caffrey Posted May 16, 2017 Posted May 16, 2017 I only have the one, all it does is create the FSRM file screens/groups for all your shares - saves a bit of time
ozydave Posted May 16, 2017 Posted May 16, 2017 Yep, If you done have FSRM installed on server in question run the script reboot then run again it will then created the file screen templates. I already had FSRM on one server so just ran the script. It knew I had it installed but just created the screen templates
Archipelego1 Posted May 17, 2017 Posted May 17, 2017 We've just implement FSRM filters. Anyone had FSRM screening save their bacon?
PotNoodleTech Posted May 18, 2017 Posted May 18, 2017 Yeh I've just implemented FSRM too. It's such a good bit of software and the guy who made the powershell scripts is a saint!! Literally one click and 5 mins per server and job done. Now that I've got this software on im gonna start adding some more lists. No more .bat .lnk .exe etc etc for my users!!
penfold Posted May 18, 2017 Posted May 18, 2017 As mentioned in another thread - Just check your FileScreens before you do this as you could end up losing existing ones - Part of the script deletes the File Screen and then re-creates a new one. If you have additional file screens on the default shares they will be lost. I've just remembered that I had an media file block on one of my shares and that's gone. If you are using the original script from this thread then the one linked by @caffrey wont include the powershell command to automatically block mapped drives for that user. I've applied both at the minute but will be looking to combine them in the future.
Areku Posted May 18, 2017 Posted May 18, 2017 or mp3's or swf or mpg or avis..... MWA HA HA H AH AHA... (we have a separate shared area for our multimedia students 1
Arthur Posted October 24, 2017 Posted October 24, 2017 (edited) Click the link for more details. Windows Defender Exploit Guard: Reduce the attack surface against next-generation malware Windows Defender Exploit Guard is a new set of intrusion prevention capabilities that ships with the Windows 10 Fall Creators Update. The four components of Windows Defender Exploit Guard are designed to lock down the device against a wide variety of attack vectors and block behaviors commonly used in malware attacks, while enabling enterprises to balance their security risk and productivity requirements. The four components of Windows Defender Exploit Guard are: Attack Surface Reduction (ASR): A set of controls that enterprises can enable to prevent malware from getting on the machine by blocking Office-, script-, and email-based threats Network protection: Protects the endpoint against web-based threats by blocking any outbound process on the device to untrusted hosts/IP through Windows Defender SmartScreen Controlled folder access: Protects sensitive data from ransomware by blocking untrusted processes from accessing your protected folders Exploit protection: A set of exploit mitigations (replacing EMET) that can be easily configured to protect your system and applications Attack Surface Reduction (ASR): Intelligence to control the surface area of the device Email and Office applications are generally thought of as keystones of enterprise productivity, yet they are the most common vector for attacks and can cause nightmares for security administrators. Both Office and email serve as simple and easy ways to distribute mechanism for bad actors to kick off malware and fileless attacks. Although Office macros and scripts have many productive use cases, malicious actors can use them to directly perform exploits that operate entirely in memory and are often undetectable by traditional AV techniques. All it takes is for a single user to enable macros on a legitimate-looking Office file, or to open an email attachment that executes a malicious PowerShell script, to compromise a machine. Attack Surface Reduction provides enterprises with a set of built-in intelligence that can block the underlying behaviors used by these malicious documents to execute without hindering productive scenarios. By blocking malicious behaviors independent of what the threat or exploit is, ASR can protect enterprises from never before seen zero-day attacks like the recently discovered CVE-2017-8759, CVE-2017-11292, and CVE-2017-11826. The different behaviors ASR provides coverage for in Fall Creators Updated are split among Office, scripts, and email. For Office apps, ASR can: Block Office apps from creating executable content Block Office apps from launching child process Block Office apps from injecting into process Block Win32 imports from macro code in Office Block obfuscated macro code Although malicious Office macros are oftentimes responsible for utilizing techniques like injection and launching of executables, ASR can also protect end-users from emerging exploits like DDEDownloader, which has been recently gaining in popularity. This exploit uses the Dynamic Data Exchange (DDE) popup in Office Documents to run a PowerShell downloader; however, in doing so, it launches a child process that the corresponding child process rule blocks. For script, ASR can: Block malicious JavaScript, VBScript, and PowerShell codes that have been obfuscated Block JavaScript and VBScript from executing payload downloaded from internet To highlight the intelligence behind ASR, we can look at how it can address obfuscated code as an example; in this case, there is a machine learning model powering our obfuscation detection capabilities that gets retrained multiple times per week in our cloud protection service. The model is updated on client, where it interfaces with Antimalware Scan Interface (AMSI) to make a determination on whether or not a script has been obfuscated for malicious purposes. When a high-confidence match occurs, any attempt made to access the script is blocked. For email, ASR can: Block execution of executable content dropped from email (webmail/mail-client) Enterprise administrators can set policies on their corporate email (e.g., Office 365) to limit the files that can be delivered to end user inboxes. However, they don’t have control over the files that are delivered via personal email on company devices. Given the increase in spear-phishing, employees' personal emails are also targeted and need to be protected. ASR enables enterprise administrators to apply file policies on personal email for both webmail & mail-clients on company devices. For any line of business applications running within your enterprise, there is the capability to customize file and folder based exclusions if your applications include unusual behaviors that may be impacted by ASR detection. ASR has a dependency on Windows Defender Antivirus being the primary AV on the device and its real-time protection feature must be enabled. The Windows 10 Security baseline recommends enabling most of the rules in Block Mode to protect your devices from these threat vectors. Edited October 24, 2017 by Arthur 4
mavhc Posted October 24, 2017 Posted October 24, 2017 Looks like it works on Pro and Education versions too, not just Enterprise. EMET for all!
gaz350b Posted October 25, 2017 Posted October 25, 2017 Also if your looking for the GPO ASR its in Windows components > Windows Defender Anti-Virus > Exploit Guard and not Windows components > Exploit Guard which only has 1 policy.
Popular Post Arthur Posted January 31, 2018 Popular Post Posted January 31, 2018 Security baseline for Office 2016 and Office 365 ProPlus apps – DRAFT Microsoft is pleased to announce the draft release of the recommended security configuration baseline settings for Microsoft Office Professional Plus 2016 and Office 365 ProPlus 2016 apps. Please evaluate this proposed baseline and send us your feedback via blog comments below. Download the content here: Office-2016-baseline-DRAFT The downloadable attachment to this blog post includes importable GPOs, scripts for applying the GPOs to local policy, a custom administrative template (ADMX) file for Group Policy settings, all the recommended settings in spreadsheet form and as Policy Analyzer rules. The recommended settings correspond with the Office 2016 administrative templates version 4639 released on December 15, 2017 that can be downloaded here. Instead of retaining the entire Office 2013 baseline and simply adding settings that were newly introduced in the Office 2016 GPOs, we have conducted a thorough review of all available configuration settings – as we did beginning with the Windows 10 baselines – including in the baseline only those settings that address contemporary security threats. In the process we removed over eight dozen settings that had been in previous baselines but that were determined not to advance security posture in a meaningful way, and added a handful of new settings. The result is a more streamlined, purposeful baseline that is easier to configure, deploy, and validate. Macro security Office’s support for macros remains a vital tool for enterprise automation and at the same time a vector for attack, so macro security remains an important consideration. Office 2016 introduced a new GPO setting, “Block macros from running in Office files from the Internet” that was also later backported to Office 2013. Enabling the setting disables macros embedded in Office documents that came from the internet, including through email from an external sender. Office displays a notification that does not give the user an option to enable the macros. This baseline enables the setting for all apps that offer it: Excel, PowerPoint, Visio, and Word. Because this setting affects only Office documents received from the Internet that contain embedded macros, we anticipate that enabling this setting should rarely if ever cause operational problems for enterprises. The settings do not affect documents that are received from the enterprise’s Intranet or Trusted Sites zones. The baseline also retains the “VBA Macro Notification Settings” options from our previous baselines that require that macros embedded in Office documents be signed by a trusted publisher. We recognize that some organizations have had workflows and processes relying on such macros for a long time, and that enforcing these particular settings can cause operational issues. It can also be challenging to identify all the documents and VBA projects that need to be signed. We are considering moving these settings into a separate GPO to make it easier to switch the settings on or off without affecting the rest of the baseline. Please let us know via the comments on this post what you think of that idea. Blocking Flash activation We have also added a setting to the custom “MS Security Guide” ADMX that prevents the Adobe Flash ActiveX control from being loaded by Office applications. Vulnerabilities in Adobe Flash are often exploited by sending the victim a Microsoft Office document that contains malformed Flash data and an OLE reference that activates Flash and passes it the malformed data, which triggers the exploit code. This setting allows you to either (1) block all activation of Flash from within Office or (2) only block activation of Flash when it is directly embedded or linked in an Office document. The baseline recommends that you block all activation as it is the safest option available but note that it can impact productivity scenarios (e.g. consuming embedded videos in PowerPoint) within your enterprise. Please test this setting within your environment to identify the appropriate level of protection that balances your security and productivity requirements. Office has long included a “kill-bit” feature similar to Windows’ that enables administrators to block specific controls from being activated within Office processes. Enabling the new setting in “MS Security Guide” configures Flash kill-bit registry values to block Flash activation in Office processes, reducing your security exposure. Other changes Although we have removed many settings from the baseline, there are a few changes to which we would like to call attention. All of these are under User Configuration\Administrative Templates. Microsoft Outlook 2016\Account Settings\Exchange, Authentication with Exchange Server: we are keeping this setting enabled, but changing its configuration from “Kerberos/NTLM Password Authentication” to “Kerberos Password Authentication.” We do not anticipate operational issues from strengthening this setting. Please test this change in your environments and let us know what you observe. Microsoft Office 2016\Manage Restricted Permissions, Always require users to connect to verify permission: we are removing this setting from the baseline, but there is a security and usability tradeoff, and our finding is that the security benefit is too small for the usability degradation. The setting ensures that if someone’s access to a rights-managed document or email is revoked after they have received it, they will be blocked from opening it the next time they try. The downside is that this blocks all offline access. In our experience, this kind of revocation is far less common than the need to open rights-managed items when in airplane mode. We have dropped the “Disable all trusted locations” Trust Center settings, but disabled two additional “Allow Trusted Locations on the network” settings that had been overlooked in past baselines for Project and Visio. We look forward to your feedback on this beta so that the final version strikes the correct balance between security and usability. Thank you. 5
Bob_the_Goon Posted January 31, 2018 Posted January 31, 2018 Hi Arthur. Where is the Block Flash activation in Office Documents policy within the ADMX templates. I can't seem to find it by manually searching or via a Google search. It'll just be me being thick though!
Arthur Posted January 31, 2018 Posted January 31, 2018 Where is the Block Flash activation in Office Documents policy within the ADMX templates. Once you have copied SecGuide.admx and SecGuide.adml to your central PolicyDefinitions folder from the download link above (the .adml goes in the en-US subfolder btw) you will find the policy at: Computer Configuration > Policies > Administrative Templates > MS Security Guide > [b]Block Flash activation in Office documents[/b] 1
Chuckster Posted January 31, 2018 Posted January 31, 2018 Will this prevent embedded clips such as from YouTube from working if you enable Block Flash activation in Office documents ?
Bob_the_Goon Posted January 31, 2018 Posted January 31, 2018 Will this prevent embedded clips such as from YouTube from working if you enable Block Flash activation in Office documents ? I wouldn't have thought so as YouTube uses HTML5, not Flash.
Arthur Posted February 1, 2018 Posted February 1, 2018 Goodbye boardworks lol Also Flash games students have hidden inside Office docs.
Arthur Posted February 1, 2018 Posted February 1, 2018 Will this prevent embedded clips such as from YouTube from working if you enable Block Flash activation in Office documents ? Not if you are using PowerPoint 2013 or 2016. @Bob_the_Goon is correct. https://support.office.com/en-us/article/are-you-having-video-or-audio-playback-issues-e0a94444-8ea7-4a00-974b-6ad0d6edc4b1?NS=POWERPNT&Version=16&SysLcid=1033&UiLcid=1033&AppVer=ZPP160&HelpId=103448&ui=en-US&rs=en-US&ad=US Google recently made a change where it has retired the Flash Player infrastructure that PowerPoint 2010 depends upon for playing YouTube videos. PowerPoint 2013 and PowerPoint 2016 are based on the HTML5 video playback infrastructure (instead of Flash Player) and are thus unaffected for the most part. We are aware of the issue in PowerPoint 2010 and are investigating what we can do, but practically speaking, the most effective method of resolving this issue quickly is moving to a newer version of Office (2013 or 2016). You can also use PowerPoint Online, which is free and can be used with a Microsoft account (Hotmail, outlook.com, live.com). PowerPoint Online allows for the insertion and playing of YouTube videos.
Fazza Posted February 1, 2018 Posted February 1, 2018 Also Flash games students have hidden inside Office docs. This is what we've been waiting for so testing it out now!!!
mavhc Posted February 1, 2018 Posted February 1, 2018 Imagine what will happen if the kids realise they can play games with just a pencil and paper, or even just in their own imagination, how will that be stopped?
Fazza Posted February 1, 2018 Posted February 1, 2018 Imagine what will happen if the kids realise they can play games with just a pencil and paper, or even just in their own imagination, how will that be stopped? Teacher Intervention will stop it. Much easier to see people with a pencil each drawing lines on a page full of dots (that's what I can remember doing) and making squares than minimising an Excel spreadsheet. I've implemented the GPO to prevent the Students playing Flash games in Excel so we'll see how long it lasts before they all find a workaround. Now just as long as we dont teach them to embed Flash in to a website using Serif WebPlus, oh hang on a minute!...
mavhc Posted February 1, 2018 Posted February 1, 2018 It'll be amusing when they try to embed html5 games
Arthur Posted February 13, 2018 Posted February 13, 2018 Security baseline for Office 2016 and Office 365 ProPlus apps – FINAL Download: Office-2016-baseline.zip Microsoft is pleased to announce the final release of the recommended security configuration baseline settings for Microsoft Office Professional Plus 2016 and Office 365 ProPlus 2016 apps. There are no changes from the draft release we published a few weeks ago, other than minor corrections within the spreadsheet.
DCUK6 Posted February 19, 2018 Posted February 19, 2018 Security baseline for Office 2016 and Office 365 ProPlus apps – FINAL Download: Office-2016-baseline.zip Are you able to download? Getting Network error here when i try.
Arthur Posted February 19, 2018 Posted February 19, 2018 Are you able to download? Getting Network error here when i try. Working fine here. Could it be proxy related? 1
mavhc Posted February 23, 2018 Posted February 23, 2018 It's always a good idea to have multiple layers of security rather than relying on a single product (even more so with AV software which tends to be quite buggy). ...which tends to be a way to run code at SYSTEM level just be emailing it to someone
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now