woody Posted November 14, 2012 Posted November 14, 2012 Hi I've searched but can't find this specific question answered anywhere. We currently restrict applications via WGM, but this does not stop students bringing an app in on their flash drive and running it, either from the flash drive itself, or from the desktop after copying it. Has anybody come up with a solution for this? Ideally, I would like to restrict ALL aplications except those in the allow list. Many thanks Mark
dayzd Posted November 14, 2012 Posted November 14, 2012 Are you sure you've set up application permissions in WGM properly, because that's how it should be done. I never had a problem with it allowing stuff it shouldn't when I maintained a 10.6 network a couple of years ago. I think the essentials of how I did it was to allow programs to run only from within the Applications folder, excluded the Utilities folder then found ways to hide the Applications folder from logged in users. Pretty sure I used chflags hidden /Applications to achieve this.
woody Posted November 14, 2012 Author Posted November 14, 2012 Thanks dayzd I think I've figured it. The WGM settings were set up by a company as part of an Academy IT contract. This is how they have configured it: [ATTACH=CONFIG]15891[/ATTACH] I didn't notice the forward slash in the 'Allow applications within these folders' which obviously is allowing everything except those entries in the 'Dissalow' box. So I'll take this out and have a play to enable the correct applications. Thanks
dayzd Posted November 15, 2012 Posted November 15, 2012 That sounds like it'll be the cause of it! ...It's always something simple and easily overlooked, isn't it...?!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now