Virtualize IE (Thin App) VS RemoteAPP IE  -we need some advise-

Posted on 2011-03-05
Last Modified: 2012-05-11

We are a media company and we have a group of users that because their role they have to research for news, events, etc on the internet. We had situations where their computers have been infected and this is becoming an issue because we can't keep reimaging their workstation or running the AV, troubleshooting etc.

We are evaluationg different ways to have them use VMs in order to browse the internet and use non-persitent disk so that the VM will not keep the changes. - For the time being this is what we are doing.

We are also looking into Thin App so that IE can be virtualized and executed over their workstation I think that virtualizing the app will still bring the treaths to their computers if they go to a compromised site.

The other way could be something like TS RemoteAPP but I think we are going to be in the same scenario that Think App IE.

We were wondering if someone has any suggestions about any other way to approach this problem. I am not sure if there are any way to acomplish what I want (secure IE browsing) using either ThinkAPP IR or RemoteAPP IE. Going torward the virtualizaton of IE for this particular matter will be easier for the users but I don't know if it be secure enough.

Thank you.
Question by:llarava
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +4
LVL 88

Expert Comment

ID: 35044202
1. You could use Linux LiveCD's
2. You could use a Linux Kiosk installation
3. On m$ OS's don't use IE, but rather firefox, it doesn't support ActiveX controls which makes it safer than IE. There is also a portable version of FF...

For Linux Distro's and LiveCD's check out Distrowatch:

and for FF Portable, PortableApps:

LVL 88

Expert Comment

ID: 35044210
Sorry, typo in the 2nd link above...

Author Comment

ID: 35044223
This is not a kiosk. This is for one of the company Department (50 users / 50 workstations) and they have to be able to use whatever we implement while working with the other business apps that they have installed on their workstations.

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 37

Expert Comment

by:Neil Russell
ID: 35044322
You could install a virtual PC environment on each PC with the browser in it. Snapshot it and then everytime it is shutdown it reverts to the snapshot. No danger of inections lasting longer than 1 session IF they do get anything.
LVL 88

Expert Comment

ID: 35044342
Then go for FF as I mentioned above. Set proxy settings for a non-existent proxy server in the internet connections of IE so it can't be used for web-browsing. As I mentioned, FF is more secure than IE, and you could look for further Add-ins for it so it is even more secure. and use a portable version.
LVL 122
ID: 35044585
Have you considered using VMware Workstation with VMware ACE

Author Comment

ID: 35044631
Yes I have considered workstation or virtual PC but we have decided to go with a different type of solution.

For the time being we are using View 4.6 and our users connect via RDP to to non-persistent set of VMs in order to use IE to get to the high risk sites.  For security reasons we have also used vShield in order to isolate these set of VMs from the network.

I want to know if I could virtualize IE via Thin App or TS RemoteApp so that they don't have to connect through RDP to a different VM. We just want to make this as seamless as possible for them but at the same time keep it secure.  
LVL 42

Accepted Solution

kevinhsieh earned 500 total points
ID: 35046959
I don't think that you can go the RD RemoteApp route in the classic implementation because that requires that IE be published from a Remote Desktop Session Host server (classic terminal server) and you have just pushed the infection to a single server or server farm. Maybe you can combine RemoteApp with non-persistent RD Session Hosts to achieve both the statelessness of the IE environment and the seamless experience of RemoteApp.

I have never tried ThinApp, so I don't know how that works, but I don't think that it is stateless so it wouldn't solve your problem.
LVL 13

Expert Comment

ID: 35049592
this is only an idea.we normally use kaspersky & we use it's safe run feature for risky situations

Expert Comment

ID: 35082956
Whereas I understand your reasons for virtualizing IE, and I completely agree with them, Microsoft might not share your enthusiasm.
It just as a side note as the guys above provided enough information to get you started, but I'd look into MS licensing with respect to virtualizing IE... Virtualizing IE is basically unsupported, and against MS licensing
and here

Not that I that I want to discourage you, but I think you should have all the information before you go down this route.
LVL 122
ID: 35234998
Trial ThinApp.

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When rebooting a vCenters 6.0 and try to connect using vSphere Client we get this issue "Invalid URL: The hostname could not parsed." When we get this error we need to do some changes in the vCenter advanced settings to fix the issue.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question