Exclusion policy doesn't work when Allow list policy is applied to client groups in SEPM hybrid deployment.
search cancel

Exclusion policy doesn't work when Allow list policy is applied to client groups in SEPM hybrid deployment.

book

Article ID: 277327

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security Complete

Issue/Introduction

If the administrator has SEPM in Hybrid deployment and the enrollment option in ICDm/SES cloud doesn't have the option "Manage Policies from the Cloud" enabled, the allow list policy applied to the group in the cloud account will take precedence over the exclusion policy applied to the same group in SEPM client groups, resulting in having the clients with non-functional SEPM exception policy.

Environment

SEPM in hybrid environment, and disabled "Manage Policies from the Cloud" option at the ICDm/SES cloud portal.

 

Cause

ICDm allow list policy applied to hybrid group will take precedence over the SEPM applied exception policy by design.

Resolution

Remove any allow list policy applied at the Hybrid client groups synchronized from SEPM side.

Upon a sync of the change between SEPM and the cloud, the client should detect the change, and they should remove the cloud allow list policy, resulting in exception policy provided from SEPM being enforced.