Prevent executables from running on mapped network drives

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 881
    Windows 7 Ultimate x64
       #11

    Okay i tested it out and it worked fine.

    look at this for most of the instructions.

    How to configure AppLocker Group Policy to prevent software from running - TechNet Articles - United States (English) - TechNet Wiki

    When you get to conditions. choose path

    Then select browse folders (navigate to your share using the UNC path.) choose next.

    If you dont want any exceptions choose next again.

    In the Description you can add "Please move files to desktop to run."

    Then create. You dont need any of the default runs created.

    This will update with the policy update or you can force it to update with the command gpedit /force
      My Computer


  2. Posts : 19
    Windows 7 Professional 64Bit
    Thread Starter
       #12

    Hi parman!

    Thank you a lot for your effort.

    I will follow your steps and I will make sure that the Application Identity service (AppIDSvc) is running.

    I will let you know about the results.

    Kind regards
    Rickson1982
      My Computer


  3. Posts : 881
    Windows 7 Ultimate x64
       #13

    Remember that you should not set the service to automatic until your have successfully tested it out. It's pretty straight forward and worked for me the first time so if you have any issues just ask.
      My Computer


  4. Posts : 19
    Windows 7 Professional 64Bit
    Thread Starter
       #14

    Hi parman!

    Today, I tried out your solution.

    It works perfectly for workstations which are on the domain.

    However, it does not work for workstations which are not part of the domain (imaged workstations).

    Do you have any suggestions how to deal with that problem?

    Kind regards
    Rickson1982
      My Computer


  5. Posts : 881
    Windows 7 Ultimate x64
       #15

    You will have to go into the local group policy for the pc.
      My Computer


  6. Posts : 19
    Windows 7 Professional 64Bit
    Thread Starter
       #16

    Hi!

    I think this is where I defined the rules.

    I defined them here (without success):
    Local Group Policy Editor / Computer Configuration / Windows Settings / Security Settings / Application Control Policies / AppLocker

    Do you have any other ideas?

    Do I need to change sth. in Local Group Policy Editor / Computer Configuration / Windows Settings / Security Settings / Local Policies?
      My Computer


  7. Posts : 881
    Windows 7 Ultimate x64
       #17

    1. Start menu type gpedit.msc
    2. Computer Configuration>Windows settings>Security Settings>Application Control Policies> Applocker.

    My list and your list match up. It should work fine. did you run gpedit /force afterwards. Remember that without forcing the update it will only update after a certain period of time.

    Last thing did you remember to start the service? Application Identity service

    It will also have to be setup to automatic or it will not work after reboot, but only set on automatic after its been tested and working correctly.
      My Computer


  8. Posts : 19
    Windows 7 Professional 64Bit
    Thread Starter
       #18

    Hi!

    I did all the steps exactly as you mentioned. Without success.

    I think there may be some other settings missing...
      My Computer


  9. Posts : 881
    Windows 7 Ultimate x64
       #19

    Anyway you could get me screen shots of the configuration. I just did it again using a network drive (UNC path) and it worked flawless.
      My Computer


  10. Posts : 19
    Windows 7 Professional 64Bit
    Thread Starter
       #20

    Hi!

    What configuration do you think could be interesting?

    I am sure that the configuration of the AppLocker rules is correct.

    As I said the workstation does not belong to the domain and has been set up by means of an image. Maybe there are some other security or general settings wrong which are required by AppLocker to function correctly...
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:10.
Find Us