2

For compliancy reasons we need to demonstrate that users downloading and then running certain file types (namely .exe) are first presented with a warning (for Cyber Essentials). The setup are Windows 10 workstations (build 2004) running Novell Zenworks (now Microfocus) and Sophos Antivirus.

Zenworks applies local policy to the workstation and both smartscreen and medium risk extensions are set. Looking in the registry after login as an unprivileged user the registry keys appear to be present in Computer\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Associations

When the test exe is downloaded from the internet the stream inside the file stating that it came from the internet zone is correctly set. When the file is run no warning appears and the stream disappears from the file.

Same settings tested in an Active Directory environment and works perfectly. Does anyone know of any GPO or registry settings that conflict with attachment manager? Could this be a feature within Sophos? It feels more like Zenworks but I have no proof!

Any guidance would be great

Thanks

Rob
  • 131
  • 3
  • So I have tested with a vanilla Windows 10 Pro 2004 build (no AV, no Novell and no AD). Just setting the same policies (Smart screen and high risk extensions to .exe) generates no alerts. Is attachment manager broken in the latest build of Windows 10 or is there a dependency I am unware of? – Rob Feb 01 '21 at 22:52

0 Answers0