Video Screencast Help
Symantec to Separate Into Two Focused, Industry-Leading Technology Companies. Learn more.

Application Control with withdrawn policy

Created: 05 Feb 2013 | 7 comments
diabolicus23's picture

If I deploy a client with the App & Device Control feature but I put that client in a group where I've withdrawn the App & Device Control, why I see (in the monitor section in SEPM) that App & Device Control is blocking something?

I thought that withdrawing a policy I set something like "passthrough"... Am I wrong?

Comments 7 CommentsJump to latest comment

.Brian's picture

it should. Did the client apply the newest policy you made the change to?

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

Ashish-Sharma's picture

HI

After the withdrawing a ADC policy not applied in sep client ..but if new policy are applied on that particular group.

Thanks In Advance

Ashish Sharma

.Brian's picture

Did you reboot the client first?

What exactly is being blocked? A rule from the ADC policy that you created?

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

diabolicus23's picture

Stop stop stop stop... I'm a fool smiley

The monitor section (even with details) does not report this but... the export was really useful wink

It's the tamper protection (enabled) and not the AppControl itself.
I've just discovered that tamper protection is not immediatly recognizable via monitor but I've to export the entries... good to know.

.Brian's picture

Ahh, haha, yep tamper protection is part of the application events so it will show up in the same log as ADC events...cool

Please click the "Mark as solution" link at bottom left on the post that best answers your question. This will benefit admins looking for a solution to the same problem.

SebastianZ's picture

Yes, that would be it - as you mentioned if the ADC policy is being withdrawn - ADC will be in pass-through mode allowing everything.