This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos Central - Endpoint Advanced with Intercept X -(trial) where is the option on the Endpoint computer to manually cleany up a quarantined file ( now Event Store ) ?

When a computer is reported as having - for example - a PUA, this is passed to the event store . The Sophos Central Admim gives me the option to allow the PUA or mark it as cleared, but is there an option to clean it on the endpoint reporting the PUA ? Am I missing something in the Settings tab ? ( For info, in this trial, tamper protection is not enabled)



This thread was automatically locked due to age.