Protect the Client from Unauthorized Uninstallation
Overview
This article explains how you can secure the Netwrix Endpoint Protector (EPP) client on endpoint machines against unauthorized uninstallation. To address this matter, there are two security measures available:
- Set an Uninstall Password: Requires users to enter a password defined by the EPP system administrator before uninstalling the EPP client. This applies to Windows, Linux, and macOS endpoint machines.
- Enable Tamper Mode: This feature safeguards agent integrity and prevents unauthorized termination or alteration of the Netwrix Endpoint Protector Client. Tamper Mode is available for Windows and macOS endpoints and can be enabled from the Device Control > Global Settings page.
For the full reference, see Security Password for Uninstall Protection and Tamper mode.
note
Tamper Mode requires EPP Client version 2605 Hotfix 1 or later (2605.x.2.x) for the full feature set.
Instructions
Set an Uninstall Password
- Navigate to System Configuration > System Security.
- Enter a password under Security Password for Uninstall Protection and click Save.
- After saving the changes, a notification will appear stating the uninstall password is set.
- Update the policies on the endpoint manually or wait for the policies to be automatically updated based on the time set for Policy Refresh Interval.
Enable Tamper Mode
- Navigate to Device Control > Global Settings > Tamper Mode and toggle the switch to On.
- Scroll down to the bottom of the subsection labeled Endpoint Protector Client and click Save.

- Update the policies on the endpoint manually or wait for the policies to be automatically updated based on the time set for Policy Refresh Interval.
- A machine or service reboot is recommended after enabling Tamper Mode for the setting to work correctly.
important
Tamper Mode restricts access to EPP resources. Don't enable it during pilot deployments or when troubleshooting use cases — enabling it can interfere with the diagnostic access those scenarios require.