cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1103
Views
0
Helpful
7
Replies

Device control not applied after polocy updated in Cisco endpoint secu

EdieDudley14020
Level 1
Level 1

I've added device contol to my polocy for Windows devices.  I am using the default Global Policy with the setting to Block and notify users.  It has had a week to replicate but it isn't working.  Users are still able to attach a usb device and either download or upload files.  What am I missing?

1 Accepted Solution

Accepted Solutions

Matthew Franks
Cisco Employee
Cisco Employee

I've tested the feature several times and it worked as expected.  If you'd like some help, it would probably be best to open a TAC case so someone can look at the logs and help you determine the issue.

Thanks,

Matt

View solution in original post

7 Replies 7

Matthew Franks
Cisco Employee
Cisco Employee

There isn't really enough information here to say for certain what the issue is.  Have you checked to see if there is a policy update event for any of the devices you're testing with to verify the update has taken place?

This in the Audit log
[cid:9cac5157-37ad-40b2-80e7-95cec69a44d0]

EdieDudley14020
Level 1
Level 1

In the documentation it says that something is installed on the local device.  What should I be looking for? Registry change? It just doesn't look like the policy changed has been pushed.  I have updated the Product version to the latest and that change was pushed to all devices.

Matthew Franks
Cisco Employee
Cisco Employee

If Device Control has been updated in the policy, you should see the rules in C:\Program Files\Cisco\AMP\dc\dc_rules.json. Also, Device Control is only supported on 8.1.3 and later, so make sure the connectors you're checking meet that requirement.

-Matt

Matt,

Thank you for your reply. I did some testing with a laptop I was resetting. I've tried product versions 8.13, 8.15 & 8.17. None of them blocked the USB drive from being accessed. I set this up on a test machine last fall and it did work. Not sure what changed.

Matthew Franks
Cisco Employee
Cisco Employee

I've tested the feature several times and it worked as expected.  If you'd like some help, it would probably be best to open a TAC case so someone can look at the logs and help you determine the issue.

Thanks,

Matt

Thanks Matt, I open a case TAC