Jump to content

Software Restriction Policies - Allow ONLY certain software


Recommended Posts

Posted
But is that file/path name user specific or does it just ban that whole exe on the network?

 

The path rule disallows it running from that path for any user to whom that gpo applies.

The hash rule will prevent that executable (renamed or not) from running anywhere for any user to whom that gpo applies.

 

Hash rule can be subverted by new versions / recompiling the app to change the hash only.

 

There's also (on 2003R2+) filtering options on the fileserver - we block executables in student user areas, for example.

  • Thanks 1
Posted

Administrative Tools > File Server Resource Manager > File Screening Management.

 

Look at the default templates, create a test folder tree and have a play. I'd advise against applying them at the root of the homedir folder tree, since you may wish to differentiate between groups of users. Ours has driveletter:\users\usergroup01 and we apply the template at the usergroup01 (or 02, 03) level.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...