This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Device Control Policy - Digital Cameras and Cell Phones

Hello All,

We just recently started pushing Sophos Endpoint Protection to all of our client machines and it has been quite flawless.

We have now found a new snag in the setup.  We love the device control features because it stops users from using USB sticks and what not but we do need them to be able to access photos from digital cameras, blackberrys and iPhones.

Currently when you plug in a camera and the Device Control is enabled you are not prompted saying its been blocked or anything it just does nothing.  We need to be able to give users access to these devices in a broad scope.

Is there any way to have this done without adding individual exceptions on a per device basis?  Also when it is "blocked" we don't get an alert or anything in the enterprise console.

Please help me out it would be much appreciated.

:38393


This thread was automatically locked due to age.
Parents
  • Hi All,

    I came across a similar ish issue recently though I did get device control events being reported to the console.

    Hopefully my experience and the resolution will help those who come across this post as I did.

    Our policy is to block removable storage devices from all desktop PCs. However due to pressure from above we were to allow access to digital cameras.

    I set up a device control policy to block access to all storage devices and tested. USB sticks and the like were all blocked and generated a event in the device control log. I tested with two different digital cameras, these were not blocked and did not generate an event. So as this device class did not appear to be monitored by Sophos and allowed access this suited our purpose.

    Having rolled out Sophos I then came across two users who couldnt access their digital cameras. On plugging them in an event was generate and they were blocked. On investigation it turns out that some ( in our case older) cameras are classed as "removable storage" and so Sophos righlty blocks them as per the policy. Some (in our case newer) cameras are picked up as "portable devices", these are not monitored by Sophos and so allows access.

    In our case we excempted the older camera to allow access and all is well.

    As a side note, we previously blocked all devices through the Windows policy @ Computer Config - Admin Templates - System - Removable Storage Access - "All removable Storage classes - Deny All access". On our test machine when this policy was disabled with the device plugged in and Sophos installed it got itself locked somehow. Even removing all active policies it still showed the device as "blocked" (as happens when the policy is in effect). I had to re-install Sophos to remove this, almost as if it locked/conflicted on some level. Likely as the device was still plugged in during the changes.

    Regards,

    Dave

    :39395
Reply
  • Hi All,

    I came across a similar ish issue recently though I did get device control events being reported to the console.

    Hopefully my experience and the resolution will help those who come across this post as I did.

    Our policy is to block removable storage devices from all desktop PCs. However due to pressure from above we were to allow access to digital cameras.

    I set up a device control policy to block access to all storage devices and tested. USB sticks and the like were all blocked and generated a event in the device control log. I tested with two different digital cameras, these were not blocked and did not generate an event. So as this device class did not appear to be monitored by Sophos and allowed access this suited our purpose.

    Having rolled out Sophos I then came across two users who couldnt access their digital cameras. On plugging them in an event was generate and they were blocked. On investigation it turns out that some ( in our case older) cameras are classed as "removable storage" and so Sophos righlty blocks them as per the policy. Some (in our case newer) cameras are picked up as "portable devices", these are not monitored by Sophos and so allows access.

    In our case we excempted the older camera to allow access and all is well.

    As a side note, we previously blocked all devices through the Windows policy @ Computer Config - Admin Templates - System - Removable Storage Access - "All removable Storage classes - Deny All access". On our test machine when this policy was disabled with the device plugged in and Sophos installed it got itself locked somehow. Even removing all active policies it still showed the device as "blocked" (as happens when the policy is in effect). I had to re-install Sophos to remove this, almost as if it locked/conflicted on some level. Likely as the device was still plugged in during the changes.

    Regards,

    Dave

    :39395
Children
No Data