Hi everybody,
I have only one response rule in the policy and it is Endpoint:Block rule. Rule is working fine for SMTP, HTTPS USB.. but when there is Application Monitoring included (i.e MS Teams) that same rule blocks the transfer but also quarantines the file locally on the endpoint. I don't want it to quarantine file, just want it blocked.
Is that by design when there si application monitoring included? Is there any workaround for that behaviour?
I cant find any documentation about Endpoint:Block rule quarantining files, except when using Endpoint Discovery: Quarantine.