Some third-party Anti-Virus and Threat Detection & Prevention solutions prevent non-approved applications from accessing local system resources. This can prevent the MyID Authentication Server from installing or functioning correctly.
Issues can include:
- The installation program may fail to start after initially extracting files.
- MyID MFA and PSM services failing to access database files or write to log files.
- Components are not able to connect to the Windows services.
- Services are unable to access certificates in the Windows Certificate Store.
Furthermore, some of these issues can appear to be intermittent.
In these situations, you must configure your Anti-Virus / Threat Detection and Prevention solution to allow the MyID Authentication Server to function correctly. Issues are most commonly found with the following vendors' products, however this is not an exhaustive list:
- McAfee
- Symantec
Configuring exceptions in third party solutions for MyID Authentication Server v5.x
You are recommended to set your Anti-Virus or Threat Prevention and detection solution to exclude or whitelist all .dll and .exe files in the following folder and its sub-folders:
C:\Program Files\Authlogics Authentication Server
Configuring exceptions in third party solutions for Authlogics Authentication Server v4.x
The following is a list of the Executable, DLL and .NET Framework Library files created and utilized by the Authlogics Authentication Server v4.x that you must set your Anti-Virus or Threat Prevention & Detection solution to exclude or whitelist:
Folders
The following folder and its sub folders:
C:\Program Files\Authlogics Authentication Server\
Executable code and processes
Executable code and processes located within C:\Program Files\Authlogics Authentication Server\ folder:
AuthenticationServerService.exeAuthNPS.dll
Executable code / processes located within C:\Windows\System32\ folder:
AuthRad.dll
Executable code / processes located within Authlogics folders within the Global Assembly Cache (C:\Windows\Microsoft.NET\assembly\GAC_MSIL):
AuthlogicsAuthlogics.ActiveDirectoryAuthlogics.CoreAuthlogics.PasswordPolicyAuthlogics.Providers.ActiveDirectory
.NET Framework 4.8 libraries
SystemSystem.CoreSystem.ConfigurationSystem.Configuration.InstallSystem.DataSystem.Data.DataSetExtensionsSystem.DeploymentSystem.DirectoryServicesSystem.DirectoryServices.AccountManagementSystem.DirectoryServices.ProtocolsSystem.DrawingSystem.EnterpriseServicesSystem.ManagementSystem.RunTime.SerializationSystem.SecuritySystem.ServiceModelSystem.ServiceProcessSystem.WebSystem.Web.ExtensionsSystem.Web.ServicesSystem.Windows.FormsSystem.XmlSystem.Xml.Linq
Certificate Store
Some Anti-Virus or Threat Detection and Prevention solutions can also limit which applications and processes can access certificate stores. Authlogics Authentication Server requires access to the workstation's Local Computer Certificate store and must be given access.
Windows Defender Data Execution Prevention (DEP)
Windows Defender DEP may erroneously prevent the Authlogics Authentication Server installation program from functioning correctly. Windows Defender DEP is disabled by default on Windows Server, however if it has been enabled an exclusion may be required for the Authlogics installer to function. As DEP technology includes signature updates the behaviour may not always be consistent and installation may succeed even when DEP is enabled.
0 Comments