|
Guy recommends :
Find out which of your VMs are a waste of space and which VMs need more resources.
|
Group Policy Software RestrictionsGroup Policy Security Settings - Software RestrictionsHere was a setting that I thought did not exist! I once undertook a project to prevent 95% of .vbs script files from running in a customer's domain. These would be the 'bad guys', viruses or rogue scripts. Disabling the 'bad guys' was the easy part. However, being positive and allowing the 'good guy's, required major exploration of Group Policies. What the customer wanted was to allow only logon scripts and maintenance .vbs scripts to execute, all other .vbs files must be stopped from running on his Windows Server 2003. Once I was convinced that Software Restrictions could be controlled by a Group Policy, my next problem was finding it amongst the myriad of settings. Well, a picture is worth a thousand words, so here is where I ran down the Software Restriction Policy. Computer Configuration Windows Settings Security Settings Software Restrictions Creating the Software Restrictions Group PolicyPath or Hash? If you take the trouble to get a hash value for the program you want to prevent, then savvy users cannot simply copy and paste the application to a new location. The trouble with the path is that it just restricts the program from running from one location, whereas the hash rule prevents any program with that hash value running from anywhere on the machine. Beware that this Restriction affects administrators, so it's probably a Group Policy to apply to workstations or laptops rather than servers. If you did want a path restrictions, then once you reach the Software Restrictions folder, drill down to 'Additional Rules', then right click, and select ... New Path Rule. The final part is logical and transparent, just select the path where the 'good guys' hang out. For example, where the logon scripts resided on a DC, or where the malignance scripts are to be found on an XP machine. Do double check your logic, do want this path allowed or disallowed? Only you know the answer to that question.
Guy Recommends: Solarwinds' Log & Event Management Tool
| ||||
Custom Search
|
Guy Recommends:
|
|
Home Copyright © 1999-2012 Computer Performance LTD All rights reserved Please report a broken link, or an error. | |