Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Safeguard - Port control policy (Conflict resolution)

Hi All,

Please a take a look at my design/scenario below.

Policy A - Blocks USB storage ports

Policy B - Allows USB storage ports

Policy C - Force File level Encryption to all removable storage devices

Policy A is applied to the default ".Auto Registered" OU as a "catch all". All new PCs/Notebooks when installed with Safeguard is issued Policy A to have port disabled.

Policy B is applied to a group call USB_Allow. The purpose of this group is to allow controlled group of users to have USB.

The thing is we are not using Active Directory synchronization due us having a pretty complex and ever-changing AD OU structure. So this means Computer 1 when installed with Safeguard will get Policy A by default

And computer 1 is supposed to be allowed USB usage. So it gets assigned to Group B and C.

So how do i resolve the fact that Policy A blocks, while Policy B allows? Using the priority? (Works?) Or just setting Policy B to be a no overrride?

:18773


This thread was automatically locked due to age.
Parents
  • Thanks!

    Encrypting just the whitelisted removable media sounds good (cos all other removable media are blocked anyway). But how do i do this? But should i create a distinct removable storage whitelist or just a removable storage whitelist?

    Erm actually i have not idea what hybrid/briding control means? I suppose its hybrid networking devices control?

    :18887
Reply
  • Thanks!

    Encrypting just the whitelisted removable media sounds good (cos all other removable media are blocked anyway). But how do i do this? But should i create a distinct removable storage whitelist or just a removable storage whitelist?

    Erm actually i have not idea what hybrid/briding control means? I suppose its hybrid networking devices control?

    :18887
Children
No Data