[Question] Disable Scan Feature on EDR (Both manually and automatically)

Newbie149710 Lv1Posted Oct-09-2025 18:01

My company is currently using traditional AV system. In order to meet the compliance requirement, EDR will be adopted. May I know how to disable Sangfor EDR Scan feature (Both manually and automatically). We would like to keep the traditional AV system for known AV or AV scanning. Also, we do not want to allow user to click the scan button by themselves. Please advise. Thank you.

By solving this question, you may help 340 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Newbie337989 Lv2Posted Oct-10-2025 14:04
  
Hi,

As per my understanding, you’re planning to use Sangfor EDR primarily for threat detection, endpoint monitoring, and behavioral analysis, while keeping your traditional AV for signature-based scanning.
For this, you don’t want:
- EDR to perform automatic or scheduled scans, and End-users to manually trigger scans through the EDR agent.

Try this Manual method:
- Log in to the endpoint with admin rights.
- Open the Sangfor EDR Agent interface.
- Go to Settings → Scan Settings (or similar tab depending on version).
- Disable Scheduled Scan or Automatic Scan on Startup.
- Save the settings.

Note: This method might still allow users to initiate manual scans if the “Scan” button is visible — so it’s best combined with central policy enforcement.

For Automatic method: (If you are managing EDR via Athena EDR Console or Cyber Command, you can centrally control the scan policies.)
- Log in to the Sangfor EDR / Cyber Command Console.
- Navigate to:
  - Policy Management > Endpoint Protection Policy / Virus Scan Policy
- Locate your policy group (e.g., “Default Group” or custom group for your users).
- Disable or uncheck the following options:
  - Automatic Scan / Scheduled Scan
  - Real-time Scan on File Access (if traditional AV already covers this)
  - Scan after Startup / USB Insertion / Download
- Under User Permissions, disable the option:
  - Allow User to Trigger Manual Scan
- Save and push the policy to endpoints.

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

910
182
94

Started Topics

Followers

Follow

Trending Topics

Board Leaders