Re: Software restriction policy problem
- From: Meinolf Weber
- Date: Sat, 3 Nov 2007 11:05:12 +0000 (UTC)
Hello Theo,
Check out this one:
Skip Administrators
An administrator may want to disallow the running of programs for most users, but allow administrators to run all programs. For example, a customer may have a shared machine that multiple users connect to using Terminal Server. The administrator may want users to be able to run only specific applications on the machine, but allow members of the local administrators group to run any program. To do this, use the Skip Administrators option.
If the software restriction policy is created in a GPO attached to an object in Active Directory, the preferred way to use this option is to deny the Apply Group Policy permission on the GPO to a group containing the administrators. This way less network traffic is consumed downloading GPO settings that do not apply to administrators. However, software restriction policies defined in Local Security Policy objects have no way to filter, based on users. In this case, the Skip Administrators option should be used.
To turn on Skip Administrators
.. In the Enforcement Properties dialog box, select the following option (as shown in Figure 2).
Apply software restriction policies to the following users > All users except local administrators
Note Setting the Skip Administrators option is only valid for machine policies.
Note In Windows Vista, setting the Skip Administrators option is only valid for elevated applications. For all un-elevated applications, this option will not work as software restriction policies use the (Lower) user account control (UAC) token, which does not contain admin group SID. For more information about UAC, see http://www.microsoft.com/technet/windowsvista/security/uac.mspx
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm
I have set up a software restriction policy on my Vista Ultimate PC at
home. This works fine. However, as a side affect I can no longer open
PDF (adobe reader) or Word (2007) documents from a CD or USB flash
drive by double clicking them. They will open if dropped onto an
already running program. They open fine from the main drive.
I have restricted it so ordinary users can only run programs from
"program files" and the "windows" directory.
Can anyone help?
Theo Carr-Brion
.
- Follow-Ups:
- Re: Software restriction policy problem
- From: Theo
- Re: Software restriction policy problem
- References:
- Software restriction policy problem
- From: Theo
- Software restriction policy problem
- Prev by Date: Software restriction policy problem
- Next by Date: "Initialization failed" error when running gpresult or rsop.msc on client machine
- Previous by thread: Software restriction policy problem
- Next by thread: Re: Software restriction policy problem
- Index(es):
Relevant Pages
|