Endpoint Protection

 View Only
  • 1.  Scanning Specific Drives

    Posted Nov 22, 2012 05:49 AM

    Hi I have created a group in SEPM in which i want to scan only the C & D drive, rest of the drivers it should not get scanned. Is it possible if then kindly provide the solution.



  • 2.  RE: Scanning Specific Drives

    Broadcom Employee
    Posted Nov 22, 2012 05:58 AM

    it can be achieved by using custom scan, however you need it to do it on individual machines.



  • 3.  RE: Scanning Specific Drives

    Posted Nov 22, 2012 06:48 AM

    Hello Dear,

    It looks like the only way to do this is to create a custom scan via the client interface. You can't do exactly what you want via the SEPM's Administrator-Defined Scans.

    Scans created via the Client Interface can be set to scan only one drive.
     - Open the SEP GUI > Scan for Threats > Create a new scan > Custom Scan > Check the box next to the drive you want to scan

    Since the SEPM doesn't have a practical way to determine which drive or folder location you want to scan, if you setup a Custom Scan in the SEPM, your options are limited.
     - AV/AS Policy > Administrator-Defined Scans > Add... > OK > Change 'Scan Type' to "Custom Scan" > "Edit Folders..."
     - This scan will rely on the Windows variables for locations that are common to all Windows environments. Unfortunately, it doesn't look like %SYSTEMDRIVE%.

    I have one more idea for the same...

    Do you want to scan only system drive for both auto protect and scheduled scan?

    If yes create a centralized exception for other drives.Then it will scan only system drive even if you give full scan.For this refer this KB
    Creating Centralized Exception policies in Symantec Endpoint Protection Manager.

     

     We have some servers that have many physical drives but we do not want them scanned and thus I had to put in the Drive Letter for each drive.
    Add->Security Risk Exception->Folder
    No Prefix
    Make sure the Check box is checked to include subfolders and put in teh driver letter like below.
    E:\

    Remember that this will exclude these drives from all scans, Admin scans, User scans, Active Scans and PTP Scans.



  • 4.  RE: Scanning Specific Drives

    Trusted Advisor
    Posted Nov 23, 2012 03:39 AM

    Hello,

    It is not possible to configure a scan for a specific drive from SEPM.

    However, you could Configure such scan from the SEP client machine.

    Go to SEP client >> Scan for Threats >> Create scan >> Custom scan, you can specify which drive you want to scan.

    Check this Thread with Similar Query.

    https://www-secure.symantec.com/connect/forums/how-configure-scheduled-scan-only-scan-single-drive

    Hope that helps!!