Endpoint Protection

 View Only
  • 1.  Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 20, 2013 03:04 PM

    Hi,

    My environment is SEP 12.1 on Windows 7.  Policies that block or quarantine are working properly when a logged in user is a non-admin.  However, if a local admin logs into the same machine and tries to access the same app or file, SEP does not block or quarantine the file.  How does one make sure that SEP policies work the same for non-admin and admin users?

     

    Thanks.

     

    Bob



  • 2.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 20, 2013 03:11 PM

    is this for a file that is considered a virus by SEP? I'm not sure why the non-admin/admin part would matter. If SEP detects a virus, it should take action regardless of what type of permissions the users have.



  • 3.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 20, 2013 03:22 PM

    What kind of policies are you talking about? AV, ADC?



  • 4.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 21, 2013 06:44 AM

    Hi

    Can you please elaborate the policies you have configured

    Regards

     



  • 5.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 21, 2013 07:05 AM

    I Guess  have Configured Location Based Policy, if yes then yes the  Local Admin and user will have Different Polcies. Please read here

    http://www.symantec.com/business/support/index?page=content&id=HOWTO80772&actp=search&viewlocale=en_US&searchid=1361448205962



  • 6.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 21, 2013 09:15 AM

    For example, we have an application and device control policy in place that blocks access to .lnk files.  This policy is a template that was copied from Symantec.  One of my colleagues has two accounts, one that has local admin rights and the other does not.  If he is logged into that computer as a non-admin, the policy correctly prevents him from accessing a .lnk file on a network share.  However, when he logs in as a local administrator, he is able to access the .lnk.  



  • 7.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 21, 2013 09:30 AM

    have your configured the User mode.Does it work if you reboot and login? or do smc -stop and smc -start?



  • 8.  RE: Policy behaviour changes depends on whether logged in user is local admin or not

    Posted Feb 21, 2013 09:40 AM

    Machines are in computer mode.