Jump to content

Recommended Posts

Posted

Hi,

 

I guess it must be possible, but I have a user from outside our school who comes in once a week with Students (from another School) who has

an encrypted container on a USB stick. Their school policy dictates that all data taken must be encrypted.

 

Now the problem I have (or not as my senior will not change our policy for 1 person) is that the container is some 3rd party executable that is self-decrypting

without any additional software installed on the machine that you plug your USB into.

Obviously we block exe and other binaries from executing for users for obvious reasons, but the IT guy at the other school manage to incorporate that program

on the USB stick and allow that to run whilst deny all other programs that shouldn't be run.

 

Is this possible with a domain GPO to allow a specific program to run, especially as this executable does not get installed to the station, just runs to decrypt its container?

 

Just curious as my line manager has told the other school where to go, but i'd like to know for future reference!

 

Thanks for your help!

Posted
You could clarify what software they are using to encrypt the USBs it might be Bitlocker for example, which will likely be free for your school to install and use anyway, so if it was installed it would allow them to decrypt their USB.
Posted

I stupidly forget to write down the software name, though I am pretty sure it is the manufacturers own type of encryption application you get on a Sandisk or Kingston USB thumb drive.

 

I know it is not Bitlocker, however, that would make it a lot easier! The only wall I face is my colleague who has told the other school that is to find another solution, but as a pure technical exercise would be great as I am unfamiliar with GPO and its implementation, my first IT job, we have RM CC4 so we rarely poke around AD :-( .

 

I'm guessing allowing by drive path would be erroneous if they plug in another device, the device may change device assignment letter? So, doing by hash rule might be best?

 

Cheers.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...