PDA

View Full Version : edit policy to allow users to delete from quarantine ?


Scott_e
February 10th, 2010, 09:47 AM
NOD32 AV Version 4.0.467.0
Remote Admin Console Version 3.1.11
Windows XPsp2
W2k3 server

Policy defined to stop users accessing many features but i need them to have the ability to delete files from quarantine. Is this possible ?

For example a user can right click the NOD32 icon.

Password required for:
Advanced Setup
Disable Real Time protection
Disable AV and Spyware protection
Delete from Quarentine
Amend Scheduler items

No password required for:
Computer scan
Update
Log Files
Quarentine

Im trying to move the "Delete from Quarantine" option to the no password required list.

I load:
Remote Admin Console
Policy Manager
Select the Policy required
Edit
Select ESET Smart Security, ESET NOD32 AV

From here are there any options to allow me to allow users to delete files from
Quarantine ?

( i should probably add that i would prefer to stop users accessing anything else , i.e im happy with the rest of the lock out policy, just Quarantine delete i would like to amend if possible).

Thank you for any help
Scott

RyanH
February 10th, 2010, 05:40 PM
The reason why this is not enabled is due to a security risk. If a legit file (false positive) is being put into quarantine and the user has the ability to delete quarantined items, they may be deleting an important system file. It is better to leave items in quarantine until you can verify the items in there to delete.

Future release of ESET Remote Administrator may allow an admin to view items in client's quarantine box and delete them.