Print Download PDF Send Feedback

Previous

Next

Device Scanning and Authorization Actions

You can configure a Media Encryption & Port Protection rule to require malware and unauthorized file type scans when a storage device is attached. You also can require a user or an administrator to authorize the device. This protection makes sure that all storage devices are malware-free and approved for use on endpoints.

You can select one of these predefined options for a Media Encryption & Port Protection rule:

Action

Description

Require storage devices to be scanned and authorized. Allow self-authorization.

Scan the device when inserted. If this option is selected, users can scan the storage device manually or automatically. If this setting is cleared, users can only insert an authorized device.

Require storage devices to be scanned and authorized. Do not allow self-authorization.

Scan the device when inserted. Specified administrators must authorize the device after a successful scan.

Do not scan storage devices

Storage devices are not scanned when inserted and no authorization is necessary.

New

Create a custom action with different authorization and media scan requirements.

You can configure which file types can or cannot be on storage devices.

To configure which file types can be on storage devices:

  1. Click a device scanning and authorization action and select Edit Properties.
  2. Click the Configure unauthorized file types link.
  3. In the Unauthorized File Types window, select a Mode:
    • Unauthorized - Configure the file types that are blocked. All other file types are allowed.
    • Authorized - Configure the file types that are allowed. All other file types are blocked.

    The default is unauthorized with all file types allowed.

  4. Click Add to add file types to the list.
  5. Select file types from the Available Objects list and click Add to move them to the Selected Objects list.

    If you selected Unauthorized mode, select the file types that are not blocked from storage devices.

    If you selected Authorized mode, select the file types that are allowed on storage devices.

  6. Optional:
    • Click New to create a new file type.
    • Click Remove to remove a group from the list.
  7. Click OK.
  8. Click OK.

Related Topics

Custom Scan and Authorization Actions