Endpoint Protection

 View Only
  • 1.  App-Policy

    Posted Jul 08, 2013 09:19 AM

    We have Windows 2008 R2 with SEP 12.1.2015 we have created a app policy for blocking *.exe files from USB and by mistake it apply on the my cpmpany group now it apply all servers, pc and dc also now all application including explorer.exe is also blocked and pc and server are not allow to login. Any suggestion how to remove this policy because we cannot login on all pc an servver.

    Thanks

     

     



  • 2.  RE: App-Policy

    Posted Jul 08, 2013 09:21 AM

    But you can login to the SEPM via the remote console, correct?

    Have you withdrawn the policy completely from all group? Or at the very least, put the rule into TEST mode?



  • 3.  RE: App-Policy

    Posted Jul 08, 2013 09:25 AM

    I'm pretty sure that withdrawing or removing policy will not work as it would have blocked smc.exe also....

    create  a new policy, import it manually on the machine

    How to export/import an existing Symantec Endpoint Protection policy



  • 4.  RE: App-Policy

    Posted Jul 08, 2013 09:28 AM

    He says he can't login to anything so not sure how he is going to import than either...

    You can try this from safemode perhaps but this may prove challenging as client functionality is limited. You should be able to remove app/device control component in safemode although it sounds like this affects many machines?

     

     



  • 5.  RE: App-Policy

    Posted Jul 08, 2013 09:29 AM

    Hi

    even we are not able to login to SEPM server then how we can withdrawn

    and how to put the rule into TEST mode

    Thanks

     

     



  • 6.  RE: App-Policy

    Posted Jul 08, 2013 09:35 AM

    Do you have access to a PC that is not affected by this rule? Have you tried booting into safemode and removing the app/device component so you can have a functioning machine?

    You can use the SEPM remote console.

    Access via https://<sepmname>:9090 and download the console and login. However, I'm assuming you have access to a machine not affected by this.

    Once in, you can go to the App/device control policy and select the rule and click the drop down to put into test mode.

    However as Rafeeq mentioned this may not work as well.



  • 7.  RE: App-Policy

    Posted Jul 08, 2013 09:41 AM

    Agreed with Brian.

    Hope it has not blocked windows, in safe mode enable msiexec

    1. Go to (Start) and select (Control Panel)
    2. Select (Uninstall Program) on Vista, Win 7, and 2008 operating systems or (Add/Remove Programs) on older systems.
    3. Select (Symantec Endpoint Protection)
    4. Select (Change) a new window will open
    5. Select (Next)
    6. Select (Modify) and then (Next)
    7. Click on the Plus (+) sign next to (Proactive Threat Protection) to expand it
    8. Click on the arrow icon next to (Application and Device Control)
    9. From the drop down menu select (Entire feature will be unavailable)
    10. Select (Next) and follow through with the wizard.
    11. Reboot the System

    or else Support can help you out.