kennysarmy Posted March 9, 2018 Posted March 9, 2018 As I understand it, the sophos device control policies are machine policies. We have the enterprise console on a local server that links to AD, but it only allows us to sync computer OUs to Sophos groups. It sounds like you have a slightly different setup, so you might have more user based options than us though. Yes we're in the cloud! Just reading up on an AD Sync utility you can stick on your DC which can map users/groups etc to the cloud - that might then allow us to be more granular in our policies.
leeshellard Posted March 9, 2018 Posted March 9, 2018 Yes we're in the cloud! Just reading up on an AD Sync utility you can stick on your DC which can map users/groups etc to the cloud - that might then allow us to be more granular in our policies. We use cloud too and have the AD sync you can then set policies based on AD groups or users. Sync is easy to set up.
kennysarmy Posted March 12, 2018 Posted March 12, 2018 We use cloud too and have the AD sync you can then set policies based on AD groups or users. Sync is easy to set up. Think I've just sorted out. Will do a bit of testing today with some policies but the groups are syncing. Only issue is I've not used LDAP over SSL as I don't know how to sort out the certificate part - any help appreciated.
korifugi Posted March 12, 2018 Posted March 12, 2018 We allow them, but use Bitlocker - applied by GP. Quite often it throws members of staff saying "It's full but I've only just bought it" (and those that have Macs at home don't like it)
gshaw Posted March 12, 2018 Posted March 12, 2018 Encrypted for now via GPO (for staff only, no restrictions for students). Eventually would prefer to drop completely but have to manage the process to avoid user outcry.
Bev Posted March 12, 2018 Posted March 12, 2018 Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that?
Rob_D Posted March 12, 2018 Posted March 12, 2018 Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that? If you're using google or Onedrive you might be able to stop downloading (onedrive and rights management/ Azure information protection should be able to do this). But at some point it's got to just become a training policy issue.
free780 Posted March 12, 2018 Posted March 12, 2018 Windows Information Protection can prevent uploads to cloud services. It is not supported on shared devices only 1:1.
enjay Posted March 13, 2018 Posted March 13, 2018 Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that? Training and frequent reminders. 1
korifugi Posted March 13, 2018 Posted March 13, 2018 Training and frequent reminders. ...and a mighty big 'clue bat'.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now