I'm curious to the behaviour of the default policies in the enterprise console.
This curiosity starts with the following case.
In the middle of the night a colleague of my is called out of his bed because of a problem at out network.
Investigation shows my colleague a suspicious file whice was blocked by Sophos.
Mine colleague, who is not a regular admin of sophos, solved the problem by authorization of the blocked file on the local client.
The next morning I saw an notification in the SEC that the policy of the client was different as the default.
I take action by inform at and verify the action of my colleague. When I was agree with him I authorized the blocked file in de central policy so every other client in the group of the changed client is uptodate with this change.
After this case I heard that the default behaviour of SEC is that as a policy whice is changed localy, like mine colleague did in the case above, and there will be not take any action in the SEC the default policy will pushed to the changed client at the next update of sophos.
In the case above I didn't saw this behaviour, but if this is the default behaviour I don't like it.
If in the time between the action of my colleague until I saw the notification Sophos was updated I never had saw the notification and the client should be set back to the policy as the where before the action of mine colleague.
The first time I should be aware of the issue should be if my colleague brief me or when the file will be blocked again be sophos.
In the past we had a lot of strange situation by the behaviour of the managment tool of Mcaffee (our last virusscanner whice is replaced by sophos).
I had a discusion with our reseller whice have the opinion that this is the most likely behaviour otherwise you don't have the need of a central managment.
I'm not agree with my reseller I should like that SEC notify the differency in policy In the console and with any possible notification, but not that SEC correct them by it self (to the wrong setting).
My queation is as follow:
The default behaviour is that as descripted: The centrale policy overrules the locale policy at the time sophos will be update.
If so is there a possibility to change the default behaviour to the way I should like that SEC behaves itself.
If this is not a possibility is there a possibility to make this matter to a feature request.
With best regards
Peter
This thread was automatically locked due to age.