# Stopping Elastic Endpoint service

**URL:** <https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027>\
**Category:** Endpoint Security\
**Created:** [January 2, 2021, 9:21pm UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027 "2021-01-02T21:21:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 2, 2021, 9:21pm UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027/1 "2021-01-02T21:21:01Z")

</div>

Hello,

While testing with Elastic Endpoint on my home Windows 10, I noticed I can stop the service with no issue at all.

Service Name: ElasticEndpoint

What would stop a bad actor from stopping the service? if I remember correctly in order to stop the service of some other edr's at work, I need a password. Is there a way to password protect the service?

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![ferullo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ferullo/32/74240_2.png) [@ferullo](https://discuss.elastic.co/u/ferullo)\
**Post date:** [January 4, 2021, 4:48pm UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027/2 "2021-01-04T16:48:29Z")

</div>

Hi @willemdh, thank you for the feedback. Right now, there is no password needed to stop Elastic Endpoint Security on the host, but it is something we're considering in our roadmap for future improvements.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [January 4, 2021, 5:58pm UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027/3 "2021-01-04T17:58:56Z")

</div>

@ferullo Ok, thanks for the info.

Actually I had a quick look at our McAfee and Cylance EDR's and apparently their services are not password protected, but the service / process seems unstoppable.

For McAfee the service can be stopped through the McAfee Endpoint Security gui (from the endpoint), but only once you login the gui as a McAfee administrator.

The processes also can't be stopped through task manager (although I'm admin):

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/0/607394a0b60a46a916529138574ae5dfdd72becc.png)

Please note that we would need this kind of functionality for us to start using Elastic Endpoint Security in production. I'm sure there are workarounds, but it should not be as easy as just stopping the service / process imho..

Grtz

Willem

---

<div class="post-metadata">

**Author:** ![NickFritts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickfritts/32/47189_2.png) [@NickFritts](https://discuss.elastic.co/u/NickFritts)\
**Post date:** [January 6, 2021, 12:19am UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027/4 "2021-01-06T00:19:58Z")

</div>

Hi again @willemdh don't worry, what you're talking about is definitely on our roadmap. With the initial beta release we wanted to make sure any issues users ran in to they were easily able to recover from.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2021, 12:19am UTC](https://discuss.elastic.co/t/stopping-elastic-endpoint-service/260027/5 "2021-02-03T00:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
