PC Review


Reply
Thread Tools Rating: Thread Rating: 1 votes, 1.00 average.

Applying Deny All Software Restriction

 
 
Jim
Guest
Posts: n/a
 
      28th Feb 2008
I am creating a new GPO for Software restrictions. I have set the default
rule to "Software will not run, regardless of the access rights of the user."
We are creating a desktop image that we know exactly what applications will
be allowed to run. I figured this was a perfect candidate for blocking all
applications.

I am testing out the GPO. I have created a Hash Rule for Roxio Classic
Creator and set that rule to Unrestricted.

I go to click on the Shortcut for Roxio and I get a message saying that that
Roxio executable is blocked by the SRP. I go to the Event Log and see this:

Event Type: Warning
Event Source: Software Restriction Policies
Event Category: None
Event ID: 865
Date: 2/27/2008
Time: 9:21:08 AM
User: N/A
Computer: BLUEMAX
Description:
Access to C:\Documents and Settings\pds2\Start Menu\Programs\Roxio Easy
Media Creator 9\Data\Creator Classic.lnk has been restricted by your
Administrator by the default software restriction policy level.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

So I try to create a hash rule for the LNK file, but the hash is the same as
the actual Executable and I still get the same error.

I took the LNK out of the Designated file types and it allowed the Roxio
Classic Creator to run, but it also allowed everything to run.

Is there something wrong I am doing or other documentation on to create a
SRP that will block everything except what I want to run?

 
Reply With Quote
 
 
 
 
Gis Bun
Guest
Posts: n/a
 
      28th Feb 2008


"Jim" wrote:

> I am creating a new GPO for Software restrictions. I have set the default
> rule to "Software will not run, regardless of the access rights of the user."
> We are creating a desktop image that we know exactly what applications will
> be allowed to run. I figured this was a perfect candidate for blocking all
> applications.
>
> I am testing out the GPO. I have created a Hash Rule for Roxio Classic
> Creator and set that rule to Unrestricted.
>
> I go to click on the Shortcut for Roxio and I get a message saying that that
> Roxio executable is blocked by the SRP. I go to the Event Log and see this:
>
> Event Type: Warning
> Event Source: Software Restriction Policies
> Event Category: None
> Event ID: 865
> Date: 2/27/2008
> Time: 9:21:08 AM
> User: N/A
> Computer: BLUEMAX
> Description:
> Access to C:\Documents and Settings\pds2\Start Menu\Programs\Roxio Easy
> Media Creator 9\Data\Creator Classic.lnk has been restricted by your
> Administrator by the default software restriction policy level.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> So I try to create a hash rule for the LNK file, but the hash is the same as
> the actual Executable and I still get the same error.
>
> I took the LNK out of the Designated file types and it allowed the Roxio
> Classic Creator to run, but it also allowed everything to run.
>
> Is there something wrong I am doing or other documentation on to create a
> SRP that will block everything except what I want to run?


Deny should only be used when any other option does not work [i.e a last
resort].

You are better off to remove the permission than denying.


 
Reply With Quote
 
Kam
Guest
Posts: n/a
 
      7th May 2008
I've had to put in these Additional Path Rules (as Unrestricted):

*.lnk
C:\Documents and Settings\All Users\Start Menu
c:\Documents and Settings\All Users\Desktop

Kam.

"Jim" wrote:

> I am creating a new GPO for Software restrictions. I have set the default
> rule to "Software will not run, regardless of the access rights of the user."
> We are creating a desktop image that we know exactly what applications will
> be allowed to run. I figured this was a perfect candidate for blocking all
> applications.
>
> I am testing out the GPO. I have created a Hash Rule for Roxio Classic
> Creator and set that rule to Unrestricted.
>
> I go to click on the Shortcut for Roxio and I get a message saying that that
> Roxio executable is blocked by the SRP. I go to the Event Log and see this:
>
> Event Type: Warning
> Event Source: Software Restriction Policies
> Event Category: None
> Event ID: 865
> Date: 2/27/2008
> Time: 9:21:08 AM
> User: N/A
> Computer: BLUEMAX
> Description:
> Access to C:\Documents and Settings\pds2\Start Menu\Programs\Roxio Easy
> Media Creator 9\Data\Creator Classic.lnk has been restricted by your
> Administrator by the default software restriction policy level.
>
> For more information, see Help and Support Center at
> http://go.microsoft.com/fwlink/events.asp.
>
> So I try to create a hash rule for the LNK file, but the hash is the same as
> the actual Executable and I still get the same error.
>
> I took the LNK out of the Designated file types and it allowed the Roxio
> Classic Creator to run, but it also allowed everything to run.
>
> Is there something wrong I am doing or other documentation on to create a
> SRP that will block everything except what I want to run?
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Deny Software installation John B Windows XP Setup 2 11th Mar 2004 01:17 AM
Deny Software installation John B Windows XP Security 1 10th Mar 2004 11:38 PM
Restriction message repeats while applying Group Policy =?Utf-8?B?RWxpemFiZXRo?= Microsoft Windows 2000 Active Directory 1 22nd Nov 2003 10:57 PM
Deny installing software Frank Windows XP Security 1 14th Nov 2003 06:48 PM
Deny software installation from cd rom and 3 1/2 Michael Counts Microsoft Windows 2000 Group Policy 1 10th Sep 2003 10:56 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:16 PM.