Issue: Real-time scanning or DeepGuard has detected a file to be malicious. How to submit a sample file to Virus labs to find out if it is a false positive? What if a possibly malicious file has not been detected, how to submit a sample file to virus labs to find out if it is a false negative? Resolution: If you suspect…
Issue: When an WithSecure endpoint product is installed on a computer or server, there is high CPU or memory (RAM) usage and applications are experiencing performance issues. The connectivity of some applications can also be slow or blocked completely. Issue affects all WithSecure clients:* Elements Endpoint Protection EPP…
Issue: Getting an error of "Your login to WithSecure™ Partner Portal failed. Please try using a different browser, or you can open a support ticket at: https://www.withsecure.com/en/support " when logging into Partner Portal. Resolution: This error message appears typically when user has an existing WithSecure user…
Issue: I would like to register my Policy Manager Server which is not connected to a network (offline), how do I proceed?Resolution: * Contact WithSecure support by opening a support request here. * Provide the following information for WithSecure technical support to create an offline registration file: * Account Name *…
Issue: Elements Linux Protection or Business Suite Linux Security 64 installation fails with error "Warning: Installation timed out on setting up SELinux integration.". Full error message: Installing WithSecure Linux Security 64 Setting up integration with SELinux Warning: Installation timed out on setting up SELinux…
Issue: How to reset two factor authentication (2FA) for a WithSecure Business Account (Elements, Partner Portal, eService Portal) user account. Example scenarios: User has a new mobile device and wants to move or transfer the authenticator to the new device Device that had the multi factor authentication (MFA) application…
Issue: How does the network drive scanning work?Resolution: Scan network drives setting is enabled by default. How does it behave? * Scanning only happens upon execution of (executable) files on the network drive * Basic open / close, copy / paste operations for a file are not scanned #For Elements EPP, users can enable…
Issue: Normally, the alert notification email from EDR will be sent when a detection with he risk level at "Severe", "High" and "Medium" has been added to the portal, but is it possible to configure the alert email that ONLY will be notified when "Severe" or "high" risk level has happened? Is it possible to filter the…
Issue: WithSecure Elements Endpoint Detection and Response (EDR) sensor does not activate on Ubuntu. The state appears as "Waiting for connection" in the Elements Endpoint Protection portal and the Elements Endpoint Detection and Response portal. Resolution: Elements Endpoint Detection and Response functionality requires…
Issue: After installing Elements Agent client with EDR subscription, the message "Device sensor is not operational" is shown in the local Elements Agent user interface. Resolution: You need to ensure that you have allowed the network traffic to the following addresses in your network firewall. The client sensor silently…
Issue: Following a Elements Collaboration Protection change on September 10, mailbox usage reporting to the dashboard was unintentionally left disabled. As a result, the Active Mailboxes metric in the Home Dashboard may incorrectly show 0 active mailboxes from September 11 onward. Resolution: This is a reporting issue only…
Issue: How does Elements Collaboration Protection subscription usage work? How does Collaboration Protection allocate licenses when there are more mailboxes than licenses available? Resolution: How license allocation works Initial setup or protection settings change Protect all mailboxes When "Protect all mailboxes" is…
Issue: Elements Collaboration Protection Security event page shows the warning "Mailbox protection for mailbox was temporarily disabled due to service issues. The system will attempt to restore it automatically." from the source Provisioning service. What causes this issue and does something need to be done to fix it?…
Issue: Error when updating Azure Entra ID Identity script; "ERROR during Azure deployment: Cannot validate argument on parameter 'Tenant'. The argument is null or empty. Provide an argument that is not null or empty, and then try the command again. Collecting information on failed deployments..." Resolution: Do make sure…
Issue / Symptoms: Error: "The management group cannot be found" when deploying Elements Identity Security for Entra ID with the /deploy.ps1 command. Additional errors: "The deployment validation failed. Deployment WSecCD-azure_entra_id terminates with the unexpected state." Resolution: If you get this error, we recommend…
Issue: I receive the following error when trying to access the Exposure Management in the Elements Security Center: No access rights. You do not have rights to Exposure Management content of this organization. No permission You don't have access to view this page. Please contact your organization administrator to receive…
Issue: * I would like to confirm if WithSecure Elements Vulnerability Management (Radar) can detect CVE-2021-44228 (Log4j2)? * What is the schedule for adding detection for CVE-2021-44228 (Log4j2)? * How can I verify when detection for CVE-2021-44228 (Log4j2) is available? Resolution: The detection of CVE-2021-44228 is…
Issue: My Elements Vulnerability Management Linux Scan Node Agent is not running, scanning or updating. I get the following error: Engine update: Scan Node Agent does not contain the latest available (revision: 65388) vulnerability signatures and updates. Either the Scan Node Agent is not running or there is no network…
Issue: I found that Elements Vulnerability Management Authenticated scan (WinRM using HTTP port 5985) found fewer vulnerabilities. There is no information about installed software or patches in the scan result.Resolution: If you are using port 5985 (HTTP) for the WInRM configuration in the system scan template, make sure…
Issue: After onboarding a new Elements Exposure Management, the Identities view in the Elements Security Center does not populate data. I followed the steps documented in the help guide: https://www.withsecure.com/userguides/product.html#business/xm/latest/en/concept_hvd_jcy_bbc-latest-en How soon can I expect the data to…
Issue: Partner requests for Partner Portal instructions or User Guide on how to use the new Partner Portal: * How to renew existing renewable subscriptions * How to amend subscriptions (increase of decrease the amount of licenses or upgrade subscription to include EDR or Premium) Resolution: You can find the latest Partner…
Issue: Real-time scanning or DeepGuard has detected a file to be malicious. How to submit a sample file to Virus labs to find out if it is a false positive? A web site (URL) is blocked by WithSecure either due to its rating (malicious) or category. What if a possibly malicious file has not been detected, how to submit a…
Issue: This article applies to the following WithSecure products: Elements Agent (EPP for Computers and EPP for Servers), Business Suite Client Security and Server Security The WithSecure Corporate product installation fails with the error below: Example error: -- Error 1722. There is a problem with this Windows Installer…
Issue: What is the recommendation for Windows/Windows SQL server scanning settings? Should the SQL databases and logs be excluded in the virus scanning settings?Resolution: As a general rule we always advise to follow Microsoft's official recommendations from their KB base about exclusions on Microsoft corporate software.…
Issue: When the Policy Manager Server forwards event logs to the syslog server, the log comes in UTC time format. Can it be changed to the Policy Manager Server's operating system time format? Resolution: Regarding the syslog timestamp from Policy Manager Server — this is by design. Policy Manager Server always forwards…
Issue: Why do Client Security and Server Security host devices send the following alert to the Policy Manager Consoler Alerts tab? Access to file was blocked. Application path: C:Example\Example.exe Path: C:\ProgramData\Example\Example\ Resolution: This type of block is the function of the Tamper Protection functionality.…
Issue: When URL Protection is enabled, links in email sent internally and externally has its URL syntax replaced which may break certain links. How to allow those URLs without disabling URL Protection in Cloud Protection for Salesforce?Resolution: Follow these steps to exclude a URL:* Login to Cloud Protection and go to…
Issue: WithSecure is using Future Method to run scans and clashes with custom scripts that also uses Future Method. Any suggestions on how to resolve this?Resolution: By default Cloud Protection for SalesForce uses Queueable Jobs for invoking email attachment scan. However if Future Method was called, this means that the…
Issue: Salesforce stores "documents" in three different objects: ContentVersion (aka Files), Document, Attachment. WithSecure Cloud Protection for Salesforce does not appear to be checking Documents uploaded via API or Manually. It is testing ContentVersion and Attachment.Resolution: This is by design. WithSecure Cloud…
As of February 2026 partner users can no longer self-register into the Partner Portal. Instead, their company administrators can add them to their company. This change enhances security and removes the waiting time for activating new accounts. Here is how to add a new user account to Partner Portal as a Partner Portal…