Hi,
Appreciate similar has been asked in previous posts but I was unable to ascertain how best to meet my requirements from those posts.
In short, we block writing to USB's for all users except for select USB devices. This is achieved by creating a device definition and specifying the device GUID. We have an area of the business who need to write to multiple types of USB and therefore the intention is to add an exception based on an AD group.
I've tested the following but it doesn't appear to be working:
Data Loss Prevention 11 > DLP Policy > <PolicyName> > Settings > Privileged Users
Here I've added an AD group. From reading the description of this feature I believe it should meet my requirements...
Select AD users or groups which are only monitored by DLP policy rules.
If these users trigger a rule, an event is logged to McAfee ePO but prevent action is not enforced
Any guidance would be greatly appreciated.