Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No live user displayed for Intercept X Advanced for Server

I have recently noticed that all our servers with Intercept X Advanced for Server do not show the 'user' details in the logs and any user based firewall rules fail (obviously). This is with a user logged in via Remote Desktop.

These are domain joined servers, they have a heartbeat but nothing appears in the authentication log. Windows 10 workstations with Intercept X Advanced work fine. I am running the latest version of Sophos XG (SFOS 18.5.1 MR-1-Build326)

Is this a limitation of the Server version of Intercept X or is there something else going on?



This thread was automatically locked due to age.
Parents Reply
  • Thanks that's the info I needed and can confirm that it is now working. Not sure why the Server version should be so different.

    I'm also a bit surprised that this question hasn't come up before but I spent quite a bit of time searching the forum and didn't find anything.

    As a tip for anybody who needs to do the same and comes across this post, I would suggest you add 'local service', 'network service' and 'system' to the excluded users or you end up with a lot of recurrent authentication failures in the authentication log.

    The format for the reg entry is:
    reg add "HKLM\Software\Sophos\Sophos Network Threat Protection\Application" /v SatcExcludedUsers /t REG_MULTI_SZ /d "network service"\0"system"\0"local service"

Children
No Data