Jump to content

Recommended Posts

Posted

So I want to prevent students using Search to find MMC.exe

I have put in an Applocker exe Deny Path rule and applied it to students.

 

%WINDIR%\System32\mmc.exe

 

 

Students are still able to open MMC.exe via search.

 

Any ideas please?

Posted

User Configuration / Policies / Administrative Templates / Windows Components / Microsoft Management Console

* Restrict the user from entering author mode

* Restrict users to the explicitly permitted list of snap-ins

 

Enable both. Don't permit any snap-ins. As it's a per user policy, apply to only the students.

 

And my guess as to still being able to run MMC.exe from search, does also blocking %WINDIR%\SysWOW64\mmc.exe help?

 

Bryn

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...