Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Windows Server Group Policy Whitelist

Posted on 2015-01-15
1
Medium Priority
?
98 Views
Last Modified: 2015-02-22
Hi -

I recently added a system based group policy the stop exe files from running in app data (see below) I have a program that users must run under "C:\Users\%username%\AppData\Local\BroadIn" But cant ont seems to add the exception the the group policy.

I tried...

Path:  %USERPROFILE%:\AppData\Local\BroadIn\*.exe but it did not seem to work
Security Level: Unrestricted

But it did not seem to work....

Any help would be appreciated.

----------------------------------------------------------------------------------------------------------------------------------------------------------
Computer Configuration –> Policies –> Windows Settings –> Security Settings –> Software Restriction Policies

Path: %localAppData%\*.exe
Security Level: Disallowed
Description: Don’t allow executables from AppData (Win 7)

Path: %localAppData%\*\*.exe
Security Level: Disallowed
Description: Don’t allow executables from AppData subfolders (Win 7)

Path: %localAppData%\Temp\*.zip\*.exe
Security Level: Disallowed
Description: Prevent unarchived executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\7z*\*.exe
Security Level: Disallowed
Description: Prevent 7zipped executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\Rar*\*.exe
Security Level: Disallowed
Description: Prevent Rar executables in email attachments from running in the user space (Win 7)

Path: %localAppData%\Temp\wz*\*.exe
Security Level: Disallowed
Description: Prevent Winzip executables in email attachments from running in the user space (Win 7)

The following paths are for Windows XP machines (if you still have them; I put these in just in case with the same disallow security settings)
%AppData%\*.exe
%AppData%*\*\*.exe
0
Comment
Question by:doctor069
1 Comment
 
LVL 47

Accepted Solution

by:
Donald Stewart earned 2000 total points
ID: 40551507
Try using the path

%localAppData%\*\ACTUALFILENAMEHERE.exe

with unrestricted.

This way until the filename actually matches what you have placed here, it wont run.
0

Featured Post

[Webinar On Demand] Database Backup and Recovery

Does your company store data on premises, off site, in the cloud, or a combination of these? If you answered “yes”, you need a data backup recovery plan that fits each and every platform. Watch now as as Percona teaches us how to build agile data backup recovery plan.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

564 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question