Hi All,
This is my first SophosTalk Post, so go easy on me :-)
I am currently reviewing how we manage client which appear in Sophos as not having reported back for a while, and the best practise to manage them.
I have been reading this thread:
Which contains some useful steps about how to remove old clients from the SEC, but here's what bothers me;
As far as I can tell, through the SEC, seeing that a client hasn't reported back isn't proof that the client is an old PC which is now off the network, and can be removed from the console, it could be a PC that's got some virus preventing that PC from reporting back to the Sophos server - so removing it from SEC not only means you don't have a true licence count, but also means you may have a PC on your network that is infected.
I inherited our AV service about a year ago, and my predecessor had created some clever scripts that compared the last time a client had reported back to when the client was last seen on the network. If both were over a set amount of time, we could safely remove them from the console, but if a client was on the network recently but not reporting back to sophos, we knew we had a problem!
These scripts don't work any more because they relied on a browsing function on our domain which has now been deactivated - so I'm trying to figure out what others do....
Are we going way over the top here?!
Regards,
Ben
This thread was automatically locked due to age.