G
Guest
Here's the scenario we have :
We have several hundred W2K SP4 PCs, several hundred WXP Pro SP1a PCs.
Our network is NT4 but we will migrate to AD in-time.
I know that with AD Software Policies we can stop users from running
applications using policies - however while we currently don't have this
capability, does anyone have a good equivalent?
The "Don't Run Windows Programs" POLEDIT policy is not feasible as we'd have
to list vast arrays of files as it does not accept masks.
Using "Only allow following Windows Programs" is equally bad as the range of
applications we use really is vast, to track down all of their component .exe
files and other components (that must be able to be run) would be a massive
task.
This restriction, however applied - must work for Network and Removable
Drives - now if there's a setting I can put on Removable Drives (Like No Exec
on Linux filesystems), then I'd happily do that via a security policy.
I'm at my wits end with this one as we use a 'sweeper' which erases these
files from our servers, yet the users can still plug in their USB memory
sticks and run .exe files or whatever that may be on them. I work at a school
so security is something that's better off prevented first (stop them doing
something at the start), rather than run around and try and catch it later.
Any thoughts?
We have several hundred W2K SP4 PCs, several hundred WXP Pro SP1a PCs.
Our network is NT4 but we will migrate to AD in-time.
I know that with AD Software Policies we can stop users from running
applications using policies - however while we currently don't have this
capability, does anyone have a good equivalent?
The "Don't Run Windows Programs" POLEDIT policy is not feasible as we'd have
to list vast arrays of files as it does not accept masks.
Using "Only allow following Windows Programs" is equally bad as the range of
applications we use really is vast, to track down all of their component .exe
files and other components (that must be able to be run) would be a massive
task.
This restriction, however applied - must work for Network and Removable
Drives - now if there's a setting I can put on Removable Drives (Like No Exec
on Linux filesystems), then I'd happily do that via a security policy.
I'm at my wits end with this one as we use a 'sweeper' which erases these
files from our servers, yet the users can still plug in their USB memory
sticks and run .exe files or whatever that may be on them. I work at a school
so security is something that's better off prevented first (stop them doing
something at the start), rather than run around and try and catch it later.
Any thoughts?