CD-block through APC
Created: 01 Oct 2012 | Updated: 01 Oct 2012 | 6 comments
Need to create the policy in ADC where user can ready the contain from CD but unable to copy the same contain on the system?
Please suggest?
Discussion Filed Under:
Comments 6 Comments • Jump to latest comment
This is a known limmitation, you will need to follow this:
After setting up an Application and Device Control policy to block CD writing, CD writing is not blocked as expected, and write attempt is not logged
http://www.symantec.com/business/support/index?pag...
SEP Knowledge Base
Endpoint SWAT
Convert the "READ ONLY ACCESS.txt" to "READ ONLY ACCESS.DAT"
All step attach in your attach forum
https://www-secure.symantec.com/connect/forums/need-usb-read-only-access-only-adc
set here as read only ( as mentioned in article)
http://www.symantec.com/business/support/index?page=content&id=TECH104800
ADC policy guidance "Application and Device Control_V1 2.pdf" attach here
Hi,
Try with possible workaround
To work around this problem, create both of the following policies:
Create an Application and Device Control policy that blocks the specific applications that write to CD or DVD drives
Create a Host Integrity policy that sets the following Windows registry key to block write attempts to CD or DVD drives:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer
DWORD NoCDBurning
Decimal Value: 1
If the Explorer Key is not present, add the Key with the DWORD and Value.
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Hello,
Check out this article, this should help -
How to make USB drives read-only with Symantec Endpoint Protection using Application and Device Control
http://www.symantec.com/business/support/index?page=content&id=TECH95813
After setting up an Application and Device Control policy to block CD writing, CD writing is not blocked as expected, and write attempt is not logged
set here as read only ( as mentioned in article)
http://www.symantec.com/business/support/index?page=content&id=TECH104800
You can make CD/DVD read only by editing the USB read only policy (Application Control default policy) and then edit the * in the policy and select CD/DVD.
You need to be aware that CD/DVD ready only is only partially applied using Application Device Control.
Only when CD/DVD writing is done using Windows Writer using EXPLORER.exe then only application control will block it.
If you do it using Nero or any other program SEP will not block it. You will have to block such programs using Application Control.
Check this Thread:
https://www-secure.symantec.com/connect/forums/regarding-policy
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
11. Than Ok.
12. Go to the action Tab in "files and folders Attempts".
13. Select the Read attemps with Allow Access and Create/Delete/Write Attempt with Block Access.
14. Then Ok.
These are the step to create the RO policy for CD/DVD and if you want to RO access with USB Device then select Removable device also
Thanks & Regard
Honey Jack
If your issue has been solved, please use the "Mark as Solution" for the valid thread.
Hi- If your issue is resolve then mark the valid comment as a solution
Would you like to reply?
Login or Register to post your comment.