Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Controlled application allowed sometimes, blocked others

Hello

I have been given the task of monitoring our Sophos Central and determining further configurations.

I have noticed that we have 7-Zip blocked under application control (as well as a few others like  Toolbars, Unity Web Apps, Unity Web Players, Eclipse IDE , etc) and sometimes they are blocked and sometimes they are not..

 

Any ideas?

 

Thanks,

Matt



This thread was automatically locked due to age.
  • Nothing on this yet?

    I am having the same issues. Blocks on some PC, others it doesn't.

     

  • No. 

    I tried to get support from them at the end of the school year and was told to 'reproduce the issue'. I don't know what causes the issue, and our students were already gone so there wasn't enough traffic at the time. They took log files and such, but I never got a definitive answer. 

    I've even had it tell me that stuff is blocked on my workstation, and I know for a FACT that I have none of it installed or attempted to use anything like it.

  • I have recently noticed this as well.  Strangely, however, The app may still be blocked even if I see the "Controlled application allowed" notice.  For instance we have Windows Store blocked.  After scanning a system it will detect the app and say "Controlled application allowed: Microsoft Store App (Download manager)".  I'll go to that system try to open the Store and it Sophos will block it as I wanted. 

  • I haven't really looked at that.. but I'm sure it's happening here as well as the initial problem. 

    The reporting has been a nightmare trying to figure out what exactly is going on.

  • I have found out that most of these are "ghost" detections.
    Which means Sophos found the file for this app on an On-Demand scans.

    My fix for this is to go the policy, settings, turn off "Detect conntrolled application during scheduled and on-demand scans"

    You will stop receiving these "ghost" detections after a couple of hours.