EDR installation
The following requirements need to be met for EDR to work on an endpoint:
The BEST agent needs to be installed on the endpoint with the EDR Sensor and Advanced Threat Control modules enabled.
If your endpoints already have the BEST agent deployed, you can use a Reconfigure agent task to add the modules to the endpoint. For more information, refer to Reconfigure agent.
If no agent is installed, you will need to use an installation package to deploy BEST on your endpoints along with all required modules. For more information, refer to Install security agents - standard procedure.
A policy that has the EDR feature enabled on the Incidents Sensor page needs to be applied to the endpoint.
For information on how to enable EDR for a specific policy, refer to Incidents Sensor.
Also, Advanced Threat Control needs to be enabled in the same policy from the Antimalware > On-Execute policy subsection. Refer to On-execute for details.
A license that includes the EDR feature.
You can find a list of compatible licenses under Security features.
Tip
If this is your first time using EDR, we recommend checking out our EDR onboarding guide.