Jump to content

Recommended Posts

Posted (edited)

Have been a Sophos Central user for a long time, though only recently started using more of the peripheral / application control policies, and they are not working. Well, they are but not within an environment whereby you have many users to a computer (e.g. a school!)

 

For example,

User-based policy to restrict USB storage devices for Students only - Student logs in, USB is blocked - but then same restriction stays in place when a non-student logs in (even an administrator)

 

I appreciate that there may be some form of delay, after logging in whilst computer communications with Sophos Central (Cloud) to obtain policy and apply etc. But when you look within Sophos Central, it has identified the correct user, and applied the appropriate policy.

 

I spoke with Sophos Support, and they basically stated that a (non-student) user would have to open Sophos End Point and apply (force) an update, so that the updated policies are then detected and applied - Crazy! But I've tried it anyway and it doesn't work. So now, as more and more students log into more computers, the student policies are basically being (and staying) applied even when a non-student user logs in! And I couldn't get a definitive answer as to whether the Sophos client caches the policies locally, or checks to Sophos Central each and every time? As can understand forcing an update if I had recently changed or created a policy etc.

 

Totally not suitable - At this rate I will have to cancel using Sophos Policies altogether and resort to applying the restrictions via GPP within GPO! (I did note that Sophos' application restriction polices work so much better - usually applied a short period of time after logging in).

 

Just wondered what other users' experience of Sophos Central Policy Control was like?

 

Thanks,

Edited by MYK-IT
Posted

Wondered if any Sophos Central users could kindly test, or advise if they have a similar policy configuration?

 

User-Based Policy

Block [secure Removable Storage] & [Removable Storage]

Groups - {specific group of users} e.g. Students

 

- Log in as a User (member of {students} Group)

- Check that USB is blocked

- Log out

- Log in as a User (not a member of {students} Group)

- Confirm if USB restriction still applies (including if forced update of Sophos Endpoint and / or waiting for a period time resolves incorrect restriction)

 

Thanks,

Posted

:behindsofa: Apologies, don't mean to spam... will be last time I 'bump' this...

 

I know there are other Sophos Central users on here, also using Peripheral Control policy to restrict USB devices, so i was just intrigued if you applied it 'user-based' whether it works correctly, based on who is logged in or not?

 

Many "Thank Posts" are waiting to be clicked! :)

 

Thanks,

Posted

We’re a Sophos Central user here and we found the user policies to be useless.

 

They don’t apply or apply and aren’t removed when users change as you describe.

 

We block ex’s downloads for staff and students via Sophos as well as on our internet filtering as a belt and braces approach and for admins who should be allowed to download files often get the Sophos block message, like it thinks we are staff/students.

  • Thanks 1
Posted
We’re a Sophos Central user here and we found the user policies to be useless.

 

They don’t apply or apply and aren’t removed when users change as you describe.

 

We block ex’s downloads for staff and students via Sophos as well as on our internet filtering as a belt and braces approach and for admins who should be allowed to download files often get the Sophos block message, like it thinks we are staff/students.

That's sounds like you have either got nested groups in your ad which isn't supported ms or sophos. Or perhapse Policies which conflict in the console

Posted
Have been a Sophos Central user for a long time, though only recently started using more of the peripheral / application control policies, and they are not working. Well, they are but not within an environment whereby you have many users to a computer (e.g. a school!)

 

For example,

User-based policy to restrict USB storage devices for Students only - Student logs in, USB is blocked - but then same restriction stays in place when a non-student logs in (even an administrator)

 

I appreciate that there may be some form of delay, after logging in whilst computer communications with Sophos Central (Cloud) to obtain policy and apply etc. But when you look within Sophos Central, it has identified the correct user, and applied the appropriate policy.

 

I spoke with Sophos Support, and they basically stated that a (non-student) user would have to open Sophos End Point and apply (force) an update, so that the updated policies are then detected and applied - Crazy! But I've tried it anyway and it doesn't work. So now, as more and more students log into more computers, the student policies are basically being (and staying) applied even when a non-student user logs in! And I couldn't get a definitive answer as to whether the Sophos client caches the policies locally, or checks to Sophos Central each and every time? As can understand forcing an update if I had recently changed or created a policy etc.

 

Totally not suitable - At this rate I will have to cancel using Sophos Policies altogether and resort to applying the restrictions via GPP within GPO! (I did note that Sophos' application restriction polices work so much better - usually applied a short period of time after logging in).

 

Just wondered what other users' experience of Sophos Central Policy Control was like?

 

Thanks,

This sounds like the quick login protocol in Windows 10 which is cashing the previous users profile for a quicker load time conflicting with the sophos user policies.

 

Windows 10 has a number of tricks for quicker logon and this is one of them. It often creates security issues and problems with user based policies like this.

Posted
That's sounds like you have either got nested groups in your ad which isn't supported ms or sophos. Or perhapse Policies which conflict in the console

 

 

We don't have any nested groups - All users are either in "Domain Administrators", "Staff" or "Students" with no overlaps for any user.

 

The policies are configured on these groups on the Sophos console - I have always found user policies to be very unreliable as I say.

 

Computer polices on the other hand work without any difficultly at all.

Posted
We don't have any nested groups - All users are either in "Domain Administrators", "Staff" or "Students" with no overlaps for any user.

 

The policies are configured on these groups on the Sophos console - I have always found user policies to be very unreliable as I say.

 

Computer polices on the other hand work without any difficultly at all.

 

Same configuration / results here too.

Posted
Do you have the windows 10 quick login enable to switch user profiles? This conflicts with the sophos central console knowing who's logged in
Posted
Do you have the windows 10 quick login enable to switch user profiles? This conflicts with the sophos central console knowing who's logged in

 

We don't - We have all fast user switching disabled so only one person can be logged in at any one time.

Posted
We don't - We have all fast user switching disabled so only one person can be logged in at any one time.

 

Nope, fast user switching disabled here too.

 

I've come to the conclusion that Sophos Central's peripheral policies work well for computer-based control but not for user-based level. Therefore, I'll probably revert to using Group Policy (specifically GPP) as some registry keys are Computer Configuration (as opposed to user configuration) so I can use 'targeting' to ensure the settings apply based on user (level) AD security group level still.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...