This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Mapped Network Drives - exclude from weekly scans

On Sophos Central

All our endpoints have mapped network drives to our file servers.

File servers are fully protected & locked down.

When running the weekly full scan we need to exclude the mapped drives from being scanned at the endpoints. Only the local files need to be scanned. How can i do this at the policy?



This thread was automatically locked due to age.
Parents
  • Hi,

    Out of interest, how do you know they are scanned?

    Just to say, mapped drives may only be accessible to the user session that mapped them.  

    For example: If a mapped drive is created by a user in a non-elevated command prompt; by default this mapped drive will not be visible in an elevated session for the same user

    There is this DWORD: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System!EnableLinkedConnections = 1|0 which allows you to map drive and see it in other sessions. technet.microsoft.com/.../ee844140(v=ws.10).aspx

    If the schedule scan runs as local system, i.e. it is setup as a scheduled scan on the remote computer to run as local system: It may not be able to "see" the mapped drives depending on how they were mapped.

    Regards,

    Jak

Reply
  • Hi,

    Out of interest, how do you know they are scanned?

    Just to say, mapped drives may only be accessible to the user session that mapped them.  

    For example: If a mapped drive is created by a user in a non-elevated command prompt; by default this mapped drive will not be visible in an elevated session for the same user

    There is this DWORD: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System!EnableLinkedConnections = 1|0 which allows you to map drive and see it in other sessions. technet.microsoft.com/.../ee844140(v=ws.10).aspx

    If the schedule scan runs as local system, i.e. it is setup as a scheduled scan on the remote computer to run as local system: It may not be able to "see" the mapped drives depending on how they were mapped.

    Regards,

    Jak

Children
No Data