Introduction
This document outlines the supported Windows anti-malware, patch management, disk encryption, and firewall products compatible with the Cisco ISE posture agent. The Cisco Secure Client Windows Compliance Modules are detailed with version 4.3.4628.8192.
It is recommended to utilize the latest versions of compliance modules available on Cisco.com for the most current security fixes and product support. Compliance module packages are archived from Cisco.com six months after their release date.
For support on unsupported products or versions, an enhancement request can be submitted. Upgrades to new versions are supported only from compliance modules available on Cisco.com.
A specific issue was noted for Windows 10 where the posture state might be marked as non-compliant when the USB block condition is enabled. This issue is not present in Windows 11.
Support Chart Overview
The following table provides a description of the columns included in the support charts:
- Product Version: Specifies the version of the product supported by the Cisco ISE posture agent.
- Definition State Check: Indicates if the Cisco ISE posture agent can retrieve anti-malware definition version and date.
- Live Update: Shows if the Cisco ISE posture agent can trigger live updates for products.
- Application Running Check: Determines if the Cisco ISE posture agent can check the application's status.
- Application Kill: Indicates if the Cisco ISE posture agent can terminate the application.
- Application Uninstall: Shows if the Cisco ISE posture agent can uninstall the application.
- Min. Compliance Module Version: Displays the minimum required compliance module version for product support.
- Encryption State Check: Specifies if the Cisco ISE posture agent can check the encryption state of a particular product.
- Firewall Enabled Check: Determines if the Cisco ISE posture agent can verify if the firewall is enabled.
- Enable Firewall: Indicates if the Cisco ISE posture agent can enable the firewall as part of remediation.
- Enable Remediation: Specifies if the Cisco ISE posture agent can enable patch management software.
- Update Remediation (Install Missing Patches): Shows if the Cisco ISE posture agent can update patches on the endpoint.
- Activate GUI Remediation: Indicates if the Cisco ISE posture agent can display the patch management software's GUI.