db2995 Posted May 25, 2017 Posted May 25, 2017 Good Evening, I'm looking to implement some software retriction policies on our network. Our clients are Windows 7 SP1 pro and DC is Server 2012 R2. Basically, is it better to deploy SRPs via user policy or computer policy? Also, what would be the recommended path / hash rules to put in place to allow certain things to run if we go down the route of disallowing everything in the first instance? Many Thanks David
deano Posted May 25, 2017 Posted May 25, 2017 User policy,however I would not use SRP as it's the old method. I would use applocker, it blocks everything and allow what I say rather than allow everything and block what I say
db2995 Posted May 25, 2017 Author Posted May 25, 2017 Would certainly look into Applocker but doesn't work with Windows 7 Professional unfortunately. Only enterprise or ultimate editions.
jthompson Posted May 25, 2017 Posted May 25, 2017 We do our SRP as a computer policy. When originally setting it up, I read in a couple of places that doing it as a user policy wasn't as reliable (can't offer any more detail to support that, though). Would strongly recommend building it as a default disallow from the start. Just do some thorough testing and also make sure to communicate well with staff about what's happening, to help you mop up the obscure paths. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now