Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Whitelisting Browsers in Domain

Posted on 2014-04-08
3
Medium Priority
?
227 Views
Last Modified: 2014-05-09
We are looking for a way to only allow IE and Chrome for use within our windows 2008 R2 domain. I have setup a software restriction policy via GPO to block other third party browsers from launching, but wanted to see if there was an easy way just to whitelist Chrome and IE and block the other browsers.

Would be opened to third party solutions as well.
0
Comment
Question by:GR JN
3 Comments
 
LVL 84

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 750 total points
ID: 39987873
whitelist by manufacturer google and microsoft.
0
 
LVL 80

Accepted Solution

by:
arnold earned 750 total points
ID: 39987912
What other software do you have? I.e. Central managed anti-virus/security app that has the functionality you want I.e. Symantec SEP, Mcafee ENT and Kaspersky. These have the feature you want that you can allow only the following.

The builtin software restriction require you to define which application are allowed and which are denied.
0
 
LVL 65

Expert Comment

by:btan
ID: 39988553
believe it should be applocker instead of SRP which is the predecessor. that is already quite a good start, since you are only whitelisting the application to execute via hash or publisher or path. But they can be bypassed which is probably the other layer of controls to mitigate that "gap". The hash will be good but it is too restrictive if app are updated. Also portable apps (assuming no hash rule enforcement), it can be run w/o installing and given that user should not be in any way able to assume admin role.

Device control via devicelock or Symantec SEP device and appl control will be good to allow authorised device only - whitelist device or simply reject any possible ext storage device and mobile device storage.

Appl control are available as well by the named product but better not to conflict with OS applocker - in other words chose one to ease the operational administration.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Know the reasons and solutions to move/import EDB to New Exchange Server. Also, find out how to recover an Exchange .edb file and to restore the file back.
Unable to change the program that handles the scan event from a network attached Canon/Brother printer/scanner. This means you'll always have to choose which program handles this action, e.g. ControlCenter4 (in the case of a Brother).
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question