Jump to content

Recommended Posts

Posted
As I understand it, the sophos device control policies are machine policies. We have the enterprise console on a local server that links to AD, but it only allows us to sync computer OUs to Sophos groups.

It sounds like you have a slightly different setup, so you might have more user based options than us though.

 

Yes we're in the cloud!

 

Just reading up on an AD Sync utility you can stick on your DC which can map users/groups etc to the cloud - that might then allow us to be more granular in our policies.

Posted
Yes we're in the cloud!

 

Just reading up on an AD Sync utility you can stick on your DC which can map users/groups etc to the cloud - that might then allow us to be more granular in our policies.

 

We use cloud too and have the AD sync you can then set policies based on AD groups or users. Sync is easy to set up.

Posted
We use cloud too and have the AD sync you can then set policies based on AD groups or users. Sync is easy to set up.

 

Think I've just sorted out.

 

Will do a bit of testing today with some policies but the groups are syncing.

 

Only issue is I've not used LDAP over SSL as I don't know how to sort out the certificate part - any help appreciated.

Posted

We allow them, but use Bitlocker - applied by GP.

 

Quite often it throws members of staff saying "It's full but I've only just bought it" (and those that have Macs at home don't like it)

Posted
Encrypted for now via GPO (for staff only, no restrictions for students). Eventually would prefer to drop completely but have to manage the process to avoid user outcry.
Posted
Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that?
Posted
Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that?

If you're using google or Onedrive you might be able to stop downloading (onedrive and rights management/ Azure information protection should be able to do this). But at some point it's got to just become a training policy issue.

Posted
Encrypting USB or using Google Drive is fine in theory, but I'm worried about the personal laptops that the data is then downloaded onto a home. How do you control that?

 

Training and frequent reminders.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...