Windows Thread, problem with software access policy in Technical; We have setup software access policys so that they disallow .exe being run from D:,E:,F:, and from desktops.
We have ...
-
22nd February 2007, 05:25 PM #1
- Rep Power
- 11
problem with software access policy
We have setup software access policys so that they disallow .exe being run from D:,E:,F:, and from desktops.
We have allowed unrestricted access to the shared area.
This all works fine. The Z:\ which is mapped to the user home dir doesn't work.
I 've set Z: so that it is disallowed, I can still run exe file from this drive.
All other drives are mapped with login scripts.
what going wrong?????
-
-
IDG Tech News
-
22nd February 2007, 05:46 PM #2 Re: problem with software access policy
I think the best way to do software restriction is on a 'white list' basis. Rather than trying to deny execution from certain paths, do a flat 'deny' from everywhere and then open up specific paths (eg C:\Program Files, C:\Windows etc).
-
-
22nd February 2007, 06:36 PM #3 Re: problem with software access policy
If you really must blacklist, blacklist the UNC of the shared drive rather than the drive letter.
But ajbritton is right, it is much more logical to block everything and allow a specific set of programs through.
-
-
22nd February 2007, 06:50 PM #4 Re: problem with software access policy
Agreed, set your SRP to DISALLOWED by default, then open up the programs you want via either PATH or HASH rules.
Hash rules are a better choice, as it prevents kids from renaming the files to an allowed filename so they can run them.
-
-
23rd February 2007, 11:06 AM #5
- Rep Power
- 11
Re: problem with software access policy
We have it now to block all.
I'm then adding in paths rules to allow the shared area and the multimedia drive.
When i login as test the software policy is stopping the login script setup the P: and Y: drives.
The rules i set for these 2 drives are using drive letters. Should i be using the unc path to the shared folder?
-
-
23rd February 2007, 11:32 AM #6 Re: problem with software access policy
-
-
23rd February 2007, 11:39 AM #7 Re: problem with software access policy
Just a thought here but i believe drive Z is used in the system for something when it comes to batch / command scripts etc....
Sorry i cant be that clear, but all I can remember is that I was trying to do something using drive Z and when I used a different drive letter, it worked.
Maybe this is why you had:
've set Z: so that it is disallowed, I can still run exe file from this drive.
Nath.
-
-
23rd February 2007, 11:46 AM #8 Re: problem with software access policy
We have z: as our home drives wiht no problems.
-
-
23rd February 2007, 11:49 AM #9 Re: problem with software access policy
Odd...
well whatever it was, I remember we discussed it on here lol
Nath.
-
-
23rd February 2007, 11:56 AM #10 Re: problem with software access policy
I set removable drives to start at Z: and go backwards, perhaps that's what you were thinking of tarquel?
-
-
23rd February 2007, 12:19 PM #11
- Rep Power
- 11
Re: problem with software access policy
thanks guys for your help.
I've just got it to work.
I'm not using disallow all.
To get the home shares drive Z; to work i had to add
Z:\%username% disallow
-
SHARE:
Similar Threads
-
By cookie_monster in forum Network and Classroom Management
Replies: 8
Last Post: 12th June 2007, 10:28 AM
-
By localzuk in forum Windows
Replies: 14
Last Post: 16th February 2007, 08:14 PM
-
By timbo343 in forum Windows
Replies: 35
Last Post: 13th October 2006, 02:23 PM
-
By Gatt in forum Networks
Replies: 26
Last Post: 23rd January 2006, 02:53 PM
-
By woody in forum School ICT Policies
Replies: 24
Last Post: 8th November 2005, 11:47 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules