Hello I use SEPS 11.04 and I checked the block programs from running from removable drives check box under the application and device control policy. After I activated this policy I noticed that *.exe is blocked while *.msi still runs. Is there a way to change that? I mean the policy comes with * under the apply this rule to the following process which means any process to my understanding. Why isn't *.msi included in this I really don't know. I have tried to add *.msi to the policy and its still running. Please advice thank you in advance
1 In SEPM go to . Policies/Application and device control / New policy /Application contol
3. Select "Block appl. from running" -edit- on Block These appl. add line C:\WINDOWS\SYSTEM32\MSIEXEC.EXE
3. In action choose Block
( It my or may not work , Test this first and then try this in production)
"If you want to block msi, you need to block the entire application..
from here.
c:\windows\system32\msiexec.exe "