Jump to content

Recommended Posts

Posted

i got around this by setting the policy to not run any EXEs by default, and then enabling the running of EXEs (exceptions) from %windir% %programfiles% any network location that requires them.

 

i tried at one stage to prevent this too but the zip runs the exe from the users temp folder which would be in the %appdata% folder. in the end i bit the bullet and disabled the running of exes and vbs and cmd etc etc and just making a list of exceptions only around 20

 

Software Restriction Policies/Security Levels

Policy Setting

Default Security Level Disallowed

Software Restriction Policies/Additional Rules

Path Rules

%LOGONSERVER%\NETLOGON

Security Level Unrestricted

Description

Date last modified 29/02/2008 10:45:30

%logonserver%\sysvol

Security Level Unrestricted

Description

Date last modified 29/02/2008 11:24:07

%programfiles%

Security Level Unrestricted

Description

Date last modified 29/02/2008 10:58:56

%windir%

Security Level Unrestricted

Description

Date last modified 29/02/2008 11:03:39

\\Myserver\netlogon

Security Level Unrestricted

Description

Date last modified 29/02/2008 11:35:12

\\Myserver\sysvol

Security Level Unrestricted

Description

Date last modified 29/02/2008 11:35:21

\\mydfs\dfs\programs

Security Level Unrestricted

Description

Date last modified

  • Thanks 1
Posted
Be careful with restricting exes in the %temp% folder, we had a problem with some older serif software not working because it copied stuff to the %temp% folder to run

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...