Endpoint Protection

 View Only
  • 1.  SEPM policy

    Posted Nov 28, 2013 06:10 AM

    Dear All,

    Today I made a policy in my SEPM about block USB devices, and I just checked and found that this policy is not working in safe mode. I dont know whether I have created policy properly or not, How can I check it. and If this policy is wrong then kindly provide setting so that i can block in safe mode also.



  • 2.  RE: SEPM policy
    Best Answer

    Posted Nov 28, 2013 06:15 AM

    Hi Yshirodkar,

    Auto-Protect would not run in Safe Mode and does the Application and Device Control.

    The Application and Device control drivers will automatically disable themselves in the event that they see they are running in safe mode

    Check these Threads:

    https://www-secure.symantec.com/connect/forums/application-and-device-control-not-working-under-safe-mode

    https://www-secure.symantec.com/connect/forums/need-block-usb-safe-mode-safe-mode-networking

    https://www-secure.symantec.com/connect/forums/safe-mode

     



  • 3.  RE: SEPM policy

    Posted Nov 28, 2013 06:21 AM

    Does it work in Normal mode, if yes then all your policies are correct.

    safe mode runs with minial services. thats why its not blocking



  • 4.  RE: SEPM policy

    Posted Nov 28, 2013 06:30 AM

    Rafeeq : Yes sir this policy is properly working in normal mode.

     

    Rash_m  : I am going through with your above post.



  • 5.  RE: SEPM policy

    Posted Nov 28, 2013 07:07 AM

    Hi,

    SEPM policy are not working in safe mode.

    Safe Mode only troubleshooting purpose if you want to block USB on safe mode you can use GPO.

    Safe Mode -Access block Utility

     

    https://www-secure.symantec.com/connect/ideas/safe-mode-access-block-utility



  • 6.  RE: SEPM policy

    Broadcom Employee
    Posted Nov 28, 2013 07:33 AM

    whats the policy you referring to?

    as stated above the ADC policy or service is not started in safe mode.



  • 7.  RE: SEPM policy

    Posted Nov 28, 2013 08:06 AM

    It won't work in safe mode, this is by design.



  • 8.  RE: SEPM policy

    Posted Nov 28, 2013 09:50 PM

    Hello,

    Sep Policy is work only in Normal Mode as per design. Safe Mode is use for troubleshooting part that why Sep client and policy not work because if it can enable in safe mode then while using the troubleshoot tool it create issue in running.

    It only disable through group policy. If you want to disable use the same option.

    Check the below thread

    https://www-secure.symantec.com/connect/forums/need-block-usb-safe-mode-safe-mode-networking

     



  • 9.  RE: SEPM policy

    Posted Nov 28, 2013 11:14 PM

    Hi

    ADC policy works in normal mode and in safemode the NTP drivers does not gets loaded and so you the USB does not gets block.  This is by design

    Regards

     



  • 10.  RE: SEPM policy

    Posted Nov 29, 2013 05:35 AM

    Thank u all for ur great support.