How do you do....it? Thread, Software Restriction Policy (w2k3) - path question in Technical; Hello all,
I'm setting out SRP up to stop the little darlings from running exes etc from their home drives. ...
-
19th October 2006, 10:17 AM #1
- Rep Power
- 0
Software Restriction Policy (w2k3) - path question
Hello all,
I'm setting out SRP up to stop the little darlings from running exes etc from their home drives. I have searched for an answer to the query I'm about to pose but didn't find an answer.
So, my question is:
If I implement a 'path' restriction, eg:
\\fileserver\%username% - will that restrict everything in that path that's in the 'file types' properties (I assume it does)
Can I - for peace of mind - also restrict just one type, and if so, would this work:
\\fileserver\<share>\*.exe ??
Can I use this to restrict just .exe's and zip's from that share? Or is that overkill given the file types cover .exe and more?
Sorry - probably a v silly question, but one I need reassurance on!
-
-
IDG Tech News
-
19th October 2006, 01:34 PM #2
- Rep Power
- 0
Re: Software Restriction Policy (w2k3) - path question
It appears that you are attemptign a blocking list. A better approach would be to specifcify approved locations such as Code:
"C:\Program Files", "C:\Windows" \\<domain_name>\SYSVOL
This way you don't have to be so explicit in what you are trying to block because executables outside the approved areas won't be run.
-
-
19th October 2006, 01:53 PM #3 Re: Software Restriction Policy (w2k3) - path question
Nice one there
I cant wait til i can get around to this R2 update
Finding BitComet [P2P proggy] in a pupils user who just laughed at me when i had him was not enjoyable....
touche [when i get R2 sorted hehe]
Nath.
-
-
19th October 2006, 02:07 PM #4 Re: Software Restriction Policy (w2k3) - path question
If you could set that restriction on one PC OU you could pick off the executable from the list of exclusions.
This is how I found it works, by picking up the dissalowed list from the PC setting
-
-
19th October 2006, 02:26 PM #5 Re: Software Restriction Policy (w2k3) - path question
SRP is sometimes a bit like black magic. I have had no luck with wild cards although many say you can use them.
I have also seen issues with SRP resolving the %username% variable.
If you want to include a path restriction you may need to set it at a higher level eg: \\server\homefoldershare$\
You may also want to add a SRP path rule for other dives like E: F: G: to prevent them running exe's from usb drives
-
-
19th October 2006, 05:05 PM #6
- Rep Power
- 0
Re: Software Restriction Policy (w2k3) - path question
Just white list the approved locations then you won't have to worry about variable substition for home share UNCs. Same thing for removeable drives. IF they're not on the allowed list then the executables won't run from them.
-
SHARE:
Similar Threads
-
By FN-GM in forum Windows
Replies: 13
Last Post: 10th December 2007, 01:22 PM
-
By cookie_monster in forum Windows
Replies: 2
Last Post: 27th November 2007, 01:54 PM
-
By cookie_monster in forum Network and Classroom Management
Replies: 8
Last Post: 12th June 2007, 10:28 AM
-
By indiegirl in forum How do you do....it?
Replies: 0
Last Post: 19th October 2006, 10:11 AM
-
By Gatt in forum Networks
Replies: 26
Last Post: 23rd January 2006, 02:53 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules