This issue has been solved.

Application and device Control (ADC) with Windows 7

Created: 13 Oct 2012 | Updated: 16 Oct 2012
Login to vote
0 0 Votes

Dear All

I using SEP 11.x and have been config ADC funtion. I see that device control function not effected for windows 7 but windows XP is OK. Example : I banned the use of usb device=>result :

  • For windows XP : OK, not dectech when user plug USB device port
  • For windwos 7 or vista : not OK. still used USB device

can you help me this issue

Thanks/Duy

Quick Look Solution

Thanks all very much..! This

Thanks all very much..! This problem sloved

Filed Under

Comments

Ashish-Sharma
Accredited
13
Oct
2012
Votes
0

As I suspect you may have

As I suspect you may have Windows 7 x64 machines, keep in mind Application and Device Control module is not compatible with 64bit environement if you are using SEP 11.0.

SEP 12.1 Application and Device Control module is however compatible with 64bit systems.

Please refer to the article below:

http://www.symantec.com/docs/TECH102267

https://www-secure.symantec.com/connect/forums/how-block-usb-using-sepm-windows-7

https://www-secure.symantec.com/connect/forums/sep-64bit-os-supported

https://www-secure.symantec.com/connect/forums/64-bit-systems-usb-block

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

pete_4u2002
Symantec Employee
13
Oct
2012
Votes
0

whats the SEP version

whats the SEP version used?

what is the OS bit?32/64?

 

13
Oct
2012
Votes
0

Hi Pete SEP version used : 

Hi Pete

SEP version used :  11.0.7200.1147

OS : windows 7 professinal 32 bit service pack 1

Thanks/Duy

Ashish-Sharma
Accredited
13
Oct
2012
Votes
0

Hi, Check SEP policy are

Hi,

Check SEP policy are applied or not ?

Try to create new package and install one system and check policy are apply or not

Check this

After setting up an Application and Device Control policy to block CD writing, CD writing is not blocked as expected, and write attempt is not logged

http://www.symantec.com/business/support/index?page=content&id=TECH104800

Please note that Windows 7 and Vista do not have the process IMAPI.exe, the feature they use is IMAPIv2.0.This feature uses dll  files in both windows vista and windows7.The IMAPI service that existed in Windows XP was not used for Vista and windows7. Hence there is no service interfering with 3rd party software that we can disable.However,we can locate and block "launch process attempts" for the associated dll(s)

NOTE : For Windows 7 OS you can use following file fingerprint value as Windows 7 dose not use imapi.exe, it uses imapiv2.0. This feature uses .dll files. 

*Values listed below are for Windows 7 SP1. Values can change after applying new service packs.

 Widnows 7 32bit OS:

For imapi.dll file the value is 55d9803fd821c293d97614c39e6603d4
For imapi2.dll file the value is 2d11bc8b460957e62e4420373a0d8bda
For imapi2fs.dll file the value is 7a82634c75cd12efcf43897a2e28ce
 
Windows 7 64bit OS:
For imapi.dll file the value is A259E4991C9C422895B944BEABB9799F
For imapi2.dll file the value is 8B886A0AC14EAA8599142887991A5A2E
For imapi2fs.dll file the value is D47180120A4F8EE4076920DA07577729
 
 

 

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

Brian81
Trusted Advisor
Certified
13
Oct
2012
Votes
+1

For Win7, you need to upgrade

For Win7, you need to upgrade to SEP 12.1 so it is compatible.

 

Symantec Endpoint Protection 11.0 compatibility with 64-bit platform

http://www.symantec.com/business/support/index?page=content&id=TECH102143&locale=en_US

Sumit G
Accredited
Certified
14
Oct
2012
Votes
0

Create a test group and try

Create a test group and try the policy as per attached document

https://www-secure.symantec.com/connect/downloads/...

Move the window 7 clients in the same group and check the result.

If it come help then implement in production

Regards

Sumit G.

Mithun Sanghavi
Symantec Employee
Accredited
15
Oct
2012
Votes
0

Hello, Could you make sure

Hello,

Could you make sure the Network Threat Protection and Application & Device Control are installed on the Windows 7 32 bit machines.

Secondly, also make sure these ADC policies are applied to the same group where these Windows 7 clients reside.

What happens if you disable the UAC on the Windows 7 machines?

Again,  

Here are the Steps to block the USB Drives -

1. First you have start and logon to “Symantec Endpoint Protection Manager”

2. In the main windows | tool bar select: “Policies” | Hardware Devices | right click and ADD

3. In Device Name write “USB Storage” and Device ID “USBSTOR*.*” | OK 

4. Then click inside “Application and Device Control” in the main menu and then right click inside “Application and Device Control” and Edit. 

5. Device Control | Blocked Devices and click Add

6. Select “USB Storage” and click OK

7. Active Notification: Mark: “Notify users when deviced is blocked”, click “Specify Message Text” ) | add messange | OK (c) and click OK.

8. To assign to the policy just click in “ASSIGN”

9. Select the group to be applied and click “Assign”

10. Done the policy will updated to all workstation member of this group.

 

Check these Articles:

How to Block or Allow Devices in Symantec Endpoint Protection

http://www.symantec.com/docs/TECH175220

How to block USB Thumb Drives and USB Hard Drives, but allow specific USB Drives in the Application and Device Control Policy in Symantec Endpoint Protection.

http://www.symantec.com/docs/TECH106304

How to block USB Keys with SEP

http://www.symantec.com/docs/TECH106361

Hope that helps!!

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3

Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a

Sumit G
Accredited
Certified
16
Oct
2012
Votes
0

Hi Have you try the attaach

Hi

Have you try the attaach link?

Regards

Sumit G.

16
Oct
2012
Votes
0
SOLUTION

Thanks all very much..! This

Thanks all very much..! This problem sloved

Ashish-Sharma
Accredited
16
Oct
2012
Votes
0

HI, Can you provide what's

HI,

Can you provide what's the solution.

Your answer help some one

Thanks In Advance

Ashish Sharma

SEPM Knowledgebase Documents  

 

17
Oct
2012
Votes
+1

Hi all Before I configed as

Hi all

Before I configed as bellow

That configed only effected for windows XP . windows 7 is not effected . I don't know why. can you explain ?

After I re-config as bellow :

After config I see effected both Windows 7 32 bit and Windows XP

That's my experience ..! sharing to you

Thanks/ phamduyus

Mick2009
Symantec Employee
06
Nov
2012
Votes
0

"Thumbs up" for adding that

"Thumbs up" for adding that information!  &: )

This may also be of help to admins with the same situation / sort of question:

Best Practices for Deploying Symantec Endpoint Protection's Application and Device Control Policies 
Article URL http://www.symantec.com/docs/TECH145973 
 

With thanks and best regards,

Mick