mdrabble Posted July 20, 2015 Posted July 20, 2015 I've just about finished sorting GPOs etc on my newly configured domain and about to go live at the beginning of August. I am going to be deploying Win7 Enterprise on all workstations so staff can encrypt USB devices using Bitlocker and thought should I use AppLocker or SRP to block .exe and other files. Old domain uses SRP as there was a mixture of Enterprise and Pro workstations. What are peoples thoughts on this? Cheers
minimoo Posted July 20, 2015 Posted July 20, 2015 My understanding was that applocker was windows 7 and above. SRP only worked on XP and below. I might be wrong here, but those thoughts are backed up by https://technet.microsoft.com/en-us/library/ee424371(v=ws.10).aspx So Applocker would seem to be the only choice Only thing that's interesting about that page is there is a note from microsoft saying using different GPO's for applocker vs srp rules
Arthur Posted July 21, 2015 Posted July 21, 2015 should I use AppLocker or SRP to block .exe and other files. AppLocker since Publisher Rules are very handy (SRP doesn't have these) and thinking about the future, you would need AppLocker to block Windows Store apps should you upgrade to Windows 10. My understanding was that applocker was windows 7 and above. SRP only worked on XP and below. AppLocker was introduced with Windows 7 although only the Enterprise and Ultimate editions can actually enforce AppLocker policies. This means that you would have to use SRP with the Pro edition of Windows 7. http://vgy.me/LORhKJ.png Source: https://en.wikipedia.org/wiki/Windows_7_editions#Comparison_chart
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now