Skip to content

Define Device Control Evidence Data Remote Location : GPO #6

@Matthew-Cherry87

Description

@Matthew-Cherry87

GPO 'Define Device Control Evidence Data Remote Location' does not appear to function.

When configured, workstations with access 8 and mask 16 only copy evidence data - files written to removable media - locally to 'C:\Windows\Defender Duplication Data'

Defender engine 4.18.2202.4
Windows 10 21H2 Enterprise
GPO setting is successfully written to registry HKLM:\Software\Policies\Microsoft\Windows Defender\Device Control\DefaultDuplicationRemoteLocation'

I have tried configuring SMB shares and specifying GPO as a UNC path ( I assume this is what is required, given the setting has absolutely no documentation or description within the GPO's adml file or this Repo, but that results in no change in behaviour. Endpoint devices will successfully create 'duplicates' of files written to removable media locally, but not to any 'remote path' specified in this GPO.

There's also no errors or issues recorded in MPDeviceControl.log on the endpoint to suggest any attempts yet alone issues with it attempting to copy evidence data to remote location.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions