This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Device Control Policies and AD Containers

We currently have an AD structure that organizes PCs by department and then has a subcontainer for USB exception. We currently control USB policies by group policy, but would like to switch over to Sophos Device Control to get more granular with device type/SN. If we have a device control policy to block at the department level, does the device control policy to allow (the subcontainer level) get superceded by the one to block?

:51584


This thread was automatically locked due to age.
Parents
  • Hello Nansterz,

    each console group (no matter how it has been created, whether it is synched or not) has its own set of policies policy assignments. At subgroup creation time these are set to the parent's.

    Please note that changes to a policy apply to all groups using this policy while applying a different policy does not propagate to subgroups.

    HTH

    Christian

    :51626
Reply
  • Hello Nansterz,

    each console group (no matter how it has been created, whether it is synched or not) has its own set of policies policy assignments. At subgroup creation time these are set to the parent's.

    Please note that changes to a policy apply to all groups using this policy while applying a different policy does not propagate to subgroups.

    HTH

    Christian

    :51626
Children
No Data