Re: Software Restriction not working



Keep in mind that applications often call other executables when you try to
start them and that shortcuts are also restricted by SRP which may or may
not be a problem in your case. You might try changing your rule to allow
access to the whole folder for IE to see if that makes a difference and
trying to execute IE directly from the iexplore.exe file in the folder
instead of via the desktop. Look in the application log to see if you can
find anything helpful recorded there with Software Restriction Policies as
the source of the event. For hard to troubleshoot problems you may want to
use the free tool filemon from SysInternals to see if it shows access denied
entries in its log when you try to execute IE which may point to another
file. If you have not seen the link below it is pretty good at explaining
some of the ins and outs of SRP. --- Steve

http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx

"Gr8Gyro" <Gr8Gyro@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:78FB0175-DDEB-45FC-9BD8-BC9CBCB7021F@xxxxxxxxxxxxxxxx
>I have software restriction policy on a win2003 set as follows:
> Local Group Policy
> Default security level: disallowed
> Path rules
> c:\program files\internet explorer\iexplore.exe - unrestricted.
>
> If i understand group policies, this should allow a user access only to
> internet explorer yet when I click on IE I get the unallowed message
> because
> of policy restrictions.
>
> Can someone tell me if I am doing something wrong??
>
> I would appreciate any feedback.
>
>
> --
> Gyro


.



Relevant Pages

  • Re: [patch] remove MNT_NOEXEC check for PROT_EXEC mmaps
    ... partition, and AT THE SAME TIME want stuff to execute from there (being ... IMHO there should be some policy that can be achieved. ... suggests that there is no strict policy at all any more. ...
    (Linux-Kernel)
  • Re: Rule No fire
    ... > .Net document type of your schema that the rules will execute on. ... > are able to select your message as a parameter for the policy you are ... >>the orchestration is executed, the polict is loaded but no rule is fired ...
    (microsoft.public.biztalk.server)
  • Re: Preventing users installing programms...?
    ... Anyhow see the link below for the policy I was mentioning. ... To restrict users from running specific Windows programs on a standalone Windows ... >>can change permissions back to allow execute. ...
    (microsoft.public.win2000.security)
  • Re: BizTalk 2004 Business Rule Engine
    ... You are not deploying an assembly when you deploy rules, ... policy by name, and then pass in facts to the engine and execute the policy. ... > thing I am facing is when I deploy the Policy from Business Rule ...
    (microsoft.public.biztalk.general)
  • Re: Prevent Office Apps from Being Used to Compromise TS
    ... Eric Robinson wrote: ... security level to high, which would prevent users from doing this. ... Policy to create a Software Restriction Policy that ositively identifies any ... application you allow users to execute. ...
    (microsoft.public.windows.terminal_services)