sippo Posted July 9, 2010 Posted July 9, 2010 But is that file/path name user specific or does it just ban that whole exe on the network?
pete Posted July 9, 2010 Posted July 9, 2010 But is that file/path name user specific or does it just ban that whole exe on the network? The path rule disallows it running from that path for any user to whom that gpo applies. The hash rule will prevent that executable (renamed or not) from running anywhere for any user to whom that gpo applies. Hash rule can be subverted by new versions / recompiling the app to change the hash only. There's also (on 2003R2+) filtering options on the fileserver - we block executables in student user areas, for example. 1
sippo Posted July 9, 2010 Posted July 9, 2010 Thanks Pete. Where can I find the filtering options in 2003r2?
pete Posted July 9, 2010 Posted July 9, 2010 Administrative Tools > File Server Resource Manager > File Screening Management. Look at the default templates, create a test folder tree and have a play. I'd advise against applying them at the root of the homedir folder tree, since you may wish to differentiate between groups of users. Ours has driveletter:\users\usergroup01 and we apply the template at the usergroup01 (or 02, 03) level. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now