Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Whitelisting Browsers in Domain

Posted on 2014-04-08
3
222 Views
Last Modified: 2014-05-09
We are looking for a way to only allow IE and Chrome for use within our windows 2008 R2 domain. I have setup a software restriction policy via GPO to block other third party browsers from launching, but wanted to see if there was an easy way just to whitelist Chrome and IE and block the other browsers.

Would be opened to third party solutions as well.
0
Comment
Question by:GR JN
3 Comments
 
LVL 80

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 250 total points
ID: 39987873
whitelist by manufacturer google and microsoft.
0
 
LVL 77

Accepted Solution

by:
arnold earned 250 total points
ID: 39987912
What other software do you have? I.e. Central managed anti-virus/security app that has the functionality you want I.e. Symantec SEP, Mcafee ENT and Kaspersky. These have the feature you want that you can allow only the following.

The builtin software restriction require you to define which application are allowed and which are denied.
0
 
LVL 63

Expert Comment

by:btan
ID: 39988553
believe it should be applocker instead of SRP which is the predecessor. that is already quite a good start, since you are only whitelisting the application to execute via hash or publisher or path. But they can be bypassed which is probably the other layer of controls to mitigate that "gap". The hash will be good but it is too restrictive if app are updated. Also portable apps (assuming no hash rule enforcement), it can be run w/o installing and given that user should not be in any way able to assume admin role.

Device control via devicelock or Symantec SEP device and appl control will be good to allow authorised device only - whitelist device or simply reject any possible ext storage device and mobile device storage.

Appl control are available as well by the named product but better not to conflict with OS applocker - in other words chose one to ease the operational administration.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
How to record audio from input sources to your PC – connected devices, connected preamp to record vinyl discs, streaming media, that play through your audio card: Vista, Windows 7, Windows 8, Windows 8.1 and Windows 10 – both 32 bit & 64.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question