Risk or threat exclusions not working for client managed by SEPM after cloud enrollment
book
Article ID: 247910
calendar_today
Updated On:
Products
Endpoint Protection
Issue/Introduction
After enrolling the SEPM into the cloud. The SEPM managed clients began to trigger on files that were already excluded in the Symantec Endpoint Protection Manager (SEPM) exclusion policy.
Environment
Enrolled hybrid SEPM with the cloud.
Cause
The cloud policy "Default Whitelist Policy" overwrites the on premise exclusion policy.
Resolution
Symantec is currently investigating this issue. This KB will be updated when a fix is released. To work around the issue:
Remove the Default Whitelist Policy with policy type "Allow List (SEP 14)" from all SEPM groups in the cloud console.
After removal of the cloud policy, allow time for the change to occur on SEPM
In the SEPM console, check that the expected exception policies are applied to the correct groups as required.