Endpoint Protection for Mac deletes detected malware after definition update when policy is configured to log only
search cancel

Endpoint Protection for Mac deletes detected malware after definition update when policy is configured to log only

book

Article ID: 165205

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

The Symantec Endpoint Protection (SEP) for Mac client is configured to not repair or quarantine detections.  There are three places to configure this option in the Virus and Spyware policy under Mac Settings.

• AutoProtect 
• Scheduled Scan configuration and Common Settings
• Administrator On-demand scans and Common Settings

Even if these features are set to not repair or quarantine files, the definition update scan may quarantine or delete files.

 

Environment

  • SEP 14 and newer
  • Mac OS X 10.9 and newer
  • macOS 10.12 and newer

Cause

  • There is a targeted scan that runs on the SEP for Mac client after definitions are updated and after a manual or on-demand scan.
  • This scan is logged at SEPM as a "Definition Download" scan.  
  • This scan cannot be disabled or otherwise configured.


 

Resolution

{KNOWN_ISSUE.EN_US}

As a workaround, create SEP scan exceptions and/or submit files as False Positive if known good files are being deleted.

References

Report a Suspected Erroneous Detection (False Positive)

How to create a Security Risk Exception for Mac in SEPM