Jump to content

Recommended Posts

Posted

Hello

 

I currently use McAfee with DLP Endpoint protection - this works well in that .exe and other files cannot be run or copied from the USB stick so blocked totally. It won't even let you copy the file anywhere.

 

I had it set so that all users (apart from admin) have denied access to .exe files as you can filter by OU in active directory.

 

However, I'm looking to change Antivirus solution which doesn't have the same feature.

 

I've created a Group Policy object which works when trying to directly access .exe files from USB drives (it says blocked by group policy).

However, it still allow you to copy it to the users own desktop or any other location (C: Drive new folder etc).

I've created a file server rule so they cannot copy .exe files to network drives, but need some way of stopping them being able to copy the files to anywhere else from the USB /external drives, ideally on a user basis so that admins can still log in to client PCs and install programs etc, but denied to all other users.

 

Can anyone help me out before I make the switch.

 

Thanks

Posted

Does that apply to within Office Applications as well?

I find office is a big loop hole as students cannot browse UNC paths from My computer but can from within an open/save as office dialogue box.

Posted

Can they still copy it to their own desktop and run though?

 

We've got the C drive hidden from pupils so they can still run things by the shortcut but can't navigate around it to copy stuff there.
Posted
Does that apply to within Office Applications as well?

I find office is a big loop hole as students cannot browse UNC paths from My computer but can from within an open/save as office dialogue box.

 

It's done through GPO and doesn't show up at all in Office or any other application (other than small bug in Impero but I've logged that for them to work on).

 

Can they still copy it to their own desktop and run though?

 

Not for us, we've got redirected Desktop to a common folder with Read Only permissions to the folder that it uses. If they use redirected desktop to a folder in their network drive then it shouldn't work either with the File System rules in place. If it's not redirected and is picking up a local desktop then it will probably work but I'm not sure why you'd use that option.

Posted

Have you tried location blocking of .exe's? That what we have deployed. In Group policy there are Software Restriction Polices, and we've specified everything to block, but allowed via Paths specified. So allow %PROGRAMFILES% etc. and then restrict read/write to the C: so students and staff alike cannot access, write and run their own executable's.

 

So when they chuck in a USB as we havn't specified the path nothing can run from there. Likewise if they copy it to their user spaces.

Posted
It's done through GPO and doesn't show up at all in Office or any other application (other than small bug in Impero but I've logged that for them to work on).

 

 

 

Not for us, we've got redirected Desktop to a common folder with Read Only permissions to the folder that it uses. If they use redirected desktop to a folder in their network drive then it shouldn't work either with the File System rules in place. If it's not redirected and is picking up a local desktop then it will probably work but I'm not sure why you'd use that option.

 

Really ? Id open Office Word or Excel ... On a limited user account and go to open and type in a UNC path to a server in the open dialogue box. Can you get to a server this way ?

Posted
Really ? Id open Office Word or Excel ... On a limited user account and go to open and type in a UNC path to a server in the open dialogue box. Can you get to a server this way ?

 

I can put in the server unc path and it navigates there but doesn't show any shared folders. If I navigate to a server that has "public" shares (ones not specified as hidden for everyone) I get "accessing \\servername has been disallowed". We're pretty tight with our NTFS permissions on folders and shares so it's probably possible if you haven't locked it down tighter than needed.

  • Thanks 1
Posted
I can put in the server unc path and it navigates there but doesn't show any shared folders. If I navigate to a server that has "public" shares (ones not specified as hidden for everyone) I get "accessing \\servername has been disallowed". We're pretty tight with our NTFS permissions on folders and shares so it's probably possible if you haven't locked it down tighter than needed.

 

Nice one.

Posted
I use a GPO to block them running .exe's etc. as well as hiding C Drive so on so forth, basically what everyone else uses. I also use ESET Endpoint Protection and File Resource manager to stop people putting batch files, cscripts and anything else on the server.
Posted (edited)

Hiding C: will stop it showing up in office/explorer etc, but it there is a way to browse C: from within word. Not sure how tech savy your users are but putting this as a hyper link will allow you you bring up C: in an explorer window.

 

\\127.0.0.1\C$

 

Permission settings will detirmin what damage they can do.

Edited by Patrick
Posted

Users are unable to access UNC paths etc from Explorer, however they are still able to access UNC paths from within Office 2010, but I gather that the same policy should enforce it there also.

 

However, as for the C:\ drive they cannot access it from explorer, and the C: drive doesn't show in the open/save box however in the file name box if they type in C:\ it opens up the C: drive which I gather it's not meant to?

 

 

Hiding C: will stop it showing up in office/explorer etc, but it there is a way to browse C: from within word. Not sure how tech savy your users are but putting this as a hyper link will allow you you bring up C: in an explorer window.

 

\\127.0.0.1\C$

 

Permission settings will detirmin what damage they can do.

Posted

That's what I haven't worked out yet - why it works with explorer and not office.

Looks like I'll have to create a new OU and disable heritance, apply the setting and see if it works..

 

I assume it is the "User Configuration | Administrative Templates | Start Menu and Taskbar and then ‘Remove Run menu from Start Menu’ option?

 

 

Yes, it shouldn't do that. I get an error saying access to this resource is not allowed. Or something along those lines.
Posted

Hi

can any one help me with this problem???

I've created a brand new OU with a new simple domain user, so that no GPOs are applied.

If then create and assign a single GPO object with the 'remove run menu from start menu' it still only has effect from within my computer , but from within Office I can still type a UNC path into the open/save Dialog box.....

Posted
Hiding the c drive is a waste of time. Right click, new shortcut, put whatever you want in there \\localhost\c$, hit save 2x (normally get an error the first time) and viola. Office not required.
Posted
Hiding the c drive is a waste of time. Right click, new shortcut, put whatever you want in there \\localhost\c$, hit save 2x (normally get an error the first time) and viola. Office not required.

 

That assumes pupils can make shortcuts, or even right click in places where shortcuts can be made.

Posted

If you have redirected desktops with FSRM blocking .lnk files then they won't have permission to.

 

Hiding the c drive is a waste of time. Right click, new shortcut, put whatever you want in there \\localhost\c$, hit save 2x (normally get an error the first time) and viola. Office not required.
Posted

They can make the shortcut on their home PC and run it from a flash drive. If you block flash drives, they can email the shortcut to themselves and run it from temp.

 

Yes, if you block .lnk files through GPO that might stop that, but open a whole new can of worms / work for you to do.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...