SimonInOz Posted August 16, 2019 Posted August 16, 2019 Hi, I have been using SRP's in a W10 EDU domain environment. According to this article: https://www.bleepingcomputer.com/forums/t/679012/microsoft-planning-to-scrap-software-restriction-policies-feedback-this/ These are gone, or going. The replacement suggested, Windows Defender Application Control doesn't seem to be for EDU machines: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control Just wondering if anyone else is in this position, and what you are using as a replacement. We do have some webroot licenses, but not enough and I would have to buy more. (not that thrilled with it TBH). Anyone using Sophos Endpoint? Cheers
Arthur Posted August 16, 2019 Posted August 16, 2019 (edited) Just wondering if anyone else is in this position, and what you are using as a replacement. I used to use SRPs back when my school was using Windows XP, but switched to AppLocker after migrating to Windows 7 more than a decade ago and have been using it ever since (including with Windows 10 Education). Microsoft aren't getting rid of AppLocker any time soon. When it comes to configuring AppLocker properly you may find the following guide by the NCSC helpful. www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/eud-security-guidance-windows-10-1809#applockerconfig Edited August 16, 2019 by Arthur
SimonInOz Posted August 16, 2019 Author Posted August 16, 2019 Thanks Arthur, we use mostly Adobe/O365 plus a few other apps, so I am guessing this would be safe for that sort of environment? I will need to do some testing, but looks pretty comprehensive. many thanks for the link and post. Cheers.
Arthur Posted August 19, 2019 Posted August 19, 2019 we use mostly Adobe/O365 plus a few other apps, so I am guessing this would be safe for that sort of environment? My school is similar (Adobe CC & Office 2016/2019 etc.) so I don't think you will have any issues. Definitely test first however.
v01d Posted August 23, 2019 Posted August 23, 2019 Thanks Arthur, we use mostly Adobe/O365 plus a few other apps, so I am guessing this would be safe for that sort of environment? I will need to do some testing, but looks pretty comprehensive. many thanks for the link and post. Cheers. Make heavy use of AppLocker's 'audit' policy so that you can test thoroughly before implementing it and when making changes going forward. That should provide you with enough of an idea if issues suddenly crop up along the way.
free780 Posted August 24, 2019 Posted August 24, 2019 Depending on the size of your environment you can setup event forwarding and powershell daily blocks/audits.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now