Symantec Endpoint Protection (SEP) for Mac clients are not forwarding Device Control events to the Endpoint Protection Manager (SEPM).
Normally, Mac clients should forward any events for devices that are listed in "Blocked Devices" or "Devices Excluded From Blocking" in Mac Settings of the Application and Device Control (ADC) Policy in the SEPM. All events should forward if "Log detected devices" is checked.
Even though these conditions are met, Device Control event forwarding may not work in SEP for Mac versions later than SEP 14.0 RU1; events will be logged locally at the client, but do not appear in the SEPM.
SEP for Mac 14.0 RU1 and later
OS X, macOS, Mac
Symantec is aware of this issue and will update this article when a solution becomes available. Click the Subscribe to this Article button to be notified of future updates through email.
Subscribing will provide email updates when this Article is updated. Login is required.