Endpoint Protection Small Business Edition

 View Only
  • 1.  Application and Device Control

    Posted Jan 21, 2015 09:10 PM
    Hi everyone,
     
     
    I have two objectives in setting up application and device control in SEPM 1) Prevent users from installing additional computer programs 2) Prevent users from using external data storage via USB port.
     
    CONCERNS :
     
    1. For application control, I was able to set a policy in preventing users from installing additional computer program in their respective computers. The policy excludes Microsoft related updates.  Is it possible to exclude other software updates like for browsers and Java?
     
    2.  For the device control, I would like to block the use of any external data storage so I selected the following hardware device control in the list: USB, IDE, Smart Card Readers and Storage Volumes.  During my test I encountered an access problem.  I was able to identify why excluded devices still being blocked by SEP.  The "Storage Volume" device name enables blocking of USB flash drive even though it is in the list of excluded devices.  Storage Volume identification is not the same with my USB flash drive.  Why is my USB flash drive being blocked if I add "Storage Volume" in the list of blocked devices?  


  • 2.  RE: Application and Device Control

    Posted Jan 21, 2015 09:15 PM

    Yes, you can just set the java executable name in the box to not not apply to the following processes.

    And your USB as well has been excluded?



  • 3.  RE: Application and Device Control

    Posted Jan 21, 2015 09:37 PM

    Yeah, I tried to exclude my USB but it's still blocked. 



  • 4.  RE: Application and Device Control
    Best Answer

    Posted Jan 21, 2015 09:51 PM


  • 5.  RE: Application and Device Control

    Posted Jan 21, 2015 10:43 PM

    Thak you Sir Brian for this info. Much appreciated. 



  • 6.  RE: Application and Device Control

    Posted Jan 22, 2015 07:54 AM

    You're welcome.