I'm hoping someone else has ran into a similar situation and can provide an easy answer.
In short, if we have a Rule in our base DLP policy which blocks USB transfers based on sensitive info (PII, etc.), but another Rule in the same policy with monitors and allows transfers, does the 'block USB transfer' rule still activate if it sees sensitive info, even though the 'monitor' rule conflicts with it. Basically, if the two Rules conflict, will the more restrictive one take precedence?
Some context, because I know this seems bizarre. But due to the problems with SecureBoot and Sophos Central, we can't just push out a rule that asks users to confirm potential sensitive info transfers, so I'm trying to find a way around it that will let users transfer normal files as they've always done but now give IT visibility of those transfers via Sophos Central, but still block transfers of sensitive info.
By all means, please ask me to clarify anything here; I realise it's a strange situation.
This thread was automatically locked due to age.