenant accountsResolution: In relation to the issue of OneDrive assets losing protection over time, you might want to review the Elements…
Issue / Symptoms: Error: "The management group cannot be found" when deploying Elements Identity Security for Entra ID with the /deploy.ps1 command. Additional errors: "The deployment validation failed. Deployment WSecCD-azure_entra_id terminates with the unexpected state." Resolution: If you get this error, we recommend…
Issue: Some scheduled system scan (network scans) end up with "Terminated" status.Resolution: We recommend to look into the scan log, which can be viewed by:* Log in to the Elements Vulnerability Management portal * Go to the Security Configuration > Scans > Network scans page * Open the scan group which is having issues…
Issue: I would like to use third-party application with Elements Vulnerability Management portal using the API, but how do I start?Resolution: The quick introduction and best practice guide to the Elements Vulnerability Management API are available here. You can find the full reference manual for Elements Vulnerability…
Issue: How can I check if specific vulnerability or CVE is covered in Elements Exposure Management (formerly known as Vulnerability Management)?Resolution: Option 1: You can view if Elements Exposure Management has coverage for a specific vulnerability directly from the Elements portal: * Login to Elements Elements…
Issue: How does WithSecure Elements Vulnerability Management count scanned unique IP addresses (license usage)?Resolution: Elements Vulnerability Management calculates a total number of unique IPs scanned for vulnerabilities in each and every Elements Vulnerability Management organization. In general:* Only vulnerability…
Issue: Elements Exposure Management vulnerability scans on Linux contain false positive detection for backported software. Any recommendation for scanning backported software? Resolution: For any host with backported software. we would suggest performing authenticated scan to get more accurate result. If the "Skip…
Issue: The hive.db file under C:\Windows\System32\config\systemprofile\AppData\Roaming\f-secure\HiveRoot -folder is growing. Can it be deleted?Resolution: The hive.db file under C:\Windows\System32\config\systemprofile\AppData\Roaming\f-secure\HiveRoot is the cache of our scanning engine for clean files. The file can be…
Issue: How to order evaluation (trial) license for a new customer in the WithSecure Partner PortalResolution: Follow these steps to create an evaluation order for a new customer account in the WithSecure Partner Portal. 1. Log in to your Partner Portal account 2. Click Ordering and select Yearly 3. Click New Order 4. In…
Issue: This article applies to the following WithSecure products:* WithSecure Elements Agent (EPP for Computer or EPP for Servers) * WithSecureBusiness Suite (Client Security or Server Security) How do I uninstall an WithSecure business product via a GPO uninstallation?Resolution: You can follow the steps below to…
Issue: * .XLS and .XLA attachments are blocked by F-Secure filter * The following attachment has been stripped: Source: user1@example.com Destination: support@domain.com File name: 41125001012.xls File size: 192000 bytes Scan result: Attachment '41125001012.xls' matches 'AttachmentFiltering::Included' stripping condition;…
Issue: Linux Security 64 servers display real-time scanning status as "Disabled" in Policy Manager console status page. Policy for these servers is set to real time scanning as "on" and users are not allowed to change this setting. Why does the status show real-time scanning as disabled even if it should be…
Issue: WithSecure Linux Security 64 is not connecting to the Policy Manager Server and it is not visible in the "Import new hosts" tab in Policy Manager Console.Resolution: Check the "/var/opt/f-secure/fspms/logs/request.log" file of Policy Manager server whether there is any request from that Linux client by searching for…
Issue: How to upgrade Cloud Protection for Salesforce? Is there any roll-back option available after upgrade to latest version so that incase if there is any issue with the new version then we can rollback to old version. Resolution: The latest version of the Cloud Protection for Salesforce solution is always available in…
Issue: When URL Protection is enabled, links in email sent internally and externally has its URL syntax replaced which may break certain links. How to allow those URLs without disabling URL Protection in Cloud Protection for Salesforce?Resolution: Follow these steps to exclude a URL:* Login to Cloud Protection and go to…
Issue: After the deployment of Cloud Protection for Salesforce 2.0 tried to import leads into Pardot with the help of an integration user they get the following error message: "Custom Validation Exception: WithSecure Cloud Protection: Your message cannot be processed because you do not seem to have the Cloud Protection…
Issue: Why Am I Getting Error 503 When Attempting to Access Elements EDR? Resolution: If you're encountering a 503 error while trying to access EDR, it may be due to recent changes in the system. Here’s an explanation of what’s happening and how to resolve the issue. Recent Changes: A few weeks ago, the legacy view in EDR…