We have recently switched from a major competitor corporate anti-virus suite product to avast EndPoint Suite.
We are a software development company. As such, we have many unknown or uncommon applications that we frequently use. Accordingly, the automatic sandbox is frequently activating when we launch applications that are commonly used here.
How can I turn the sandbox off for a specific group of client PCs?
I have tried adding global exceptions for the executables. However, the “excluded” applications are frequently sandboxed anyway. Further, every day ten or more new applications are being reported to me by staff as having been “blocked”.
Additionally, after having sandboxed and tested an application and then allowing it to be run, if it is almost immediately relaunched, it is again sandboxed.
Isn’t there any heuristic applied to this?
"I just checked this application;"
"The user allowed it to run after I permitted it;"
"The application's signature hasn't changed;"
"Maybe I don't need to sandbox it again"