We were running AntiVirus Enterprise 8.8 and a few months back we migrated to ENS. Most of our users work on Remote Desktop servers, server 2019 if that matters. Now if one of the users triggers a threat detected message (through the McAfee Agent) it shows up for ALL users logged into that system. ie if there are 10 users logged in, and one would download the Eicar testfile for example, a threat detected message shows for all 10 users in their session.
Is there a way to suppress those messages except for the user that's actually logged in? As it actually shows the filename with full-path, there are some privacy concerns as well.
This is Junichi, McAfee Technical Support.
This behavior is as design.
Therefore, can you please try to disable the function "Threat Detection User Messaging"?
This function is in the OAS policy. Please modify the OAS policy for only servers?
1. Login ePO console
2. Go to Policy Catalog and select Endpoint Security Threat Prevention.
3. Click On-Access Scan policy
4. See "Threat Detection User Messaging" section, and disable "Display the On-Access Scan window to users when a threat is detected"
5. Click save
6. Run agent wakeup to the servers.
It seems my reply to this has been removed, or I didn't post it correctly. Thanks for responding, but it's not an answer to my question. Obviously we know that disabling the message alltogether will... disable the message alltogether. But we DO want users to be informed they misbehave, or open something that tries to misbehave. But NOT other users on the same system. That's actually a huge privacy concern.
So where can I fill a feature request?
After a cumbersome ticket with McAfee Enterprise 'support' they just tell me 'bugger off'. I just don't unerstand how this company works. There is a privacy issue with their Security product when used on Remote Desktop servers. When one user gets a detection, ALL users get that message on their screen. And that can lead to serious privacy issues. We've had two of these incidents in the past where an 'you are about to be fired' document that was edited at home, got infected and ALL users on that machine got the message including the filename. And the very same thing happened to another company with a document about a hostile takeover.
These messages should ONLY show up for the user that triggers them, not all. But McAfee just tells me to disable users being informed altogether, and even Enterprise Support tells me there is no issue at all and this is not likely to be fixed at all.
Wow, just wow. This is worse than Microsoft support and that's a bold thing to achieve. I'm utterly unsatisfied with McAfee in this one, and even more so with their support. This might very well lead us to another solution altogether. Just posting here so people see how serious you are taken as a small customer.
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: