Certain events trigger registration of a the agent on an endpoint with its Carbon Black App Control server. When this occurs, the following conditions can affect AD policy mapping.

  • When the Carbon Black App Control agent is first installed, the endpoint will register with the server for the first time with the users that are logged on at the time. If no users have logged on since the last time this endpoint was started, the Carbon Black App Control server shows an empty user list for that agent endpoint.
  • When an agent endpoint is restarted, if the Carbon Black App Control agent reconnects to the server before any user logs in, the user list for that registration will be empty.
  • All agent endpoints (whether or not they use automatic policy assignment) re-register when their list of user sessions changes.
    Note: Because of the way in which Windows handles sessions, a user’s session on a Windows endpoint does not necessarily end upon logout. It persists until it is replaced by a different user's session.
  • Agent endpoints are disconnected by the server whenever the server restarts and re-registered when they reconnect to the server.
  • The server disconnects an endpoint (forcing re-registration) when the agent endpoint’s policy assignment is changed manually, or if it is changed from manual to automatic.