Jump to content

Recommended Posts

Posted

Can't you just not give the users admin permissions so they can't install other browsers? 

Can you use a default deny policy applocker policy through intune (so only whitelisted apps will run) or even a blanket can't run exe files from their documents/downloads/USB drives? I know you can do this with local/domain applocker policies.

Posted

Do you think that a second/alternate browser would useful for redundancy? 

 

What about the day when Edge breaks after an update?

  • Like 1
Posted
Spoiler

 

I used to block everything when I had a flat network but the users are taking their devices home now. 

 

I want them to use Edge as that's what the Smoothwall cloud filter is installed on. The end users are able to install browsers even without admin privileges as some put it in their user profiles.   None have admin rights, just standard users. 

 

I didn't want to AppLocker them to death like desktops as I don't mind them playing games at home if they want. It does look like they can install Roblox on their devices which we block with Senso in school time. 

 

Senso will still pick up anything they do outside of school anyway but the cloud filter is obviously a problem in they use other browsers. 

Posted
15 minutes ago, Rob_D said:

Can't you just not give the users admin permissions so they can't install other browsers?

This, how are they installing anything?

Posted

Depending on your environment and use case, they shouldn't be able to install anything. However, browsers often install in the user profile so may get through more of your restrictions - I block users from downloading executables too.

 

I have not had any users need a second browser for redundancy - that'd usually be Chrome, and if it doesn't work in Edge it's unlikely to work in Chrome!

Posted

Although both Chromium, we have had instances of one browser working but not the other.

 

We’re not using Intune, so restrict executables from appdata.

 

Roblox is often regarded as a Safeguarding issue on school owned devices.

Posted

Since you mention Intune I'm guessing they are not on a domain?  If they are you can block whatever .exe you want with group policy.

 

We have also used Sophos to block browsers as well.  Does your AV app allow blocking?

 

All that being said if a device is not personal (meaning paid for by the taxpayers) I see no reason for end users to have admin rights.  Just asking for problems and dancing with liability IMHO.

Posted
1 hour ago, Simcfc73 said:

Just to confirm they do not have any admin rights

Are they stand alone or do they sync to your Domain?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...