Solved

Whitelisting Browsers in Domain

Posted on 2014-04-08
3
221 Views
Last Modified: 2014-05-09
We are looking for a way to only allow IE and Chrome for use within our windows 2008 R2 domain. I have setup a software restriction policy via GPO to block other third party browsers from launching, but wanted to see if there was an easy way just to whitelist Chrome and IE and block the other browsers.

Would be opened to third party solutions as well.
0
Comment
Question by:GR JN
3 Comments
 
LVL 79

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 39987873
whitelist by manufacturer google and microsoft.
0
 
LVL 77

Accepted Solution

by:
arnold earned 250 total points
ID: 39987912
What other software do you have? I.e. Central managed anti-virus/security app that has the functionality you want I.e. Symantec SEP, Mcafee ENT and Kaspersky. These have the feature you want that you can allow only the following.

The builtin software restriction require you to define which application are allowed and which are denied.
0
 
LVL 62

Expert Comment

by:btan
ID: 39988553
believe it should be applocker instead of SRP which is the predecessor. that is already quite a good start, since you are only whitelisting the application to execute via hash or publisher or path. But they can be bypassed which is probably the other layer of controls to mitigate that "gap". The hash will be good but it is too restrictive if app are updated. Also portable apps (assuming no hash rule enforcement), it can be run w/o installing and given that user should not be in any way able to assume admin role.

Device control via devicelock or Symantec SEP device and appl control will be good to allow authorised device only - whitelist device or simply reject any possible ext storage device and mobile device storage.

Appl control are available as well by the named product but better not to conflict with OS applocker - in other words chose one to ease the operational administration.
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
exchange, active directory 4 24
PerfMon Report Time Out 6 23
Windows Password recovery 7 36
Does Robocopy do a Delta copy of a file (Remote copy) ? 2 17
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question