The response rule "Endpoint Prevent: User Cancel" is only supported on Windows. If a user on a Mac triggers the same policy the traffic is allowed. I cannot find a way to put a condition on RR based on agent OS. I can't find a "Stop Processing Rules" trigger either.
I am trying to create the following RR's for a single Endpoint policy
- Endpoint Prevent: User Cancel (Windows)
- Endpoint Prevent: Notify (Mac)
DeviceID only looks at removable media not the OS.
Anyone got a clever idea on this one?
------------------------------
If it were easy it would have been done already. -Peter H. Diamandis
------------------------------