On Endpoint 12.1.4 I have modifed two policy element -- the first was to not allow staff on endpoint computers to modify exceptions. That worked.
The second was to not allow staff on endpoint computers to disable endpoint protection. That did not work. Staff can right click on the Symantec shield, and then click Disable Symanted Endpoint Protection SBE and that will turn off the auto protect.
On the policy in place, under Protection Technology, there is the Auto Protect item. The enable auto protect box is checked and I have confirmed that the lock is closed down.
Because the one setting I made worked on this same policy, I know that communications is working properly. Any ideas as to why I can't prevent staff from disabling endpoint on the desktop?
- Lars