This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Exe files (*.exe, *.bat, *.com, ...) should not be executed on an external drive

Hello,
We're using Sophos Central Intercept X in our domain, and would like to add a policy that will prevent our users from running or copying files from external drives,

e.g.USB drives.
Our goal is to go one step further: we want to create such a rule in general, but we also want to allow certain drives by their unique hardware identifier.

Can this be achieved with Sophos?



This thread was automatically locked due to age.
  • Hello osrsem,

    Thanks for reaching out to us.

    I was able to find the answer to this question in a separate thread.

    It is still possible to use Peripheral Control to only allow certain USB drives to establish a connection with your device, but the control of file transfers can only be done in an outward direction, hence the name Data Loss (Protection).