Notification is not displayed even "Notify users when external devices are Allowed" is on
search cancel

Notification is not displayed even "Notify users when external devices are Allowed" is on

book

Article ID: 276061

calendar_today

Updated On:

Products

Endpoint Security

Issue/Introduction

Notification is not displayed even "Notify users when external devices are Allowed" is on if "Log detected external devices" is off in "Blocked External Devices" in Device Control Policy.

<Steps to reproduce>

1. Login to ICDM and create a Device Control Policy like following and assigned it to Windows client.

Blocked External Devices
 - Log detected external devices: Off
 - Notify users when external devices are blocked: On
 - Show a customer notification on the device: [Policy-Block]

Allowed External Devices
 - Log detected external devices: Off
 - Notify users when external devices are blocked: On
 - Show a customer notification on the device: [Policy-Allow]

Device Control rules
 Group by: Windows Rules
Add following rule and set ACTION to [Allow All] .
 - Name: General_USB
 - DEVICE ID: USBTOR*
 - ACTION: Allow All

2. Insert the USB memory stick into the PC and confirm the notification [Policy-Allow] is not displayed.

Also open Explorer on the Windows client and confirm it is mounted as a drive.

3. Edit the Device Control Policy and change Log setting of Block from Off to On.
  Blocked External Devices
   - Log detected external devices: On

  Confirm that the policy is reflected in the Windows client.

4. Insert the USB memory stick into the PC and confirm the notification [Policy-Allow] is displayed now.

 

Environment

OS: Windows

Product Version and Build: SES Agent 14.3 RU8

Resolution

Broadcom is aware of this issue and will update this document when a solution becomes available. 
Planned to be fixed with 14.3 RU9.