[Last Call] Learn how to a build a cloud-first strategyRegister Now

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 889
  • Last Modified:

Software Restrictions via Group Policy

Having trouble with this one.  So I have %AppData%\*\PFSetup.exe setup as unrestricted and %AppData%\Local\Temp\PFSetup.exe as well because I'm unsure where it installs from

But I get this in the error log.

Access to C:\Users\ADMINI~1\AppData\Local\Temp\PFSetup.exe has been restricted by your Administrator by location with policy rule {542edcef-766b-4b80-94e2-42e180f6675d} placed on path C:\Users\administrator\AppData\Local\*\*.exe.

I do have a restriction on appdata\local\*.\*.exe but does this take precedence?
1 Solution
Yes it does.  I ran into the same issue when setting up exceptions.
It is all explained in here: http://technet.microsoft.com/en-us/library/cc780831(v=ws.10).aspx
If two identical rules with differing security levels are applied to software, the more conservative rule takes precedence. For example, if two hash rules--one with a security level of Disallowed and one with a security level of Unrestricted--are applied to the same software program, the rule with a security level of Disallowed takes precedence, and the program will not run.

Featured Post

[Webinar] Cloud and Mobile-First Strategy

Maybe you’ve fully adopted the cloud since the beginning. Or maybe you started with on-prem resources but are pursuing a “cloud and mobile first” strategy. Getting to that end state has its challenges. Discover how to build out a 100% cloud and mobile IT strategy in this webinar.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now