This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Automated reaction to "Differs from policy" possible?

Hi all,

as the administrator, you receive a message and you see in the SEC, that one or more computers differ from group policy, e.g. they have deactivated the On Access Scan.

Is there a way to automatically react to this situation, i.e. to make the server execute the "Comply with"-action by itself?

Thanks

Regards,

Michael

:29087


This thread was automatically locked due to age.
Parents
  • Hi,

    In terms of SAV, there are reg values under the following key:

    HKLM\Software\[wow6432node]\Sophos\SAVService\Status\

    that could be assessed to determine if the local adapter storage could be removed and the agent service restarted.

    E.g. As a system startup script (AD based), a script could check the above registry key(s), if not-complies, then delete the relevant adpater storage file and restart the agent service, within 20-25 seconds the client should get a policy.

    Cheers,

    Jak

    :29103
Reply
  • Hi,

    In terms of SAV, there are reg values under the following key:

    HKLM\Software\[wow6432node]\Sophos\SAVService\Status\

    that could be assessed to determine if the local adapter storage could be removed and the agent service restarted.

    E.g. As a system startup script (AD based), a script could check the above registry key(s), if not-complies, then delete the relevant adpater storage file and restart the agent service, within 20-25 seconds the client should get a policy.

    Cheers,

    Jak

    :29103
Children
No Data