App Control Server: Unapproved files not blocked by agents in high enforcement policy
book
Article ID: 288455
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Unapproved files not blocked by agents in high enforcement policy
Environment
App Control Server : All Versions
Cause
There was an allow execute custom rule created for target path "\device\harddiskvolume*\* "which caused any unapproved file on the endpoint to be approved for execution
Resolution
Delete the allow execute custom rule or modify the target path to be more precise