This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD synchronised groups - some pcs need a different device control policy

Hello,

we have a problem with the policy management in sophos enterprise console. We use the SEC 5.1.0.1839

We have two AD synchronised groups - notebooks and desktop. Now we would like to use the device control policy to block all usb and cd rom drives. We set this policy to the two groups notebook and desktop.

So far so good.

The problem is, if there is one device which needs a usb or cd-rom drive we have no chance to realise this with the policies.

We can not move the device in a other group (because the AD synchronisation) with a different device control policy and we can not apply the device control policy to a device.

How can we allow a pc to use the cd-rom drive or a usb stick?

It would be nice if someone can help me.

Greeting

:37491


This thread was automatically locked due to age.
Parents
  • Hi Jak,

    thanks for your great help!!

    I have one last question. In the AD script it is necessary to add the install user and password.

    I dont want to use the domain administrator for the installation. If i create a new user, is it necessary to to add this "install user" to the domain administration group?

    :37577
Reply
  • Hi Jak,

    thanks for your great help!!

    I have one last question. In the AD script it is necessary to add the install user and password.

    I dont want to use the domain administrator for the installation. If i create a new user, is it necessary to to add this "install user" to the domain administration group?

    :37577
Children
No Data