If you want to block only the File Transfer over Bluetooth for Windows 10 version 1809 and later, create an Application File Access Protection Rule in DLP, or Access Protection Rule in ENS. You can create the rule instead of following the steps under the "Windows 10 version 1809 to Current" section in
KB91976 - How to block file transfers via Bluetooth.
To create the Application File Access Protection Rule in DLP:
- Log on to the ePO console.
- Go to Menu, Data Protection, and select DLP Policy Manager.
- Under Rule Sets, click the appropriate Rule Set.
- On the DLP Rule Set page, select the Data Protection tab.
- Click the Actions drop-down list and select New Rule, Application File Access Protection.
- On the Application File Access Protection page:
- Enter a Rule Name.
- Set the State to Enabled.
- Set the Severity according to your requirement.
- On the Condition tab, click the three dots next to Classification.
- Select the Classification and End-User of your choice.
- Click the three dots next to Applications and click New Item.
- Enter the Application Template name and leave the rest to its default.
- Under the Available Properties section, select the Property Original Executable File Name.
- Set the Value as fsquirt.exe. Click Save.
- Select the Application Template name that was saved in the previous step, and click OK.
- On the Reaction tab, set the following:
- Set the Action to Block.
- Click the three dots next to the User Notification and select a notification from the list. Click OK.
- Select the Report Incident checkbox and select the Store original file as evidence if you want to store evidence files.
- Click Save and Close.
- Apply the rule set to a new policy and assign the same to the endpoints systems. Fsquirt.exe is responsible for the Bluetooth File Transfer wizard in windows. According to the above DLP Application File Access Protection Rule, the Classified files accessed by Fsquirt.exe are blocked. The result is that this rule blocks the Classified files from being transferred through Bluetooth File Transfer wizard in Windows.
NOTE: The files transferred using the Bluetooth File Transfer wizard are empty if you view them on the destination system. These empty files are according to product design.
- Apply the policy changes through the Policy Assignment.
To create Access Protection Rule in ENS:
Fsquirt.exe is responsible for the Bluetooth File Transfer wizard in Windows. So, you can block the exe from the AV software instead of DLP.
Use the following steps to block fsquirt.exe in ENS Access Protection Policy. You can also use these steps to block fsquirt.exe from other AV solutions.
- Log on to the ePO console.
- Go to Menu, Policy Catalog.
- Select Endpoint Security Threat Prevention Policy applied on the user system.
- Click Edit, Show Advanced, and make sure that Access Protection is enabled in the policy.
- Under Rules, click Add. Name the rule Block fsquirt and select Block & Report under Action.
- Click Add to and name the executable definition as All Process and File Name or Path as *.
- Scroll-down to create a subrule that defines the target process.
- Click Add, name the subrule as fsquirt, and select the Subrule Type as Process from the drop-down list.
- Select Any access, Change, Run from Operations.
- Scroll-down to add the Target, and click Add. Name the Executable Properties as fsquirt.
- Select Inclusion Status as Include and file name as fsquirt.exe.
If this solution or workaround does not resolve your issue, log on to the ServicePortal and
create a Service Request. Include this article number in the Problem Description field.