This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD synchronised groups - some pcs need a different device control policy

Hello,

we have a problem with the policy management in sophos enterprise console. We use the SEC 5.1.0.1839

We have two AD synchronised groups - notebooks and desktop. Now we would like to use the device control policy to block all usb and cd rom drives. We set this policy to the two groups notebook and desktop.

So far so good.

The problem is, if there is one device which needs a usb or cd-rom drive we have no chance to realise this with the policies.

We can not move the device in a other group (because the AD synchronisation) with a different device control policy and we can not apply the device control policy to a device.

How can we allow a pc to use the cd-rom drive or a usb stick?

It would be nice if someone can help me.

Greeting

:37491


This thread was automatically locked due to age.
Parents
  • Hi Jak,

    thanks for your reply.

    yes we need the AD sync to auto deploy the sophos software.

    We have 2 OUs - one for notebooks and the other for desktop pcs. So there is no problem with that.

    I will have a look in the manual for the AD script or is there any good KB article for this solution?

    Greeting

    Steffen

    :37521
Reply
  • Hi Jak,

    thanks for your reply.

    yes we need the AD sync to auto deploy the sophos software.

    We have 2 OUs - one for notebooks and the other for desktop pcs. So there is no problem with that.

    I will have a look in the manual for the AD script or is there any good KB article for this solution?

    Greeting

    Steffen

    :37521
Children
No Data