Endpoint Protection

 View Only
  • 1.  How can I send a message to SEP client

    Posted Feb 11, 2015 08:52 PM

    In our SEPM 12.1.2015.2015, some unknown client can connect back to SEPM, but we cannot find the owner by last logon user or IP or computer name. Can I trigger/send a message to this SEP client and notify them to contact us, so that we will know who is the owner of this client?

    Seems only when risk found or definition is outdated(over 7 days), there will be customized notification can be sent to client. But these clients is up-to-date

    Thanks



  • 2.  RE: How can I send a message to SEP client

    Posted Feb 11, 2015 08:55 PM

    There is no way to do a customized notification like this. Only in terms of a risk being found, such as blocking an application with the firewall or application and device control policy. Or what you mentioned.

    I guess you could just block an application like explorer.exe with ADC and have it notify the user :)

    Really this is outside the scope of what SEP is intended to do.



  • 3.  RE: How can I send a message to SEP client

    Posted Feb 11, 2015 11:14 PM

    No,It's not possible fo sepm send notifiation.

    have you check computer status report,may be you can find user last login name.



  • 4.  RE: How can I send a message to SEP client

    Posted Feb 12, 2015 05:46 AM

    "Thumbs Up" to Brian!

    As he's mentioned, it's a bit outside the purpose of A&DC, but it is possible to setup a app control rule to notify the user on whatever app control event you choose.

    Another option is using HI policies (if you have SNAC installed/enabled or are willing to upgrade to 12.1RU5), which can then be used run any sort of script you want.