Jump to content

lafayette7674

Members
  • Posts

    5
  • Joined

  • Last visited

Reputation

0 Neutral

About lafayette7674

Personal Information

  • Location
    Chicago
  1. This is why I used the loopback address. So, a UNC path uses the "user-friendly" hostname OR an IP address... SOOOO... Since that is the IP address of every host with the loopback adapter installed AND every host on our network has the loopback adapter installed; rather than use the hostname which is DIFFERENT on every host I used the loopback address... AAAnd it worked fine. That's because it's the hidden admin share for EVERY workstation and it doesn't rely on DNS, not that it matters, but it also means I don't have to create an entry FOR EVERY machine using "what you said." Further, I'm not going to share the naming convention of our organization and it "deffo" did work. I digress.
  2. Why would that be against our network policy, Arthur? How would you know? Seriously, I was just posting the way I was so no one spent too much of their time sharing the first things first types of ideas. Moving on. I will give browsing to the hidden admin share a go. That's the type of answer I was looking for. Another way to get that hash rule to work. Thank you for your response Steve. I took the idea you offered and ran with it. We will test it and see. If it doesn't work I don't really know what else to try. We have separation of duties so at that point I will transfer it to the desktop guys.I used this path: \\127.0.0.1\c$\Program Files (x86)\Microsoft Office\Office15\OUTLOOK.EXE
  3. Thank you but our network policies are even more restrictive on servers. Oh that blasted compliance! lol
  4. We know this. However, we operate in a strict network environment and RSAT is NOT authorized on workstations. I should have said that wasn't an option in the OP but thank you kindly for your response. So, unfortunately, this is not an option.
  5. I am trying to create a quarantine policy for machines that have vulnerabilities. I need minimal software access and no internet connectivity. I have configured a proxy server of 0.0.0.0 and disabled the ability to change the proxy server for items in the OU with the Quarantine GPO. I need to enable software restriction which I have done following a TechNet article. I have the default set to "Disallow." The same is configured in User Configuration. However....... Programs are still running just fine. Namely, Microsoft Outlook. We need NO email access. I would like to create a hash rule however I can't do that because the program isn't installed on the servers, obviously, therefore I cant browse to the program and select it in the hash rule. If there is another way to create rules to stop software from running please advise. I have the software restriction policy set per Computer Configuration> Policies> Windows Settings> Security Settings> Software Restriction Policies> Additional Rules. Please see the attached screenshot. Thank you for your assistance. Again, specifically we do not want Outlook to run.
×
×
  • Create New...