Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DataExchange and File Encryption on USB memory sticks/iPods

Hi,

I'm currently testing File Encryption for USB and Removeable Devices and am happy with the settings I'm using for USB memory sticks, however, I also have to test other USB devices with the obvious one being an iPod.

Settings are currently set to only encrypt when a file is copied across (not using Initial File Encryption) and it's been found that when syncing an iPod and new music is copied, it encrypts (as I expected).

Is there any way to differentiate between what type of device is plugged in, or does this require seperate SafeGuard software?

Ideally iPods (and Blackberrys) would be exempt from encryption.

Thanks

Craig

:5006


This thread was automatically locked due to age.
  • If you don't want files that a particular application write to a USB device to be encrypted, you can add that application to the "unhandled applications" list.

    To do this, you have to create a new Device Protection policy that targets local storage devices, and from there you can set the "unhandled applications" field of the policy.  Try adding iTunes.exe, iTunesHelper.exe, iPodService.exe, and AppleMobileDeviceService.exe to the unhandled applications and see if that stops music copied to the iPod with iTunes from being encrypted.

    I'm guessing that you will have to do something similar with Blackberry devices, although in my organization we have quite a few Blackberry devices, and I haven't heard any complaints about not being able to synchronize.

    :5010
  • Many thanks for the heads-up on "Unhandled Applications".

    As you've mentioned, it has to be Local Storage Devices policy, but we're targeting "Local Storage Devices/Removeable Media" and as such you can't add any applications as the option is greyed-out.

    If I use a global Local Storage Device policy, then all drives inc. local and removable will be affected, no? (which is not something we want).

    :5018
  • Create a policy targeting Local Storage Devices, and set encryption to "No Encryption".  When you create a policy group (or apply the policies to an OU), make sure that your Removable Media and Hard Disk encryption policies have higher priority, so it will override the "no encryption" in the unhandled applications.

    You can double check the policy setup with the Resulting tab on the management console.  You should see both a "Local Storage Devices" tab and "Removable Media" tab, and in the "Removable Media" tab, the default value of the unhandled applications field should have gone from being "not configured" to "iTunes.exe, ..."

    :5033