Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 01, 2007

Stay Safer with Software Restriction Policies

Hash rules and other software-restriction–policy settings prevent unwanted application execution
RSS
View this exclusive article with VIP access -- click here to join |
See More Active Directory (AD) Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

A credit union recently enlisted a security company to try to compromise the credit union’s computers. The security company successfully infiltrated the computers, starting its attack by scattering USB thumb drives around the credit union’s parking and smoking areas. Each USB thumb drive contained a Trojan horse executable. Credit union employees found most of the thumb drives, attached them to credit union workstations, then ran the Trojan horse executable. Unless you’re sure that your organization’s employees or members would never execute a file they found on a discarded thumb drive, you might want to give software restriction policies (SRPs) a closer look.

SRPs are a Group Policy feature that you can use to restrict application execution on Windows Vista, Windows Server 2003, and Windows XP computers. You can think of SRPs as similar to a set of firewall rules. You can configure SRPs to allow or deny the execution of specific applications. Then, you can configure a more general rule to allow or deny the execution of applications not covered by the specific rules. So, for example, you can configure a general rule to allow everything, while creating a rule to ban sol.exe (solitaire.exe on Vista). Or, you can begin by banning everything, then allow only applications for which you’ve created an SRP rule. . . .


Already a VIP member?
Please log on to view the full article

Why become a VIP member?

VIP-only online access
VIP CD delivered twice a year: offline access to the entire Windows IT Pro article library
Monthly issue of your choice of Windows IT Pro or SQL Server Magazine

Subscribe Now
Reader Comments
hope to know more details about the AD

khalboos February 14, 2007 (Article Rating: )


nice to know how to be secured file by disallowing drive c to view by users

jaynasty05 February 19, 2008 (Article Rating: )


please let me know how to secure files by disallowing drive c

jaynasty05 February 19, 2008 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. Put simply, Windows 7 is not responsible for any battery life issues ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...


Related Articles Reduce Admin Risks

Active Directory (AD) Whitepapers Unleash the Power of Active Directory Groups

Meeting Compliance Objectives in SharePoint

Email Controls and Regulatory Compliance

Related Events The Experts Conference 2010

The Increasing Threat of Financially Motivated Data Theft

Group Policy Management Pitfalls: How to Avoid Them

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement