Solved

prevent Chrome installing

Posted on 2013-01-21
7
650 Views
Last Modified: 2013-01-22
win2008 r2 domain
win7 clients

my users are local admins but I need to prevent them installing Chrome. they are being prompted by adverts etc to get chrome so I need to stop them installing it. maybe Software Restriction Policies?
0
Comment
Question by:Pete
  • 4
  • 3
7 Comments
 
LVL 23

Expert Comment

by:Ayman Bakr
ID: 38802128
Download files can be restricted when you enable the GPO setting under:

 User Configuration > Policies > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone > "Allow file download"

You can also restrict using other browsers through AppLocker Policy since you have Win 7 clients.

The best is not to give your users Local Admin privileges.
0
 
LVL 1

Author Comment

by:Pete
ID: 38802813
thanks for the reply, staff need local admin rights so they run our poorly written school management software.

I was hoping for paths and filenames i can restrict to prevent chrome downloading and installing?
0
 
LVL 23

Expert Comment

by:Ayman Bakr
ID: 38802908
Well, paths and filenames will not solve your issue if the user is a tech savvy and discovers how to change the execution file name or the default path of installation. Moreover, the more you try to be restrictive the more your users become tech-knowing and the more determined to break the restrictions!

Check this thread for more information and different ideas presented - AppLocker would be very great and efficient; read through to Jason Sandys comment:

http://social.technet.microsoft.com/Forums/en-US/configmgrswdist/thread/36f404ba-95e5-4808-8f17-b6875f76b72a
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 1

Author Comment

by:Pete
ID: 38803082
http://social.technet.microsoft.com/Forums/eu/winserverGP/thread/a7abcfea-8819-4680-9010-d2604a59c9bd

how about this, not too worried about staff renaming installers etc. but not sure of implications of blocking googleupdater.exe
0
 
LVL 23

Expert Comment

by:Ayman Bakr
ID: 38804534
Well, first you need to focus on what stage you want to put the restrictions:
1. At the download level
2. At the installation level
3. Post-Installation level

Once clear about that, then you can use the suggestion that suits your objective. GPO to disallow downloads, or GPO to disallow the installation or GPO to disallow the launch of an application that is already installed (again I would stress here that perhaps the best here is AppLocker Policy).

In the link you mentioned, googleupdate.exe restrictions will affect, not only chrome updates but any google related updates. You might want to stick to chrome_installer.exe; but if google changes the name of the file, the users will be able to download it again.

Frankly speaking, I would prefer the post-installation level restrictions because by this you avoid the hassle of changing file names rendering restrictions on the first two levels useless.
0
 
LVL 1

Author Comment

by:Pete
ID: 38804546
Applocker is not available for Win7 Pro which is what we have.

I would like to prevent both the downloading and the running. so maybe a SRP of *chrome.exe for the running and not sure about the downloading, any ideas what to block?

Thanks
0
 
LVL 23

Accepted Solution

by:
Ayman Bakr earned 500 total points
ID: 38805783
To prevent from running chrome installation you can create a SRP of chrome.exe and chromesetup.exe with a hash rule (so that even if they change the name of the file or path, they will still not be able to run the installation).

To prevent the download you can set the 'Allow File Download' to disabled in the GPO:
User Configuration > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Internet Zone

But this will diallow download of all files in that zone.

To prevent select file types or certain file downloads like chromesetup.exe I believe you'll be better equipped to have it set on your firewall appliance (cisco, juniper - whatever is your firewall).
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now