After reading through every doc on microsoft.com that mentions DEP, and
sorting through all the information and contradictions therein, I've come to
this conclusion:
OptIn = Turn on DEP for essential Windows programs and services only =
exclude all 32-bit programs as a whole, except system binaries and services…
so, technically OptIn is a system-wide program opt-out (that doesn’t give you
the option to exclude specific programs - they are simply all excluded except
system binaries and services)
OptOut = Turn on DEP for all programs and services except those I select: =
include all 32-bit programs as a whole, and exclude whatever I add to the
list… echnically OptOut is a system-wide program opt-in that gives you the
option to opt-out of some of those programs that are automatically opted in
What do you DEP guys think? The documentation that Microsoft has on DEP as a
topic is in need of a number of corrections and revisions.
|