---
title: "Editing Endpoint Groups"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35404952/Editing%20Endpoint%20Groups"
format: markdown
---
To edit Infoblox Endpoint groups, complete the following:

1. From the Infoblox Portal, go to **Security** > **Threat Defense **> **Endpoints** > **Endpoint Groups**.
2. On the **Endpoints **page, select the** Endpoint Groups** tab.
3. In the data table, select any data linked to the endpoint group you want to edit. This will reveal the **Edit** button in the detail pane's bottom-right corner.
4. Click **Edit **to begin the editing process.
  
5. The Edit Endpoint Group wizard is composed of five configuration steps:
  1. Overview
  2. Authentication Settings
  3. Schedule Updates
  4. Network Settings
  5. Advanced Settings

### **a. Overview**

The *Overview* page of the Edit Endpoint Group wizard to define the basic endpoint group details, assign tags, configure the group state, set the logging level, and specify when inactive endpoints are automatically removed. **NOTE**: The *Endpoint Group Name*, *Description*, and *Associated Policy* fields are uneditable. 

![The Endpoint Group Edit Wizard screen 1 - Overview.](media://b779dc50-d378-485f-820d-83fb352bdf00)


On the *Overview* page, complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **Endpoint Group Name **(uneditable) | The unique name for the Infoblox Endpoint group. |
| **Description **(uneditable) | A brief description for the endpoint group. |
| **Tags** | Add key/value tags to help identify or organize the endpoint group.<br>- Click **Add** to open the **KEY/VALUE** panel, then enter a key and value.
- To remove a tag, select the checkbox next to the tag and click **Remove**. |
| **Associated Policy** (uneditable) | An **associated policy **refers to the security policy that is linked to a specific Endpoint Group. An Endpoint Group is a collection of endpoints (devices) to which the same security policy is applied. |
| **State** | Enable or disable the endpoint group. The group is set to **Disabled** by default. Toggle the switch to the right to enable endpoints for the group. |
| **Log Level** | Select the logging level for the endpoint group. The available options are **INFO** and **DEBUG**. The default logging level is **INFO**. For information on Infoblox Endpoint system logging, see <u>*[Endpoint System Logging](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/70354570)*</u> |
| **Removal after inactivity (days)** | Enter the number of days after which inactive endpoints are automatically removed from the group. The supported range is **15 to 180 days**. If you enter no value, a value less than 15, or a value greater than 180, an error message prompts you to enter a valid value. You can update this value after the group is created. The Infoblox Platform service monitors inactive endpoints for the configured period and removes endpoints that remain inactive. |

After completing the Overview page, click **Save** to save the configuration and exit the wizard, or click **Authentication Settings** in the side menu to continue to the next page of the **Edit Endpoint Group** wizard.

### b. Authentication Settings

Use the *Authentication Settings* page of the Edit Endpoint Group wizard to configure the endpoint group’s authentication session, authentication server port, and authentication profile.

![The Endpoint Group Edit Wizard screen 2 - Authentication Settings.](media://9d054784-5ee9-4514-ac6c-ca300d991e4f)

On the *Authentication Settings* page, complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **Session TTL** | Specify how long the IDP session persists. The default value is **8 hours**. After the IDP session disconnects, the connection must be manually re-established.<br>![Session TTL time options.](media://fe30ff30-3139-47cc-a3f6-38c757150847) |
| **Authentication Server Port** | Specify the port of the authentication server used to authenticate the endpoint group. The default TCP port is **9094**. This value represents the third-party Internal Developer Platform (IDP )port number. |
| **Authentication Profile** | Click **Select Authentication Profile** to enable authentication for the endpoint group. Select an authentication profile from the list of profiles available for use with the endpoint group. The supported authentication protocols are **SAML** and **OpenID Connect**. For more information, see <u>*[Adding an Authentication Profile to an Endpoint Group to Enforce a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35470899)*</u>.<br>![Authentication Profile options.](media://8f0ff4a7-ae5a-4ecf-b3c4-deae8724e39b) |

After completing the **Authentication Settings** page, click **Save** to save the configuration and exit the wizard, or click **Schedule Updates** in the side menu to continue to the next page of the **Edit Endpoint Group** wizard.  
For information on managing access authentication, see <u>*[Managing Access Authentication](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35396331)*</u>.

### **c. Schedule Updates**

On the *Scheduled Updates* page of the Edit Endpoint Group wizard to configure how endpoint updates are installed, schedule update windows, and defer updates for a defined period.

![The Endpoint Group Edit Wizard screen 3 - Scheduled Updates.](media://e9a1573f-8ad3-42ae-8687-63a99e53f87f)

On the *Scheduled Updates* page, select one of the following update options:

| **Option** | **Description** |
| --- | --- |
| **Automatic Updates** | Select this option to install updates automatically. This is the default option. |
| **Schedule Updates** | Select this option to manually choose the day, time, and duration for endpoint updates. |
| **Defer Updates** | Select this option to defer updates. |

### **d. Automatic Updates**

If you select **Automatic Updates**, the system will automatically apply updates when they become available. 

### **e. Schedule Updates**

If you select **Schedule Updates**, complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **Days of the week to perform upgrades** | Select one or more days of the week when endpoint upgrades can be performed. |
| **Local Endpoint Time** | Select the local time of day when the upgrade window begins. |
| **Duration** | Specify how long the system can attempt to perform the update. You can select a duration from **4 to 10 hours**, in one-hour increments.<br>![Scheduling updates.](media://1a8da99e-710f-46d2-aabd-47dabec32f70) |

### Deferring Updates

You can defer endpoint updates for up to **28 days**. Deferring updates allows you to choose a specific day of the week and local endpoint time for deployment, regardless of the original scheduled release date. This prevents you from having to adjust the deferred update schedule in the **Infoblox Portal** before each new Infoblox Endpoint update release.

- Scheduled deferred updates are performed based on the time zone of the local endpoint.

To defer updates, complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **Always defer upgrades for** | Select the deferment period. You can defer updates from **1 day to 28 days**. The maximum deferment period is **28 days**. |
| **Days of the week to perform upgrades** | Select one or more days of the week when upgrades can be performed. Select **All** to allow upgrades on any day of the week. |
| **Local Endpoint Time** | Select the local time of day when deferred upgrades begin. |
| **Duration** | Select the number of hours during which updates can be performed. |
| ![Deferring updates.](media://abf6567f-04e7-4409-a770-825ab944e8ba) |

After completing the *Scheduled Updates* page, click **Save** to save the configuration and exit the wizard, or click **Network Updates** in the side menu to continue to the next page of the **Edit Endpoint Group** wizard.  
For more information, see <u>*[Scheduling Endpoint Group Updates](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35374562)*</u>. 

### **Network Settings**

On the *Network Settings* page of the **Edit Endpoint Group **wizard to configure network location, Point of Presence selection, internal DNS resolvers, fallback DNS resolvers, and mobile endpoint domains.

![The Endpoint Group Edit Wizard screen 4 - Network Settings.](media://5c7c65f3-524c-4716-998c-f2df0cc524d9)

On the **Network Settings** page, complete the following sections as needed:

| **Section** | **Description** |
| --- | --- |
| **IP Address** | Add the IP address where the endpoint group resides on the network. |
| **PoP Setting** | Use **PoP Settings** to improve performance by selecting a preferred **Point of Presence** according to region.<br>Select the preferred **Point of Presence** for the endpoint group. A PoP selection is required.<br>A PoP can be selected automatically or manually.<br>- **Automatic selection**:** **Select this option to have the PoP selected automatically. Set the **Auto Selection** switch to **On**. Auto Selection is enabled by default.
- **Manual selection**: Select this option to manually choose a preferred PoP.
- **PoP locations**: When the manual PoP selection option is chosen, select a PoP server from among the following options: |

### Internal DNS Resolvers

To add an **Internal DNS Resolver**, click **Add** and complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **DOMAINS LIST** | Click **Add** to open the list of available internal DNS resolver domain entries. |
| **FQDN/IP ADDRESS** | Enter the FQDN or IP address of the internal DNS resolver. |
| **FALLBACK TO NETWORK RESOLVER** | Enable fallback to the network resolver for domains in the list by toggling the switch to the **Enabled** position. Domains in the list are routed to the configured internal DNS resolver for resolution. |
| ![The Internal DNS Resolvers panel (expanded).  ](media://2dd52b99-27ae-4e22-8c66-a0557d1a3200) |

Click **Add** to add the internal DNS resolver to the list.

- You can reorder the list of fallback DNS resolvers by clicking :selector: then dragging the members of the list into the desired position.
- For additional information, see <u>*[Adding Internal DNS Resolvers and Fallback DNS Resolvers to an Endpoint Group](https://docs.infoblox.com/space/BloxOneThreatDefense/35470930/Adding+Internal+DNS+Resolvers+and+Fallback+DNS+Resolvers+to+an+Endpoint+Group)*</u>.

### Fallback DNS Resolvers

To add a **Fallback DNS Resolver**, click **Add** and complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **FQDN/IP ADDRESS** | Enter the FQDN or IP address of the fallback DNS resolver. |
| **STATUS** | Enable the resolver by toggling the switch to the **Enabled** position. |
| **ENCRYPTED DNS** | Enable encrypted DNS by toggling the **Prefer Encryption** switch to the right, to the **Enforce Encryption** position. |
| ![2-fallback DNS Resolver.png](media://fa6fcb7f-deae-4c90-8d24-4f32c2bfe44b) |

Click **Add** to add the fallback DNS resolver to the list.

- You can reorder the list of fallback DNS resolvers by clicking :selector: then dragging the members of the list into the desired position.
- For additional information, see <u>*[Adding Internal DNS Resolvers and Fallback DNS Resolvers to an Endpoint Group](https://docs.infoblox.com/space/BloxOneThreatDefense/35470930/Adding+Internal+DNS+Resolvers+and+Fallback+DNS+Resolvers+to+an+Endpoint+Group)*</u>.

### Mobile Endpoint Domains

To add a **Mobile Endpoint Domain**, click **Add** and complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **Domain** | Enter a domain or subdomain. |
| **Description** | Enter a description for the mobile endpoint domain. |
| ![The Mobile Endpoints Domains panel (expanded). ](media://ef029d58-f5c2-4dfd-bd6a-a014698120fb) |

Click **Add** to add the mobile endpoint domain to the list.

- You can reorder the list of mobile endpoint domains by clicking :selector: then dragging the members of the list into the desired position.
- For information on Infoblox Mobile Endpoint, see <u>*[Managing Mobile Endpoint](https://docs.infoblox.com/space/BloxOneThreatDefense/35470955/Managing+Mobile+Endpoint)*</u>.

After completing the *Network Settings* page, click **Save** to save the configuration and exit the wizard, or click **Advanced Settings** in the side menu to continue to the next page of the **Edit Endpoint Group** wizard.

### **Advanced Settings**

On the *Advanced Settings* page of the Edit Endpoint Group wizard to configure offline protection, tamper protection, and on-premises protection for the endpoint group.

Configure a custom IP address when required to address interoperability issues with VPN, SSE, or SASE solutions.

> ⚠️ These settings should be enabled only when recommended by Infoblox Support.

Custom addresses must use an IP address within the **127.0.0.0/24** range.

![The Endpoint Group Creation Wizard screen 5 - Advanced Settings.](media://d041f4ac-91c6-4906-aede-1434956d3715)

On the **Advanced Settings** page, complete the following sections as needed:

| **Section** | **Description** |
| --- | --- |
| **Offline Protection** | Enable offline protection to prevent roaming devices from accessing restricted domains when they cannot communicate with **Infoblox Threat Defense Cloud**. This can occur when the endpoint cannot connect to <u>[http://csp.infoblox.com](http://csp.infoblox.com/)</u> or when there are issues with Infoblox anycast addresses. Offline protection is turned off by default. To enable basic offline protection, toggle the **Offline Protection** switch to **On**. The **Default Block** custom list is used as the offline protection list. |
| **Tamper Protection** | Enable tamper protection to help prevent unauthorized changes to the endpoint configuration. Tamper protection is turned off by default. Toggle the switch to the right to turn tamper protection on.   
For more information, see <u>*[Endpoint Tamper Protection](https://docs.infoblox.com/space/BloxOneThreatDefense/1613135922/Endpoint+Tamper+Protection)*</u>.<br>**Manage Password protection**  
Add a password for tamper protection or generate a system-created password. |
| **On-Premise Protection** | Configure the endpoint group to detect when an endpoint is protected by an on-premises DNS or DFP configuration. On-premises protection is enabled by default. |

### On-Premise Protection settings

In the **On-Premise Protection** section, complete the following fields:

| **Field** | **Description** |
| --- | --- |
| **State** | Toggle the switch to **Enable**. On-premises protection is enabled by default. |
| **FQDN** | Use the default **probe.infoblox.com**, or define a custom, unique FQDN. Do not use a parent second-level domain, such as http://example.com. |
| **TXT Record** | Use the default TXT record, click **Generate random TXT record**, or define your own TXT record. |

Ensure that your on-premises DNS or DFP configuration is set up so when probing FQDN and TXT records, it behaves as expected according to the bypass mode documentation.

After completing the **Advanced Settings** page, click **Save** to save the configuration and exit the wizard.  
For more information, see <u>*[Checking Endpoint Status](https://docs.infoblox.com/space/BloxOneThreatDefense/35374388/Checking+Endpoint+Status)*</u>.