Solved

Whitelisting Browsers in Domain

Posted on 2014-04-08
3
223 Views
Last Modified: 2014-05-09
We are looking for a way to only allow IE and Chrome for use within our windows 2008 R2 domain. I have setup a software restriction policy via GPO to block other third party browsers from launching, but wanted to see if there was an easy way just to whitelist Chrome and IE and block the other browsers.

Would be opened to third party solutions as well.
0
Comment
Question by:GR JN
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 39987873
whitelist by manufacturer google and microsoft.
0
 
LVL 78

Accepted Solution

by:
arnold earned 250 total points
ID: 39987912
What other software do you have? I.e. Central managed anti-virus/security app that has the functionality you want I.e. Symantec SEP, Mcafee ENT and Kaspersky. These have the feature you want that you can allow only the following.

The builtin software restriction require you to define which application are allowed and which are denied.
0
 
LVL 63

Expert Comment

by:btan
ID: 39988553
believe it should be applocker instead of SRP which is the predecessor. that is already quite a good start, since you are only whitelisting the application to execute via hash or publisher or path. But they can be bypassed which is probably the other layer of controls to mitigate that "gap". The hash will be good but it is too restrictive if app are updated. Also portable apps (assuming no hash rule enforcement), it can be run w/o installing and given that user should not be in any way able to assume admin role.

Device control via devicelock or Symantec SEP device and appl control will be good to allow authorised device only - whitelist device or simply reject any possible ext storage device and mobile device storage.

Appl control are available as well by the named product but better not to conflict with OS applocker - in other words chose one to ease the operational administration.
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This Micro Tutorial will demonstrate how nuggets on the Web are formatted by using Chrome Developer Tools. These tools would not only view the site's CSS but it can also modify it and save the CSS to use on your own site.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question