marklar23 Absent Member.
Absent Member.

Custom DLU Groups not applying Win7

My company uses Sophos for our antivirus solution and in order to open the Sophos Console on a workstation, the local user needs to be a member of a SophosUser group. Back when I originally made my DLU policy when my organization only had XP systems, the DLU Group SophosUser applied to all of my users without any trouble. I've noticed that since we started upgrading to Windows 7 that none of my users that use Win7 become members of this group when they initially log in, or at any following logins. I know that lots has changed from XP to 7, is there anything that I can do to restore this functionality? I'm still running ZCM 11.1 with plans to upgrade to SP2 in the next couple of weeks.

Labels (2)
3 Replies
Anonymous_User Absent Member.
Absent Member.

Re: Custom DLU Groups not applying Win7


It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

Has your problem been resolved? If not, you might try one of the following options:

- Visit and search the knowledgebase and/or check all
the other self support options and support programs available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (

Be sure to read the forum FAQ about what to expect in the way of responses:

If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your Novell Product Support Forums Team

New Member.

Re: Custom DLU Groups not applying Win7

Need a bit more info. eDirectory? Is the group a local windows group and if so why? Are you applying a DLU to the device and user?
How are devices assigned to the group? Version of Sophos - coorporate version etc.

(NB I find putting a summary of my network environment in the signature block a help)

marklar23 Absent Member.
Absent Member.

Re: Custom DLU Groups not applying Win7

My apologies for the delay, I had some other issues come up since my original post. Yes, eDirectory.

The SophosUser group is a local Windows group, Sophos creates 3 local user groups in Windows on installation that define user access to the console, a general user, a power user, and an administrator. Just to open the Sophos console to run a virus scan or manage quarantine the local user needs to be in at least the SophosUser group.

I'm applying DLU to only the Workstations Folder in ZCM, not the users. I can test a couple of users to see if this will make a difference. Since all "Workstation" devices are automatically assigned to the Workstations folder when they are connected to ZCM, that is how they are assigned.

We are running Sophos Endponit Security and Control, version 10.0. I believe that it is the most recent version and is distributed by a management server running their Enterprise Console 5.0

Please let me know if there is anything I can try, and I'll give it a try assigning DLU to users to see if that corrects my issue too.
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.