This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Endpoint not working with DLP

Hi,

I have DLP solution named Somansa which is installed at one of my clients place along with Sophos Antivirus.

There I have enabled Application blocking through Somansa DLP which is working fine in the system where Sophos is not installed but same is not working with Sophos installed. Although there is no detection report in Sophos for any of the Somansa DLP files yet I have added exclusion in Sophos Realtime & Process for all exe files of Somansa but issue is same.

I also disabled all the Sophos modules but that also didn't work still application blocking is not working. As soon as I remove Sophos Agent from the same system application blocking starts working fine.

I don't understand what is the issue and why is this happening. previously there was no such issue, it start happening i guess since 5-6 months.

Regards,

Sarvesh Singh

India



This thread was automatically locked due to age.
Parents
  • Hi Sarvesh,

    Thanks for reaching out to the Sophos Community Forum. 

    I suggest running the "fltmc" command in an Admin Command Prompt window. This will display the drivers loaded into the operating system. Based on the order/hierarchy of the loaded drivers, Sophos' drivers may be taking precedence in intercepting file/folder and process actions. 

    As Sophos also performs DLP operations, I suggest trying to turn off the DLP policies in Sophos Central to see if any conflicts are occurring due to both programs performing DLP scanning. 

    Let me know how this goes.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi Sarvesh,

    Thanks for reaching out to the Sophos Community Forum. 

    I suggest running the "fltmc" command in an Admin Command Prompt window. This will display the drivers loaded into the operating system. Based on the order/hierarchy of the loaded drivers, Sophos' drivers may be taking precedence in intercepting file/folder and process actions. 

    As Sophos also performs DLP operations, I suggest trying to turn off the DLP policies in Sophos Central to see if any conflicts are occurring due to both programs performing DLP scanning. 

    Let me know how this goes.

    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
No Data