cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3132
Views
5
Helpful
2
Replies

Default Outlook Temp Exclusion

seanchoudhury
Level 1
Level 1

Hi,

 

We are seeing an issue where the default Cisco AMP exclusions for Outlook aren't enough because Outlook Temp is also under /private/var so it's scanning this location and we are getting inundated with Threat Detected notifications every time someone's Outlook receives an attachment. As guess my question is has anyone had success with excluding the /private/var Outlook Temp as well, this would have to be done with wildcards as the folder name is randomized.

 

--

Sean 

1 Accepted Solution

Accepted Solutions

Jetsy Mathew
Cisco Employee
Cisco Employee

Hello Sean

 

Do you have the MAC or Windows endpoint facing this issue ?

Just try the following if you are having a MAC workstation and let me know if this works. Compare the path with the one which you have.

 

Wildcard
/private/var/folders/*/*/*/com.microsoft.*/Outlook Temp

 

Regards

Jetsy 

View solution in original post

2 Replies 2

Jetsy Mathew
Cisco Employee
Cisco Employee

Hello Sean

 

Do you have the MAC or Windows endpoint facing this issue ?

Just try the following if you are having a MAC workstation and let me know if this works. Compare the path with the one which you have.

 

Wildcard
/private/var/folders/*/*/*/com.microsoft.*/Outlook Temp

 

Regards

Jetsy 

Thank you so much Jetsy! 

 

We have all MAC endpoints and the file paths we are currently excluding are:

  • Wildcard: /Users/*/Documents/Microsoft User Data/Office 2011 Identities/*
  • Wildcard: /Users/*/Library/Group Containers/* Office/Outlook/Outlook 15 Profiles/*
  • Wildcard: /Users/*/Library/Caches/Outlook/*
  • Wildcard: /Users/*/Library/Caches/TemporaryItems/Outlook Temp/*kcIB*

Suggested by Cisco Support docs, so a follow up questions is can this be added to the defaults as I'd imagine anyone who manages MAC endpoints is going to have this same issue because Outlook is storing in the /private/var path as well.