Stoping of F-secure Services
Comments
-
@ravi12 wrote:Hi to all,
We are managing all the client through FSPM console centrally. In any domain client ,administrator can stop the F-secure Services. How can we restrict the administrator of client pc to stop or pause the F-Secure Services locally.Please advise.
Create an AD computer GPO which forces F-Secure services to be started automatically on clients and from the service security, set any local admin to have only read permissions.
For debugging purposes, I suggest to add defined AD user or group of users who has full permissions to stop the services.
1 1Like -
I fear that will sooner or later interfear with the updateing mechanisms of F-Secure.
If you are a local administrator you are the master of the PC and so there is always a way to disable a service or security rule.
0 Like -
@MJ-perComp wrote:I fear that will sooner or later interfear with the updateing mechanisms of F-Secure.
If you are a local administrator you are the master of the PC and so there is always a way to disable a service or security rule.
Maybe, maybe not. Haven't seen any issues with updates yet, and all our clients are deployed with SCCM.
AFAIK F-Secure services are running as system services so removing access just from local admins shouldn't affect the F-Secure processes at all.
For sure, when you're a local admin of the PC there is always a way to disable services.
Users shouldn't be local admins at the first place in managed environment.
0 Like