Whitlisting Files vs Safelisting Users: Which is Best Practice and Why?
Hi all,
So recently at work our security setup at work has been going crazy with "Lateral Movement Detected".  100% of this activity has been false positives since the alert is always triggered by Deskside/Network Support guys transferring files like printer drivers, etc to the admin share of endpoints.  During our status meeting my solution was to safelist the support guys in the HIDS to reduce the noise.  The counter-solution from to mine from management was to leave the support users alone, but to whitelist the inventory of files all the supporting groups use for maintenance (i.e. Database, Deskside Support, Networking, Project Management, etc).  This is close to 150 files easily.  
Without arguing my position further and for the sake of being objective, do any of the best practices, frameworks, or SANS courses, any related body of knowledge, etc point to to the ideal solution to this whether it be the whitelisting of the files or safelisting the users?  
As always ladies and gentlemen, thanks for the tips, solutions, or comments.