comgam
-
Posts
15 -
Joined
-
Last visited
Never
Posts posted by comgam
-
-
Hi
we are using the Active Directory “Protected users group” that restrict, for obvious security matter, NTLM usage https://petri.com/windows-server-protected-privileged-accounts
Our Admin account for all IT Administrators tasks are member of this group (it a mandatory security for our Auditors)
now our Admin account cannot login anymore on KSC console or web. if they are removed from this group they can login … so it seems that if we try to be secure, KAS does not let us do it :)
thanks for your help on that
-
Also i cannot, as a Technician, allow only the device for like 1 or 2 hours (i can only by “Pause protection” but it make no sense because if the USB key is infected it will not be scanned)
And the request “temporary access “ is really not easy for end user, the process is to complex for them and that’s not their job
-
Hi
yes we are using those policy for other matter but you can forget to remove the device or the suer when his usage of the USB key is finished so the user
Thats why disabling the device component and having the computer appear as warning or critical because the policy is different was a good option
-
Hi
i have manually disabled “Device control” (enabled by Policy but not locked, password protected) on a computer but there is no status change on the device, no alert on the KSC (just an event in the eventlog) while on my understanding it should be since the policy is different from the one the computer is supposed to have
Since we authorize our technician to temporary disabled deice control i want to know if a protection component is stopped on a computer
Also after renabling the “Device Control” the component is still “Stopped”, see screenshot
thanks
-
well after adding “configure application settings” it works :)
-
Hi
We have a policy to disable USB port but on certain circonstance we want to allow some technician to disable this specific policy so an end user can plug his key
For that we added in the policy - General Setting > Interface > Password protection, the technician username to (+) Disable control component
But when he goes on KAS interface - Device Control and disable, when prompt for the credential they are not working
-
Hi
i m trying to deploy ce following package remotly but the command that is working in a CMD is not working through KSC, the URL is not added
msiexec /i OnlyYooz Setup 1.2.2.msi WRAPPED_ARGUMENTS="/S --url=https://www1.yooz.fr/xxx/index.html"
i tried to add the command in a batch and package the .bat but same issue
-
Hi not sure i understand, pf7033 is for 11.1 exactly ... ?
-
Hi Also is this patch is only for May version or also for earlier version since for 1703 we also have sometimes High CPU usage for no reason (no event on windows, no event on KAS...) thnaks
-
Hi is it planned to be added in a future release (just to know if we wait and how login for an update 10.1.x version ? thanks
-
Hi so you validate there is an issue with the version 11.1.0.15919 and May update ? just for our test computer under this OS thanks
-
and the most important issue is about the script where , i do not know why, it only ending 10 minutes after (event if it run in a few second since i see the process killed) while it should run and complete in less than a minute
-
understood but there is many schedule but not this one which will make sense, i mean it can be after users login for example
-
Hi i have an application "Factset" who need to close some process (like office & adobe) in order to upgrade I thought to launch the package task at startup when KES is launched so before process launched by users but KSC does not have this schedule ... Is there something that can be added in a roadmap ? Anyway, i've created a 1st task to kill process then launch the upgrade automatically after this previous task completed successfully For that i ve just created a basic batch script and it works (process are closed) but it stay at "38% runnning" , then after 10 minutes it finally finished successfully taskkill /IM FDSW32.EXE /F taskkill /IM MARQUEE.EXE /F taskkill /IM EXCEL.EXE /F taskkill /IM MARQUEE.EXE /F taskkill /IM ACRORD32.EXE /F taskkill /IM OUTLOOK.EXE /F taskkill /IM WINWORD.EXE /F exit thanks for your help or if you have a better idea :)
USB Blocked but cannot charge iPhone
in Kaspersky Endpoint Security for Business
Posted
Hi
ou users complain that now USB port are disabled, they cannot charge iphone by USB.
indeed iPhone are recognized as storage device so they have the error message but how can i allowed our user to charge their phones/. since they are travelling a lot its an important point (even it is does not seems a big issue :))
thanks