Notification is not displayed even "Notify users when external devices are Allowed" is on if "Log detected external devices" is off in "Blocked External Devices" in Device Control Policy.
<Steps to reproduce>
1. Login to ICDM and create a Device Control Policy like following and assigned it to Windows client.
Blocked External Devices
- Log detected external devices: Off
- Notify users when external devices are blocked: On
- Show a customer notification on the device: [Policy-Block]
Allowed External Devices
- Log detected external devices: Off
- Notify users when external devices are blocked: On
- Show a customer notification on the device: [Policy-Allow]
Device Control rules
Group by: Windows Rules
Add following rule and set ACTION to [Allow All] .
- Name: General_USB
- DEVICE ID: USBTOR*
- ACTION: Allow All
2. Insert the USB memory stick into the PC and confirm the notification [Policy-Allow] is not displayed.
Also open Explorer on the Windows client and confirm it is mounted as a drive.
3. Edit the Device Control Policy and change Log setting of Block from Off to On.
Blocked External Devices
- Log detected external devices: On
Confirm that the policy is reflected in the Windows client.
4. Insert the USB memory stick into the PC and confirm the notification [Policy-Allow] is displayed now.
OS: Windows
Product Version and Build: SES Agent 14.3 RU8
Broadcom is aware of this issue and will update this document when a solution becomes available.
Planned to be fixed with 14.3 RU9.