Disabling User Access to Disable Symantec Endpoint Protection
Created: 10 Jan 2008 | Updated: 21 May 2010 | 8 comments
I have the lastest SEP realease 11.0.1000.1375 installed. I would like to remove the ability for the user to right-click on the SEP icon and disable Symantec Endpoint Protection. I am running into the following issue however.....
No matter how many features I lock I cannot get the Network Threat Protection to remove it's disable feature. All other services have been locked and their disable feature is not available (as expected), but since the Network Threat Protection freature is not disabling this is causing the client to still have the ability to right-click and disable protection. It's true that it is only disabling the Network Threat Protection, but it is really annoying that it is there at all.
For the life of me I cannot find an option to get rid of this. At this point I've even got all the controls unlocked, and I cannot even change settings on the Network Threat Protection.... It tells me that I have locked this feature.
I also have noticed that in my firewall rules policy config the "Inherit Firewall Rules from Parent Group" check box is disabled and not checked.
Any help on getting this Feature to work would be appreciated. At this point I am lost. Please help.
Discussion Filed Under:
Comments 8 Comments • Jump to latest comment
Im having the same problem. Ive unchecked the box but when I update the policy via the client or the server it does not disable this feature?
Hi!!
We have choosen not to allow users to stop sep client too using SEP manager interface, but because a lot of them have administrators rights, they still can stop it through windows services panel, so we have determined to secure them through GPO.
We think that assigning privileges as shown is sufficient (we are not using Network access control). All the startups/shutdowns shown into the logs are done by System account.
Service: Startup Type Rights
Symantec Auto-upgrade Agent Manual System/ Domain Admins/IT Support
Symantec Endpoint Protection Automatic System/ Domain Admins/IT Support
Symantec Event Manager Automatic System/ Domain Admins/IT Support
Symantec Management Client Automatic System/ Domain Admins/IT Support
Symantec Network Access Control Manual System/ Domain Admins/ITSupport
Symantec Settings Manager Automatic System/ Domain Admins/IT Support
I have tried to lock down the services as described but now my clients are reporting into the console with their "Antivirus Engine Off" even though the clients are running fine. Any ideas?
Check if this helps:
How to block user's ability to disable Symantec Endpoint Protection on Clients
http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110514540148
I followed this document word by word ... Helped me in my case .... :smileyhappy:
Would you like to reply?
Login or Register to post your comment.