How to configure Applocker policies to restrict everything except a single application on RDSH, without breaking windows?


i've been searching examples of how best use applocker policies lock down 2008r2 remote desktop host.  for host in question, want users able access single application.  i block access other executables, setup files, etc, without breaking in windows.  (it wouldn't if user couldn't log in because explorer wouldn't load or such)

i should think isn't uncommon goal, can't seem find example of policy structure used in such situation.  does know of example locking down without preventing users accessing server , launching 1 exe?

hi,

q: can block applications except software publisher?

a: yes. can creating publisher condition rule allows files run signed specific software publisher. in cases binaries created dynamically, create path rule condition.

sorry misunderstanding, found similar thread here:

using applocker prevent applications except specific ones

http://social.technet.microsoft.com/forums/en-us/winservergp/thread/5a020ae7-f23b-40a6-824f-8e060bd7a390/

please go through it.

hope helps.

regards,

yan li

technet subscriber support

if are technet subscription user , have feedback on our support quality, please send feedback here.


yan li

technet community support



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file