Jump to content

Recommended Posts

Posted

Good Evening,

 

I'm looking to implement some software retriction policies on our network. Our clients are Windows 7 SP1 pro and DC is Server 2012 R2.

 

Basically, is it better to deploy SRPs via user policy or computer policy?

 

Also, what would be the recommended path / hash rules to put in place to allow certain things to run if we go down the route of disallowing everything in the first instance?

 

Many Thanks

David

Posted
User policy,however I would not use SRP as it's the old method. I would use applocker, it blocks everything and allow what I say rather than allow everything and block what I say
Posted
Would certainly look into Applocker but doesn't work with Windows 7 Professional unfortunately. Only enterprise or ultimate editions.
Posted

We do our SRP as a computer policy. When originally setting it up, I read in a couple of places that doing it as a user policy wasn't as reliable (can't offer any more detail to support that, though).

 

Would strongly recommend building it as a default disallow from the start. Just do some thorough testing and also make sure to communicate well with staff about what's happening, to help you mop up the obscure paths.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...