SEP for Mac: Troubleshooting

Though disabling SEP is not recommended, the quickest way to determine if an issue is being caused by SEP's protection technologies, is to "disable" the client temporarily to see if an issue goes away.

In the next section, we will discuss how to examine logs to determine what SEP is doing, which is the preferred method to rule out SEP as the cause of unwanted behavior.  However, the feature of allowing end-users to "disable SEP", provides an easy way to set the SEP client into a pass-through mode to determine if one of SEP's protection technologies is interfering with a task you need to accomplish and know to be benign.

To temporarily disable the Auto-Protect feature:

  1. In the top menu bar, to the far right, click the Symantec QuickMenu icon.
  2. From the drop-down list, select Symantec Endpoint Protection.
  3. From the drop-down list, select Disable Virus and Spyware protection & repeat for Disable Network Threat Protection.
  4. An authentication window will open.
  5. In the "Name:" field, type a local account name that has administrator privileges.
  6. In the "Password:" field, type the password for the administrator account.
  7. Click OK.

To re-enable SEP Auto-Protect feature:

  • wait for a few minutes (the central policy should force the client re-enable itself shortly)
  • follow the same procedures used to disable the feature, but in step 3, choose "Enable" for the protection type

To stop an active scanning process:

  1. Go to Applications -> Symantec Solutions -> Symantec Endpoint Protection
  2. If a scan is in progress, you should be presented with an option to postpone or cancel the scan