MMC Group Policy
We currently have a group policy for MMC snap-ins which is set to "Restrict users to the explicitly permitted list of snap-ins"
From here we obviously list all the snap-ins they are allowed to access. We now have a request to allow access to a new App-V snap-in.
The issue I have is this snap-in obviously isn't in the list to allow. By default if it has not been allowed it will be denied, so anyone trying to access the App-V snap-in gets the "This has been restricted by policy". The only way I can see around this, is to change the option "Restrict users to the explicitly permitted list of snap-ins" to disabled so all snap-ins are available, then put a deny on all those I don't wish to open up. As App-v is not on the list, it will now be allowed by default.
My issue is, I am now open for any future snap-ins to be run and will have no way to restrict them.
Anyone else got a similar setup.
If you open group policy editor from a machine with the app-v MMC installed do you see an option for it in group policy?
Thought you were onto something then, unfortunately it seems even when running from a Windows 7 machine with the client install, group policy doesn't show me thios option
Im out of ideas then, sorry :)
RSAT installed on the client with the appv snapin?
Well I logged an advisory call with Microsoft, and have been told this is not currently possible with a default GPO setting - They believe there is a registry setting that can be set via Group Policy Preference to enabled this. Currently waiting to be sent this info, but will update here when I've had chance to test to see if this works as expected.
Nice simple reg key fix in the end ;)
Thanks for letting us know :)