Issue
When trying to open a remote console on Windows XP, you get the following error message:
The User [user] does not belong to any subestates.
Known to apply to the following Sophos product(s) and version(s)
Enterprise Console 4.5.0
Operating System
Windows XP
What To Do
In order to get the remote console running on Windows XP, you must set up the following firewall rules for Enterprise Console in Endpoint Security and Control.
You can either do this in the policy that is applied to the remote console computer, or you can do it on the endpoint computer itself; however, if you make changes to an endpoint that has a firewall policy applied to it, you will lose your changes if the policy is ever re-applied to the endpoint from Enterprise Console.
- Application rule: ENTERPRISECONSOLE.EXE
Name = ENTERPRISECONSOLE.EXE
Where the protocol is TCP
and the direction is Outbound
and the remote address is <Management Service>
Allow it
- Application rule: SVCHOST.EXE
Name = SVCHOSET.EXE
Where the protocol is TCP
and the direction is Outbound
and the remote address is <Management Service>
and the remote port is DCOM
Allow it