Need to USB Read only access only with ADC.
Created: 02 Oct 2012 | 21 comments
Can you please help me to give the USB Read only access through ADC policy?
User can read contain from USB but may not able to copy from USB to the system?
Need to do only with ADC policy?
Please help.
Discussion Filed Under:
Comments 21 Comments • Jump to latest comment
How to make USB drives read-only with Symantec Endpoint Protection using Application and Device Control
http://www.symantec.com/business/support/index?page=content&id=TECH95813
Check this thread Also
https://www-secure.symantec.com/connect/forums/usb-device-read-only
https://www-secure.symantec.com/connect/forums/how-prevent-reading-files-sepm-121
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi
Find the attach file with name of "READ ONLY ACCESS.txt"
Copy it and rename with READ ONLY ACCESS.Dat
Import the file in the application and device control.
Process to import
Login the Console
Go to Policies Tab
Select the "Application and Device Control"
Select the "Import an Application and Device Control" Add the policy "READ ONLY ACCESS.Dat"
Snap for the guidance
hi hj1979,
Thanks to response but this policy is not working as my requirement’s .I can easily copy the file from USB to my desktop.
Thanks & Regards,
Nagesh Singh
HI,
This is not possible.
If you want not copy any data you can full block USB drive.
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi nagesh,
Read only policy mean that you can't able to paste any thing in USB device but easily to copy that data in to systems.
RO help to safe the information and no one able to copy the data in usb device.
Hi,
Go through the following article
How to make USB drives read-only with Symantec Endpoint Protection using Application and Device Control
http://www.symantec.com/docs/TECH95813
Chetan Savade
Technical Support Engineer, Endpoint Security
Enterprise Technical Support
CCNA | CCNP | MCSE | SCTS |
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.&
Hello,
Check out this article, this should help -
How to make USB drives read-only with Symantec Endpoint Protection using Application and Device Control
http://www.symantec.com/business/support/index?page=content&id=TECH95813
After setting up an Application and Device Control policy to block CD writing, CD writing is not blocked as expected, and write attempt is not logged
set here as read only ( as mentioned in article)
http://www.symantec.com/business/support/index?page=content&id=TECH104800
You can make CD/DVD read only by editing the USB read only policy (Application Control default policy) and then edit the * in the policy and select CD/DVD.
You need to be aware that CD/DVD ready only is only partially applied using Application Device Control.
Only when CD/DVD writing is done using Windows Writer using EXPLORER.exe then only application control will block it.
If you do it using Nero or any other program SEP will not block it. You will have to block such programs using Application Control.
Check this Thread:
https://www-secure.symantec.com/connect/forums/regarding-policy
Hope that helps!!
Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | MCTS | STS | ITIL v3
Twitter: @mithun_sanghavi
Don't forget to mark your thread as 'SOLVED' with the answer that best helps you.<&a
Dear mithun,
Thanks to response but this policy is not working as my requirement’s .I can easily copy the file from USB to my desktop.
I want user can read to contain from USB or from CD but if they are trying to copy from USB to system it must get block through ADC.(Want to block only with Application and Device control policy).
Thanks & Regards,
Nagesh Singh
11. Than Ok.
12. Go to the action Tab in "files and folders Attempts".
13. Select the Read attemps with Allow Access and Create/Delete/Write Attempt with Block Access.
14. Then Ok.
Thanks & Regard
Honey Jack
If your issue has been solved, please use the "Mark as Solution" for the valid thread.
Hi- If your issue is resolve then mark the valid comment as a solution
Daer All,
Yet this issue has not been resolve?
Any help would be appreciated.
Thanks & Regards,
Nagesh Singh
Hi,
This is not possible.
If you want not copy any data you can full block USB drive.
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
can we do with HI Policy.
I want user can Read the data but can't copy the same data to System?
Thanks & Regards,
Nagesh Singh
DLP agent might help to some extent.
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
Hi,
I am not sure you can try .
http://www.symantec.com/business/support/index?page=content&id=HOWTO11091
https://www-secure.symantec.com/connect/articles/sep-and-snac-unbeatable-combination
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Hi All,
We have raised the same case in Symantec and they told us this is not possible only through ADC policy.
I have gone through the entire article which you guys given me above but nothing works.
Is anyone having more idea about it?
Thanks & Regards,
Nagesh Singh
HI,
We have already told your requirement not possible in SEP ADC policy.
Thanks In Advance
Ashish Sharma
SEPM Knowledgebase Documents
Create a new ADC policy -->add file and folder rule --->add-->put * for files and folder-->and select removable drive and cd/DVD drive against only match file and folder-->ok-->go to action tab-->select continue processing for read attempt -->and block for write attempt.
Hi Riya31,
I did it but I am very much able to copy the file from USB to my Desktop.
Thanks & Regards,
Nagesh Singh
did you try DLP agent, does that help?
Cheers!
Pete
Help Link: http://www.symantec.com/business/support/overview.jsp?pid=54619
Hi pete_4u2002,
We do not vave DLP in my environment.
Thanks & Regards,
Nagesh Singh
Would you like to reply?
Login or Register to post your comment.