Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SafeGuard Enterprise 550 questions

Hi All,

I am new to SafeGuard, i still have many things which i am unclear of now.

1) Active Directory. If i do not synchronize my AD with the SGN, and i just create a domain myself. How do i add users to it? I assume when a new user connects to SGN, he will be added to auto.registered container.. how to do i move this user to the domain i created? I noticed the Move button is greyed out.

2) Local Storage Encryption. I configured a local storage encyption policy with the purpose of encypting our notebooks (HDD). But i recieved feedback that the policy is encrypting mobile devices that are detected as usb storage by Windows. Is there any way i can prevent this?

:3457


This thread was automatically locked due to age.
Parents
  • I actually had to ask technical support for clairification before creating my policies on this one.  According to support, the following device protection targets map to actual devices:

    Boot Volumes

    - System Partition

    Other Volumes

    - Non-system partitions on the system disk

    - Non-system internal IDE hard disks (all partitions)

    - Non-system internal SATA hard disks (all partitions)

    - eSATA external hard drives, all parittions

    Removable Media

    - USB storage devices (flash drives, hard disks, card readers, etc)

    - Firewire (iee1394) storage devices (hard disks, etc)

    So, if you want to use sector-based encryption to encrypt a machine that has both a C and D drive, you need to create TWO  Device Protection policies with a media encryption mode of "Volume Based".  One needs to target Local Storage Devices\ Mass storage\ Boot Volumes (for C drive encryption), and the other needs to target Local Storage Devices\ Mass storage\ Other Volumes (for the non-system partition).

    I hope this helps.

    :3794
Reply
  • I actually had to ask technical support for clairification before creating my policies on this one.  According to support, the following device protection targets map to actual devices:

    Boot Volumes

    - System Partition

    Other Volumes

    - Non-system partitions on the system disk

    - Non-system internal IDE hard disks (all partitions)

    - Non-system internal SATA hard disks (all partitions)

    - eSATA external hard drives, all parittions

    Removable Media

    - USB storage devices (flash drives, hard disks, card readers, etc)

    - Firewire (iee1394) storage devices (hard disks, etc)

    So, if you want to use sector-based encryption to encrypt a machine that has both a C and D drive, you need to create TWO  Device Protection policies with a media encryption mode of "Volume Based".  One needs to target Local Storage Devices\ Mass storage\ Boot Volumes (for C drive encryption), and the other needs to target Local Storage Devices\ Mass storage\ Other Volumes (for the non-system partition).

    I hope this helps.

    :3794
Children
No Data