Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

September 11, 2007 12:00 AM

How do I use Group Policy to block a specific application?

Windows IT Pro
InstantDoc ID #97128
Rating: (14)

A. Windows Server 2003 introduced Software Restriction policies. A number of software-restriction options are available, such as blocking files based on their hash value (which means renaming a file won't allow it to be run), and restricting based on code-signing levels.

1. Start the GPMC, and open a GPO to edit.

2. Right-click Software Restrictions, and select New Software Restriction Policies.

3. Two nodes will appear under Software Restriction Policies: Security Levels and Additional Rules. Select Security Levels.

4. Under Security Levels, three levels are displayed: Disallowed is for default blocking of all software, Basic User is for software that can run but will run without administrator credentials, and Unrestricted allows all software to run. If you right-click any option but Unrestricted, the option to “Set as default” appears, forcing the policy to that mode (Unrestricted is already the default). If you leave Unrestricted as the default, you can then add entries to Disallowed to block certain applications/source. Alternatively, you can set Disallowed as the default, then add exceptions to Basic User/Unrestricted that can run. This is a lot of work but is necessary for a very controlled environment.

5. We want to add a disallowed rule, so select Additional Rules.

6. Right-click Additional Rules, and the various types of rules appear (i.e., hash, certificate, Network Zone, and Path). Select New Path Rule.

7. Enter the path name or filename, and enter a description. You can browse if the path is locally available. Click OK. You can use environment variables as part of path rules. For example, instead of using C:\Program Files, I can use %ProgramFiles%, %ProgramFiles(x86)% (for 64-bit platforms), and %windir%. You can also use a wildcard (*) as part of the path. I could enter %windir%\notepad.exe.

8. Click OK, and close the GPO Editor.

After the client refreshes, Group Policy disallows the specified application or any application in the specified path. In my case, I can't run Notepad.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.