Inconsistent Software Restriction testing


we have terminal server deploying, , wanted use group policy lockdown besides our normal terminal lockdown policy.  have policy cryptlocker type things launching in temp locations, wanted more comprehensive that.

this pretty simple environment, handful of known programs allow.  wanted set default deny , allow things in our additional rules run.

it *should* pretty straightforward had thought, it's been frustrating.

i started out doing via 2012r2 dc.  created policy , applied ou terminal server sits in.  applied single user though testing, since developers on here getting application set up, didn't want apply 2 rdp groups have created this.

i tried doing via user configuration, nothing happened whatsoever when user logged in.  tried via computer configuration section.  , got flakey on me.  applied ignored rules.

i had set "disallowed" default security level.  left 2 ms rules in place start, systemroot , programfilesdir registry key location rules.

so first seeing in multiple posts on various forums putting program folder path rule allow in subfolders run.  appeared not function way, tried folder, several exe's in it, without specifying exe's, c:\foldername

no joy.  tried explicitly giving path program , allowing run unrestricted.  , then, after doing gpupdate / force on terminal in question, after updates, logging in user that's in scope settings of policy security filtering, things absolute paths , exe names give me error blocked group policy.

my other policies working great, redirection of start menu , such, , generic lockdown  policy.  reason i'm having nasty time software restriction policy, , can't function.

google searches turning billion things aren't useful, , after 4 hours of searching , testing, i'm no better off when first started trying today. 

i'm hoping have obvious i've overlooked, i.e. "for work,  first have set a, b."

enforcement set on sofware files except libraries, users except local administrators (since account that's being tested not admin account) , set ignore certificate rules.  trusted publishers blank, , designated file types default list.

disallowed default setting security levels.

and example of additional rule fails testing: c:\windows\system32\calc.exe

it set unrestricted security level.

yet when try run calculator, tells me it's blocked policy.  once disable test restriction policy, works fine again.

thanks leads.

john


john

hi john,

thanks post.

disallowed default setting security levels.

and example of additional rule fails testing: c:\windows\system32\calc.exe

it set unrestricted security level.

yet when try run calculator, tells me it's blocked policy.  once disable test restriction policy, works fine again.

>>>i have tested this. default setting security levels disallow , unrestricted security level. can run calculator without blocked message.

based on experience, suggest check if have configured srp disallow default security level on computer.

i have tested in scenario below , encounter same problem you.

  1. configure srp computer object disallow default security level
  2. configure srp user object scenario above descripted
  3. when run calculator, blocked message prompt

best regards,

jay


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Group Policy



Comments

Popular posts from this blog

Error: 0x800f080c - Feature name NetFX3 is unknown

Checkedlist box

schannel