Hybrid Posted June 12, 2017 Posted June 12, 2017 Afternoon all, Does anyone have any guidance, other than adding the verified publishers of all the memory sticks' encryption software to AppLocker? I have a few users who have brought in encrypted memory sticks only for them to find out they can't run the decryption/mapping tool due to AppLocker's restrictions. Is adding the file hash rule the only real way of enforcing this? Many thanks.
Arthur Posted June 12, 2017 Posted June 12, 2017 I have a few users who have brought in encrypted memory sticks only for them to find out they can't run the decryption/mapping tool due to AppLocker's restrictions. Reformat memory stick and then encrypt with BitLocker. Problem solved?
Hybrid Posted June 12, 2017 Author Posted June 12, 2017 Reformat memory stick and then encrypt with BitLocker. Problem solved? Oh, only if life was that simple. The majority are people coming in from external agencies.
3s-gtech Posted June 12, 2017 Posted June 12, 2017 I've decided to provide the sticks myself, and have whitelisted the particular executable (and allowed it in SRP). The staff won't be allowed to use unencrypted sticks, but haven't yet found anyone that has bothered to Bitlocker their own and no-one has come to me with another brand of encrypted stick yet. Doubt they will when I'm providing them gratis!
Arthur Posted June 12, 2017 Posted June 12, 2017 That's a shame. I guess adding Publisher rules for the various memory stick manufacturers would be less work than maintaining a list of hash rules?
free780 Posted June 12, 2017 Posted June 12, 2017 Most encrypted usb sticks require administrator rights anyway. They need to load a driver. You have to get a tech to 'run as administrator'. Either that or you need the agent/driver/service deployed ahead of time. But most solutions require you to purchase to have this.
Hybrid Posted June 13, 2017 Author Posted June 13, 2017 Thanks guys. For now I'll just have to add them to the list as and when they come in.
3s-gtech Posted June 13, 2017 Posted June 13, 2017 I'm playing with Kingston Locker+ G3s and they don't need admin rights, just two sequential drive letters and the software allowed in Applocker and SRP.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now