Endpoint Encryption

 View Only

SEE agent does not respond to GPO settings

  • 1.  SEE agent does not respond to GPO settings

    Posted Apr 19, 2018 11:57 AM

    Hello and thank you for taking the time to read through this, I will try my best to keep it short and sweet. 

    ​We are running Symantec Endpoint Encryption 11.1.3. Our agent has default settings to force full disk encryption and push the Media tools to any Removable Media that gets plugged into it such a flash drive. This works splendidly.

    ​However, I am being asked to create a policy that does not force the encryption on the removable media. From my understanding this should be doable through a tweaked SEE GPO and then just restrict it to a certain group. This should override the settings on the agent themselves. However so far I have not seen this work. The GPO policies don't seem to influence the agent if the settings differ from what the agent installs with my default.

    ​Is there a particular setting or best practice or anything I am missing here? I thought it was pretty straight forward, so I am hoping I am just being dumb about it and missing something easy. Any assistance would be greatly appreciated. Thank you!