Solved

Blocking Software installation

Posted on 2010-11-30
4
325 Views
Last Modified: 2012-05-10
We have Windows 2003 Domain with all the domain Controllers running Windows 2003. We have got approx 10000 users. We have a requirement to block the Software installations in Desktops by users. We want to block .exe files from running but dont want to disturb the Windows internal executables. Is there a way to achieve that.

Many of the users in our environment are lacal admins so this creates problem.
0
Comment
Question by:Neo_78
  • 2
4 Comments
 
LVL 4

Expert Comment

by:jcurrie
ID: 34240322
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 125 total points
ID: 34240335
There are several methods one is the old "white list" in group policy

\user configuration\administrative templates\system  ….  “Run only specified Windows applications

It is not the greatest solution and the Microsoft AD team talked bout it in a mail sack last month (see question about halfway down)
http://blogs.technet.com/b/askds/archive/2010/10/08/friday-mail-sack-cluedo-edition.aspx

They mentioned app locker which is a Windows 7 feature but you can use software restriction policies  http://technet.microsoft.com/en-us/library/bb457006.aspx

Test on a few machines to get a feel for it.

Thanks

Mike
0
 
LVL 4

Assisted Solution

by:jcurrie
jcurrie earned 125 total points
ID: 34241731
Create a Group Policy

Computer Configuration > Administrative Templates > Windows Components > Windows Installer > Prhibit User Installs = Enabled + Prohibit User Installs

This method is super easy to implement but has two drawbacks

1) it only prevents installtions which use the Windows Installer
2) As a domain admin you won't be able to install programs either unless you disable the policy momentarially or push the installs through GPO
0
 

Author Closing Comment

by:Neo_78
ID: 34367890
As none of the Solutions are actually complete but helped with some options only
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Mapping Drives using Group policy preferences Are you still using old scripts to map your network drives if so this article will show you how to get away for old scripts and move toward Group Policy Preference for mapping them. First things f…
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now