Re: 2000 Server Policy on XP Client

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Oli Restorick [MVP] (oli_at_mvps.org)
Date: 07/07/04


Date: Wed, 7 Jul 2004 23:03:31 +0100

While Windows 2000 had some basic features to block execution of programs
based on filenames, Windows XP and higher have Software Restriction
Policies, which base the restrictions on the hash of the file. Therefore, a
user cannot bypass your restriction by renaming their banned executable to
winword.exe, for example.

If you manage your Windows 2000 Active Directory from a Windows XP Pro
machine, you should find the software restriction policies. You don't need
to upgrade your domain to Windows Server 2003 to gain this functionality.

Hope this helps

Oli

"Dan Cooper" <Dan Cooper@discussions.microsoft.com> wrote in message
news:E6023B4C-D243-4A90-A49E-BA24C12CDCC4@microsoft.com...
>I have a new policy in effect blocking all applications from being run,
>except the ones i allow. this works great on my 2000 Workstations, but has
>no effect on my XP Pro workstations... is there anything im doing wrong for
>this not to work, or do i have to upgrade to Server 2003??
>
> Thanks,
> Dan



Relevant Pages

  • RE: Restricting Programs using AD ??
    ... Software restriction policies are a new feature in Microsoft® ... you do not have to upgrade your Windows ... object and configure your software restriction policy. ...
    (microsoft.public.win2000.active_directory)
  • RE: services running in windows domain (winXP clients)
    ... software restriction policies only work for ... applications that are called by the Windows explorer process. ... or does it include any ".exe/.com/.dll" or otherwise executable files? ...
    (Focus-Microsoft)
  • Re: GP-based Application Ban-list via Hash/Fingerprint
    ... If your computers are running Windows XP, you can use Software Restriction ... Policy to disallow everything by default, then create rules specifying what ... Windows Group Policy ...
    (microsoft.public.windowsxp.security_admin)
  • Re: run only allowed windows applications
    ... Your advice is right on but unless you know something I don't about Windows ... > You can still use software restriction policies to do this on Windows ... > -Make sure drives are formatted NTFS ...
    (microsoft.public.win2000.group_policy)
  • Re: Software Restiction Policies in Windows XP
    ... > I have Windows XP Home Edition, and I know that Software Restriction ... > Policies can easily be set-up in the Professional Edition by using ...
    (comp.security.misc)