Solved

Exchange '10 ExecutionPolicy (RemoteSigned, Restricted, etc.) Setting

Posted on 2013-06-24
5
423 Views
Last Modified: 2013-06-27
On SP3 (Enterprise) and a third-party application had use set the configuration to "Set-ExecutionPolicy RemoteSigned" (then Yes to confirm).

We elected not to go with the solution but it seems that setting may still be on/active in our Exchange environment and we just want to make sure the setting is not any different by default or leaving any holes in security.

By default what should the setting for Get-ExecutionPolicy be?

By default when I type Get-ExecutionPolicy -List, it shows the ExecutionPolicy as RemoteSigned (not Undefined).
0
Comment
Question by:RTM2007
  • 3
  • 2
5 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39273095
The default is restricted. However most sites I work with use RemoteSigned, as it allows the use of self created ps1 files.

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 39273126
What are the security concerns with leaving the LocalMachine scope set to RemoteSigned as opposed to undefined?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39273146
Undefined means anything can be run, so that could include scripts that are unsigned and therefore could be malicious.

The four definitions are here:
http://technet.microsoft.com/en-us/library/ee176847.aspx

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 39273151
So is Undefined essentially the same as Unrestricted from the list?

Essentially does that mean RemoteSigned is safer?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39273178
I wouldn't like to say. Undefined means there is no policy at all. I don't know if Unrestricted has no restrictions at all.

Simon.
0

Featured Post

Do email signature updates give you a headache?

Constantly trying to correctly format email signatures? Spending all of your time at every user’s desk to make updates? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today!

Join & Write a Comment

Suggested Solutions

"Migrate" an SMTP relay receive connector to a new server using info from an old server.
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
how to add IIS SMTP to handle application/Scanner relays into office 365.

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now