Endpoint Protection

 View Only
  • 1.  Application Control - Exception List

    Posted Jun 22, 2017 06:26 AM

    Hi All,

    I'm looking at the possibility of using Application and Device control to prevent users from running any applications not deemed necessary.

    How can I prevent access to all applications with the expection of required windows apps and a set list(Office etc?)

    Thanks


    Dean



  • 2.  RE: Application Control - Exception List

    Posted Jun 22, 2017 06:34 AM

    Sounds like you'd want to start with the System Lockdown feature first. You can grab a fingerprint list of your golden image and start from there.

    http://www.symantec.com/docs/HOWTO80849

    http://www.symantec.com/docs/HOWTO80848



  • 3.  RE: Application Control - Exception List

    Posted Jun 22, 2017 08:38 AM

    Thanks for that. It looks like it will work.

    I'm tring it now. I've set to blacklist everything without any exceptions as I hope to be able to identify required apps and add them to a white list later.

    I have selected the option to "Log unapproved Applications" but after 1 hour nothing is showing. Have I configured it wrong or do I need to give it more time?



  • 4.  RE: Application Control - Exception List

    Posted Jun 22, 2017 08:43 AM

    Which mode did you enable?



  • 5.  RE: Application Control - Exception List

    Posted Jun 23, 2017 05:03 AM

    I enabled "Log unapproved Applications"



  • 6.  RE: Application Control - Exception List

    Posted Jun 23, 2017 06:42 AM

    Whitelist or Blacklist?

    Capture_198.JPG

    Additionally, do you have the applicationa nd device control component installed? It's required for system lockdown.



  • 7.  RE: Application Control - Exception List

    Posted Jul 10, 2017 03:57 AM

    I wasn't able to get the "Log Unapproved Applications" to log anything but I was able to implement the Lockdown.

    We had have an issue with a few legitimate programs already installed being block.

    I'd like to know if Windows Updates will cause issues with this configuration. Will we need to take a new finger print after every update?

     

    As an alternative we have being looking at Application Control again. This time though we'd like to allow applications to run only if they are in certain directories.

    I've been unable to get this to work though, Any help on this would be appriciated.