This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Option to prevent tampering with Sophos services and settings

Hello Folks -

We just recently implemented Sophos S&C 9.0 for our end-users.  The product works great but we are looking for some sort of mechanism to prevent our limited number of users who are also local administrators on their laptops from stopping the Sophos services.  I know with other vendors products that regardless of whether the user is an admin or not they still provided some sort of setting(s) that would prevent the users from doing so.

I do realize (and I saw this on other posts in this forum) that it doesn't go along with "safe computing practices" but in some companies (i.e. telecoms) it is often at times cumbersome to lock down certain departments (RF engineers, field crews, etc) especially when these departments are in direct contact with vendors, etc.  I can restrict with a Group Policy the "Install with Elevated Privilges" settings but many applications are hard coded to require an administrator installing the software.

I saw that Sophos Professional Services can assist with this type of configuration but in my honest opinion this is something that should be included in an enterprise class endpoint solution.  I also may be searching on the wrong keywords so if there is an article / suggestion on how to accomplish this please steer me in the correct direction.

Thanks!

:2028


This thread was automatically locked due to age.
Parents
  • I posted my original question about Tamper Proof 4 years ago - Sophos has made strides in implementing tamper proof since then but like some other users are reporting the services can be stopped by admin users.  This has been one of my largest "beefs" with Sophos - something other competitors have been able to figure out how to do (and long ago might i add) - prevent the AV services from being disabled by users with Admin priviliges.  Sophos moderators / power users continuously respond with the typical "Well you shouldn't be giving out admin rights..." ...yes we all know those priviliges should not be granted on a whim but in some industries / situations / IT shops with limited support you just need to grant those rights to certain individuals.

    Posts here on the forum seem to rely on the Iron Fist mentality that if those services are disabled by your users then there should be repurcussions internally - the offending user(s) should be reprimanded / fired.  That again is not always practical - might fly in a government / financial setting.  I've mentioned this fact to our account team for YEARS so hopefully one of these versions it may get locked down better then it is currently.  I guess in the end we are still using Sophos for whatever that is worth.

    :55157
Reply
  • I posted my original question about Tamper Proof 4 years ago - Sophos has made strides in implementing tamper proof since then but like some other users are reporting the services can be stopped by admin users.  This has been one of my largest "beefs" with Sophos - something other competitors have been able to figure out how to do (and long ago might i add) - prevent the AV services from being disabled by users with Admin priviliges.  Sophos moderators / power users continuously respond with the typical "Well you shouldn't be giving out admin rights..." ...yes we all know those priviliges should not be granted on a whim but in some industries / situations / IT shops with limited support you just need to grant those rights to certain individuals.

    Posts here on the forum seem to rely on the Iron Fist mentality that if those services are disabled by your users then there should be repurcussions internally - the offending user(s) should be reprimanded / fired.  That again is not always practical - might fly in a government / financial setting.  I've mentioned this fact to our account team for YEARS so hopefully one of these versions it may get locked down better then it is currently.  I guess in the end we are still using Sophos for whatever that is worth.

    :55157
Children
No Data