Re: File Level Blocking



The closest you probably could come within the native operating system is to
use Software Restriction Policies that is available in XP Pro and Windows
2003 where you can use path, hash and certificate rules and also modify the
designated file types list. The link below explains how to use and deploy
Software Restriction Policies. FYI and user that is a local administrator
can bypass SRP by booting the computer into Safe Mode. SRP should not be
implemented however without extensive testing to make sure they work as
planned and do not overly restrict the user. Also desktop shortcuts [.lnk
files] by default are included in the designated file types. When tweaking
SRP it will help to check the application log for SRP events if problems
arise and also use the free filemon tool from SysInternals to see what files
are accessed/executed when a user tries to run an application. --- Steve

http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx
--- Software Restriction Policies

"Alex" <x929@xxxxxxxxxxxxx> wrote in message
news:OMft%23WReGHA.380@xxxxxxxxxxxxxxxxxxxxxxx
Is there a way to lock down all file types with the exception of a
"whitelist" on a Windows Server?
I want to actually specify what file extentions are allowed to execute on
a server. I.E. .exe, .doc, .xls but I want to block everything else.

TIA

Alex



.



Relevant Pages

  • Re: File Level Blocking
    ... I have thought about SRP. ... modify the designated file types list. ... and deploy Software Restriction Policies. ... shortcuts by default are included in the designated file ...
    (microsoft.public.windows.server.security)
  • RE: Restrictions using GPOs
    ... > The Software Restriction Policies is a way that administrators can ... it only applies to Windows XP and later systems. ... > - Don''t run specified Windows applications ... > Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: File Level Blocking
    ... permissions on all files except for permitted file extensions, ... apply a security template / database you created using MMC.EXE and the ... and deploy Software Restriction Policies. ... administrator can bypass SRP by booting the computer into Safe Mode. ...
    (microsoft.public.windows.server.security)
  • RE: Restrictions using GPOs
    ... The Software Restriction Policies is a way that administrators can ... it only applies to Windows XP and later systems. ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Why are programs not digitally signed to protect against viruses?
    ... Windows XP Pro offers Software Restriction Policies which can ... be used to restrict what applications a user can install and execute based ...
    (microsoft.public.security)