This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Device Control Policies and AD Containers

We currently have an AD structure that organizes PCs by department and then has a subcontainer for USB exception. We currently control USB policies by group policy, but would like to switch over to Sophos Device Control to get more granular with device type/SN. If we have a device control policy to block at the department level, does the device control policy to allow (the subcontainer level) get superceded by the one to block?

:51584


This thread was automatically locked due to age.
Parents
  • Hello Nansterz,

    re-structure the AD groups {and in the first post} AD structure that organizes PCs by department and then has a subcontainer for USB exception

    hm, I'm not sure if I understand you correctly (and apart from this there are some details to be filled out):

    You current AD structure groups the computers by department and each department (at least where required) has a subgroup for exceptions - is that so? Not explicitly stated but to me it sounds like the SEC groups mirror the AD structure - do they? If so, then you should be fine. The "common" computers from the Department X OU would be in SEC group DeptX to which you assign a block policy. The computers in the subcontainer would go to DeptX-Ex which has a policy with exceptions. Please note that the policies are completely independent - policies are neither merged nor is more than one policy (of the same type) applied to a computer.

    Christian 

    :51760
Reply
  • Hello Nansterz,

    re-structure the AD groups {and in the first post} AD structure that organizes PCs by department and then has a subcontainer for USB exception

    hm, I'm not sure if I understand you correctly (and apart from this there are some details to be filled out):

    You current AD structure groups the computers by department and each department (at least where required) has a subgroup for exceptions - is that so? Not explicitly stated but to me it sounds like the SEC groups mirror the AD structure - do they? If so, then you should be fine. The "common" computers from the Department X OU would be in SEC group DeptX to which you assign a block policy. The computers in the subcontainer would go to DeptX-Ex which has a policy with exceptions. Please note that the policies are completely independent - policies are neither merged nor is more than one policy (of the same type) applied to a computer.

    Christian 

    :51760
Children
No Data