Addition of a new Allow setting in device control

What is a one sentence summary of your feature request?

Customer would like to have a new allow case in which it allows if the device is TD level 1+, but also allows if the TD level is detected as level 2 or 3 or 4 without trying to auto deploy easylock if it is, for example, a bitlocker device or some other encryption.

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Customer has a mixed device environment between regular unencrypted USBs, software encrypted USBs, and some hardware encrypted USBs. They would like to block users from accessing unencrypted USBs, but would like to Allow access to encrypted devices that are at least level 1 encrypted with easylock auto deploy (TD level 1+), but will also allow for TD level 2, TD level 3, and TD level 4 without attempting to deploy easylock to them.

Going with this solution, it will allow the customer to set that for their whole environment encompassing all the devices they have.

How do you currently solve the challenges you have by not having this feature?

Customer has to block software encrypted devices and only allow them on a as needed basis and setup a custom class for allowing hardware encrypted devices.

Hello Zachary,

Thank you for sharing your idea with us!
We’ll make sure to record it on our side. Our team will need some time to carefully explore the possibilities of implementing it to best address your use case.

Once we’ve completed our investigation, we’ll share any updates here.

All the best,
Simona

Hi Zachary,

We would like to inform you that your feature request is still valid on our desk, and we will provide an update as soon as it will be planned.

We sincerely appreciate your patience and understanding as we address several high-priority items on our current agenda.

Kind Regards,
Simona

Hi Zachary,

After completing our internal investigation on this use case, we confirmed that the following configuration should achieve the expected behavior:

  • You can select the TD1 level (not TD1+). In this configuration, EasyLock will not be applied to devices with TD2, TD3, or TD4 trust levels, provided that these levels are allowed.

  • Additionally, you may temporarily add TD1+ as an exception for devices that do not have EasyLock enabled. Once those devices are addressed, you can remove the exception and continue using the standard TD1 policy.

Based on our testing, this behavior works as expected. Therefore, could you please test this configuration on your side and share your feedback with us?

Thank you,
Simona