Can I Pilot Capture Client Upgrade on an Endpoint without changing Threat Protection Policy?
06/17/2020 1 3164
The version of Capture Client (and the relevant agents) that is installed on the device is normally defined by the client policy that applies to the device. However, Admins might want to pilot a new version of CC on a select number of devices before deploying on all endpoints.
But starting with Capture Client 3.0.x adds an option in the device menu to upgrade a specific device to another version of CC, this provides more granularity to how updates are pushed to the endpoints in a single tenant, mid-market Enterprises and larger MSPs/MSSPs can take more control over how to push new updates without having any issues result in widespread impact.
Log into CMC as an Administrator, Global Admin or Super Admin
Navigate to Protection → Devices
Hover over a device and click on the cogwheel menu
Select "Upgrade Client" in the dropdown menu
Select a version of Capture Client in the list
Click "Upgrade Client"
Observe that a command has been sent to the client and after a few minutes, observe that the client has been upgraded to the requested version
Note: Only upgrade is supported, not downgrade. Once a device has been upgraded to a certain CC version, there is no out-of-the box downgrade option (In that case, the way to go is to uninstall CC and re-install it through the default policy) .Only versions of SentinelOne compatible with the selected Capture Client version can be selected, client upgrade is only available if the device is currently online.