cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted

Help with policy exclusion

Jump to solution

Running ENS 10.6.1 with ePO 5.10.

I have a server that collects and stores uploaded video. I connect to that server via browsers from client machines to view video. When we try to export the video (download to local computer or burn to disc), we get a violation of an Access Protection Rule:

NT AUTHORITY\SYSTEM ran SYSTEM:REMOTE, which tried to access

W:\(path)\autorun.inf, violating the rule "Remotely creating autorun files" and was blocked.

If I disable the rule regarding "remotely creating autorun files" under Access Protection, then I can export video from my clients.

I've tried everything I can think of for file exclusions inside that rule, and I cannot get it to work without the rule disabled. Can anyone provide any assistance?

In the ePO forum, I posted this, and was told there is no way to exclude processes from System:Remote.

 

Thanks

1 Solution

Accepted Solutions
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Help with policy exclusion

Jump to solution

@bkesting The advice you were given that there's not a way to exclude remote processes specifically, was correct. The "process" that is violating your rule and what is being blocked is SYSTEM:REMOTE. As such, the only way to get the rule to cease being triggered would be to exclude SYSTEM:REMOTE. However, since the purpose of this rule is to block remote creation of autorun files, excluding this would negate the purpose of the rule. As such, if you're needing to allow this behavior, you will have to decide which is more important, and perhaps look at an alternative way to achieve your desires for either side of the equation.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

View solution in original post

1 Reply
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: Help with policy exclusion

Jump to solution

@bkesting The advice you were given that there's not a way to exclude remote processes specifically, was correct. The "process" that is violating your rule and what is being blocked is SYSTEM:REMOTE. As such, the only way to get the rule to cease being triggered would be to exclude SYSTEM:REMOTE. However, since the purpose of this rule is to block remote creation of autorun files, excluding this would negate the purpose of the rule. As such, if you're needing to allow this behavior, you will have to decide which is more important, and perhaps look at an alternative way to achieve your desires for either side of the equation.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community