diff --git a/edr-install-config/self-healing-rollback.mdx b/edr-install-config/self-healing-rollback.mdx index 0a7d52ee294..266620f463e 100644 --- a/edr-install-config/self-healing-rollback.mdx +++ b/edr-install-config/self-healing-rollback.mdx @@ -2,14 +2,14 @@ id: serverlessSecuritySelfHealingRollback slug: /serverless/security/self-healing-rollback title: Configure self-healing rollback for Windows endpoints -# description: Description to be written +# description: Revert file changes on the Windows endpoints. tags: [ 'serverless', 'security', 'how-to' ] -status: rough content +status: in review --- -import RoughContent from '../partials/rough-content-notice.mdx' +import InReview from '../partials/in-review-notice.mdx' - +
@@ -27,7 +27,7 @@ Also, rollback is triggered by _every_ ((elastic-defend)) prevention alert, so y -1. In the ((security-app)), go to **Manage** -> **Policies**, then select the integration policy you want to configure. +1. In the ((security-app)), go to **Assets** -> **Policies**, then select the integration policy you want to configure. 1. Scroll down to the bottom of the policy and click **Show advanced settings**. 1. Enter `true` for the setting `windows.advanced.alerts.rollback.self_healing.enabled`. 1. Click **Save**.