"Run only allowed Windows applications" blocks MS Office URLs

We want users to be able to open hyperlinks from MS Office apps, including mailto: and http:.

If the Group Policy "Run only allowed Windows applications" is set (under User Config | Admin Templates | System), then users opening hyperlinks from MS Office apps (including Outlook, Word, and Excel at least), see the standerd GP restriction error:

        This operation has been canceled due to restrictions in effect on this computer.  Please contact your system administrator.

Admins are NOT blocked, and if I disable that policy, neither are users.  It affects http: and mailto: urls, at least.

I can't figure out what the problem is.  Word, Excel, Oultook, Firefox and IExplore are listed as permitted in the policy and all run fine.  As far as I know, the policy allows any executable called by a permitted executable (this must be true, or I'd see errors everywhere).

I've tried the following; nothing worked.

  * Adding every executable in the MS Office install directory to the policy's whitelist
  * Adding these files to the policy whitelist:  mshtmled.dll, hlink.dll, mshtml.dll.  Filemon showed these being accessed when a hyperlink is clicked
  * Resetting this registry key per MS kb q310049:  HKEY_Local_Machine\Software\Classes\htmlfile\shell\open\command  (though any problem there should affect all users, including admins).
  * Adding "http://www.cnn.com" to the whitelist, then trying that url from Word.


Any suggestions would be much appreciated!
IntIncAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

IntIncAuthor Commented:
I should correct that first sentece (it would be nice if we could edit posts): We want to open links in the default app, whatever it is.  Our mailto handler is Outlook, for example.
0
Netman66Commented:
How about OLE?
0
IntIncAuthor Commented:
OLE works fine.  We can link, embed and edit linked/embedded files
0
How do you know if your security is working?

Protecting your business doesn’t have to mean sifting through endless alerts and notifications. With WatchGuard Total Security Suite, you can feel confident that your business is secure, meaning you can get back to the things that have been sitting on your to-do list.

IntIncAuthor Commented:
For anyone's future reference, here's what we found:

The problem only occurred in the following circumstance:
    1)  The 'run only allowed windows applications' group policy was enabled
    2)  Using Microsoft Office 2003 apps (though we didn't try other versions of Office)
    3)  Firefox was the default browser

Note that Firefox worked fine outside of MS Office links.

The solution was a combination of the following:

   1)  MS Office apparently does not use the Windows shell to process hyperlinks, but uses it's own internal process.  MS KB 218153 describes how to force it to use the shell
http://support.microsoft.com/default.aspx?scid=kb;en-us;218153

   2)  In the registry, paths to Firefox were expressed in the short filename format (e.g. c:\progra~1\Mozill~1\...).  It wouldn't work unitl we changed it to long filenames worked.  We don't know why.  We do know that when you set Firefox as teh default browser (firefox | tools | options | ... | set as default), it changes back to the short filename.

   3) The fix in this Microsoft KB article may have been required; it was over a month ago and I don't remember if it was necessary or not:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q280680


We found the solution on our own, so we are not awarding points.
0
LucFEMEA Server EngineerCommented:
I'll change my recommendation to PAQ/Refund.
Thanks for sharing your solution IntInc.

LucF
0
CetusMODCommented:
PAQed with points refunded (400)

CetusMOD
Community Support Moderator
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
OS Security

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.