Hi,
By default Sophos UTM's Endpoint Antivirus enables the detection of Suspicious Behaviour, however there is no option to enable the detection of 'suspicious files' on-access via the Sophos UTM Web Admin. It is possible to enable detection of 'suspicious files' from the settings within Sophos Antivirus on the endpoints themselves (Configure --> Anti-Virus --> On-Access Scaning --> Enable scan for... suspicious files) , however when I change the settings to enable the detection of 'suspicious files' on the endpoints manually, I find that this policy change is being overwritten by the Sophos UTM policy (which does not give an option to enable/disable detection of suspicious files).
Is there any way to enable the detection of suspicious files via the Sophos UTM, or is there a way of causing the policy set on the endpoints to retain the suspicious files detection setting?
thanks,
Richard
This thread was automatically locked due to age.