This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos and Local Security Groups

Hey,

I have been looking at the Local Security Groups created by Sophos.

I have read the descriptions and I think I am clear on what each group allows it's members to do. However, I am not entirely sure of what role they play in the overall functionality of the Sophos software itself.

I have been searching for some documentation on exactly how these groups are used and what the difference is between the Domain accounts and the Local accounts, but I have been unsuccessful.

I was wondering if anyone knows of a document that explains them?

I was wondering how they are populated? Are they populated by automatically? I think they are because on almost all our machines the user that uses the PC is in the SophosAdministrators. 

Do these groups play a role in the ability for virus's to be cleaned off the system? Let's say if a "Cleanup" was issued from the SEC, do these groups have to be populated by specific users in order for the "Cleanup" to be successful?

I want to make sure they are being used properly. We are not experiencing any issues, but I want to make sure I'm understanding their functionality and role correctly!

Thank you, 

:17213


This thread was automatically locked due to age.
Parents
  • Glad it helped to clarify a few things.  Tasks pushed down by SEC run as local system.

    You will notice for example, that if you perform a scan from SEC this will run under the local system context.  In this example you can see the task in the endpoint GUI running as local system.  Same with scheduled scans, these "Enterprise scans" also run as system.

    Regards

    Jak

    :17271
Reply
  • Glad it helped to clarify a few things.  Tasks pushed down by SEC run as local system.

    You will notice for example, that if you perform a scan from SEC this will run under the local system context.  In this example you can see the task in the endpoint GUI running as local system.  Same with scheduled scans, these "Enterprise scans" also run as system.

    Regards

    Jak

    :17271
Children
No Data