This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Best practice for On-Access scan settings

Hello,

I know by default that the On-Access scan settings for Viruses/spyware is set to "Deny access only" but I wanted to get a feel for what others are doing and why?

We are using the defaul setting for On-Access and then in our weekly scan schedule we set the Automatically clean up.  But it seems that when machiens are offline during the weekly scan schedule that they are never getting cleaned unless we manually clean them from the console during the day.

Thoughts about why we should not just set the On-Access scan to automatically clean?

Does anybody know what the defaults are for other AV prodcuts?

:2647


This thread was automatically locked due to age.
Parents
  • Hi,

    our long-term practice has been to move on-access-positives into Sophos' infected-folder. We use this as the standard-behaviour on desktop-pcs, while servers use "deny" as the standard behaviour.

    However, in the last year or so we have seen a lot of false positives from the generic patterns like mal/generic-a, and I have considered setting the behaviour to "deny" even for desktop-pcs, as the recovery of moved files has cost us a lot of time.

    The quality of the generic patterns seems to have improved over the last 2-3 months, I don't recall many false positives from this period.

    Best regards,

    Detlev

    :3104
Reply
  • Hi,

    our long-term practice has been to move on-access-positives into Sophos' infected-folder. We use this as the standard-behaviour on desktop-pcs, while servers use "deny" as the standard behaviour.

    However, in the last year or so we have seen a lot of false positives from the generic patterns like mal/generic-a, and I have considered setting the behaviour to "deny" even for desktop-pcs, as the recovery of moved files has cost us a lot of time.

    The quality of the generic patterns seems to have improved over the last 2-3 months, I don't recall many false positives from this period.

    Best regards,

    Detlev

    :3104
Children
No Data