This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

block users from changing the settings on endpoint 10 desktop agent

how can I block users from changing the settings on endpoint 10 desktop agent?

thanks

:26149


This thread was automatically locked due to age.
  • Hello nml,

    I'm not sure I understand correctly what you mean by desktop agent . If you mean the Sophos Endpoint Security and Control GUI - which settings do you want to be protected from being changed?

    Christian

    :26151
  • sorry I do mean the desktops endpoint security and control. I have enabled tamper protection but can still access the fireweall and av settings and i want to disable this on the server

    :26155
  • So the users have administrative rights on the machines (BTW: Is this an AD environment)?

    With Tamper Protection enabled only parts of the configuration should be accessible without authentication. For AV these are On-demand extensions and exclusions and Right-click scanning (as these scans are explicitly requested by the users it's in their interest to have reasonable settings anyway), Authorization (as e.g. installers may sometime trigger detections and administrators should be able to bypass this) and Scans. As far as On-Access scanning goes, they should not be able to make changes (except for Authorization).

    SCF is a different matter. Right now it is not covered by Tamper Protection as the consequences of totally locking in the settings have to be considered carefully. It might come (especially if there is sufficient interest - so you should perhaps submit a feature request through Support).

    As an aside - Web Control settings were initially "open". I (and perhaps others) have questioned this and as far as I can see the are now also subject to TP.

    Christian   

    :26159
  • this is a ad enviroment.

    basically we have the web filtering disabled.

    we have set a firewall policy which we don't want uses to alter and it seems they can on the endpoint security and control gui. They can also configure the av and hips which i would like to disable.

    The only feature I would like them to be a ble to use really is the scan feature

    :26161
  • AV and HIPS should be out of reach - you say they can change the on-access settings?

    Christian

    :26165