Unfortunately, there was a limitiation outlined in the Known Issues section of the release notes.
The issue stemmed from an architectural problem that could not be easily corrected in 7.0.
IPS exceptions allow only all users or groups or specified local users to be entered as users. Selecting local groups or domain groups as users is not supported. (364942)
Using AD groups will be fuilly supported in HIP 8.0 due out late Q3 2010.
Is it possible to create exceptions at all for Application Blocking Rules? As far as I can tell, exceptions only pertain to IPS rules.
1 of 1 people found this helpful
Yes, you should be able to create exceptions either off the event itself or by running AB in adaptive mode which will automatically create a client rule (exception).
I tried creating an exception off of the event in the log and keep getting a "Create Exception Failed" error, is there a log that will give me more details about the error?
Thanks again for your help.
The "Create Exception" option in the ePO console only works for Host IPS events (not Network IPS or App Blocking events).
You can create a "Trusted Application" rule and mark that application to be trusted by the App Blocking module, for application hooking. This will create an application blocking rule to allow your application.
There is not really "exception" rules for Application Blocking. If you wanted some type of "block all users from executing this application, except for certain users" functionality, you could try creating a custom Host IPS signature to block the "execute" operation, and then use an IPS exception to allow certain users to override this signature.