This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Help with a "NO install Group"

Is there any way to configure a group so that machines added to it can never have sophos installed to them? We have a couple of machine that must not have AV on and now and then admin who use the sophos console roll out sophos to machines not protected which installs sophos on the few machines we must not have AV on. We then have massive issues until we can remove and rectify the damage on them machines.

Is there any way to stop this happening on the few machines we need it to be unable to install on?

:5165


This thread was automatically locked due to age.
  • We have a couple of machine that must not have AV on

    You probably can't give any details about the reason. I hear such "requirements" now and then. IMO unprotected machines have no place on the general network - especially when obviously no other measures are taken to protect them. If Sophos can be installed on them from SEC they are pretty open, really.

    Is there any way to stop this happening on the few machines we need it to be unable to install on?

    Well, there are lots of threads in this forum about how to get the install working, so ...:smileywink: :smileyvery-happy:

    Seriously - excuse me sounding rude, but you have an organizational problem. If you put the machines in a group named "No Install" that should suffice. And you can assign an updating policy with an invalid install/update location so an attempted install will fail. If your admins aren't aware of the "special needs" of some of your machines - what will prevent them from moving the machines to another group? 

    Christian

    :5166