+ Post New Thread
Results 1 to 6 of 6
How do you do....it? Thread, Software Restriction Policy (w2k3) - path question in Technical; Hello all, I'm setting out SRP up to stop the little darlings from running exes etc from their home drives. ...
  1. #1

    Join Date
    Oct 2005
    Location
    Anywhere but in a school ;o)
    Posts
    522
    Thank Post
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0

    Software Restriction Policy (w2k3) - path question

    Hello all,

    I'm setting out SRP up to stop the little darlings from running exes etc from their home drives. I have searched for an answer to the query I'm about to pose but didn't find an answer.

    So, my question is:

    If I implement a 'path' restriction, eg:

    \\fileserver\%username% - will that restrict everything in that path that's in the 'file types' properties (I assume it does)

    Can I - for peace of mind - also restrict just one type, and if so, would this work:

    \\fileserver\<share>\*.exe ??

    Can I use this to restrict just .exe's and zip's from that share? Or is that overkill given the file types cover .exe and more?

    Sorry - probably a v silly question, but one I need reassurance on!

  2. #2

    Join Date
    Feb 2006
    Posts
    1,187
    Thank Post
    0
    Thanked 1 Time in 1 Post
    Rep Power
    0

    Re: Software Restriction Policy (w2k3) - path question

    It appears that you are attemptign a blocking list. A better approach would be to specifcify approved locations such as
    Code:
    "C:\Program Files", "C:\Windows" \\<domain_name>\SYSVOL
    This way you don't have to be so explicit in what you are trying to block because executables outside the approved areas won't be run.

  3. #3
    tarquel's Avatar
    Join Date
    Jun 2005
    Location
    Powys, Mid-Wales, UK
    Posts
    1,740
    Thank Post
    13
    Thanked 45 Times in 35 Posts
    Rep Power
    29

    Re: Software Restriction Policy (w2k3) - path question

    Nice one there

    I cant wait til i can get around to this R2 update

    Finding BitComet [P2P proggy] in a pupils user who just laughed at me when i had him was not enjoyable....

    touche [when i get R2 sorted hehe]

    Nath.

  4. #4
    mark's Avatar
    Join Date
    Jun 2005
    Posts
    3,986
    Thank Post
    269
    Thanked 52 Times in 46 Posts
    Blog Entries
    2
    Rep Power
    47

    Re: Software Restriction Policy (w2k3) - path question

    If you could set that restriction on one PC OU you could pick off the executable from the list of exclusions.

    This is how I found it works, by picking up the dissalowed list from the PC setting

  5. #5

    Join Date
    Sep 2006
    Location
    Essex
    Posts
    784
    Thank Post
    1
    Thanked 33 Times in 31 Posts
    Rep Power
    24

    Re: Software Restriction Policy (w2k3) - path question

    SRP is sometimes a bit like black magic. I have had no luck with wild cards although many say you can use them.

    I have also seen issues with SRP resolving the %username% variable.

    If you want to include a path restriction you may need to set it at a higher level eg: \\server\homefoldershare$\

    You may also want to add a SRP path rule for other dives like E: F: G: to prevent them running exe's from usb drives

  6. #6

    Join Date
    Feb 2006
    Posts
    1,187
    Thank Post
    0
    Thanked 1 Time in 1 Post
    Rep Power
    0

    Re: Software Restriction Policy (w2k3) - path question

    Just white list the approved locations then you won't have to worry about variable substition for home share UNCs. Same thing for removeable drives. IF they're not on the allowed list then the executables won't run from them.

SHARE:
+ Post New Thread

Similar Threads

  1. Software restriction policy, half working?
    By FN-GM in forum Windows
    Replies: 13
    Last Post: 10th December 2007, 12:22 PM
  2. Software Restriction Policy
    By cookie_monster in forum Windows
    Replies: 2
    Last Post: 27th November 2007, 12:54 PM
  3. CC3 Software Restriction Policy
    By cookie_monster in forum Network and Classroom Management
    Replies: 8
    Last Post: 12th June 2007, 10:28 AM
  4. Software Restriction Policy (w2k3) - path question
    By indiegirl in forum How do you do....it?
    Replies: 0
    Last Post: 19th October 2006, 10:11 AM
  5. GPo - Software Restriction Policy
    By Gatt in forum Wireless Networks
    Replies: 26
    Last Post: 23rd January 2006, 01:53 PM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •