Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problems with POA and SGN guest users

Hi,

I'm using Safeguard enterprise 5.50. I've got problems with activating POA on machines wich fall under domain .Auto Register folder.  The POA settings of the policy group which is assigned to this folder and activated for .Authenticated Computers says:

  Enable Power On authentication - Yes

  Forbid Guest user - No

  Import of new users allowed for - Nobody

However after installing SGN clilent and rebooting computer POA is never activated. SGN treats all (domain) users who log onto the computer as a guest users. That means that also keys and certificate is not transferred to the computer for logged in users.

Machine is able to contact SGN server. It is in fact encrypting the drives (as also other policy - related to drive encryption was assigned to .auto registered folder).

When checking RSOP for the machine and users who are logging in it shows that POA should be activated (however it is not). Users are not on any service account list.

I've tried to change POA policy to:

  Forbid Guest user - YES

  Import of new users allowed for - Nobody

but changing it ths way I'm unable logging to windows (at GINA level) and I've got prompt: Your current Safeguard settings doesn't allow you to login.  (or similar)

Do you know how to solve the issue and force POA to activate?

:6821


This thread was automatically locked due to age.
Parents
  • Hi Daniel,

    Thanks and yes, this would do the trick. I've used this as a work around. However I don't think this is complete resolution. As far as i remember, if configuration above ( Forbid Guest user - YES,   Import of new users allowed for - Nobody) would be assigned at the domain level (not on .Auto registered folder) it would assign SGN user and activate POA (but i might be mistaken).

    Regards

    :6987
Reply
  • Hi Daniel,

    Thanks and yes, this would do the trick. I've used this as a work around. However I don't think this is complete resolution. As far as i remember, if configuration above ( Forbid Guest user - YES,   Import of new users allowed for - Nobody) would be assigned at the domain level (not on .Auto registered folder) it would assign SGN user and activate POA (but i might be mistaken).

    Regards

    :6987
Children
No Data