Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Software Restriction Policy - multiple questions

$
0
0

Hi,

We have a basic SRP setup that we had applied to all users and admins on a server.
This was set to be unrestricted by default, with additional rules blocking anything in any of these paths:
%AppData%\*\*.exe
%ApPData%\*.exe
%LocalAppData%\*\*.exe
%LocalAppData%\*.exe

We have some queries around how SRP works, and issues we are now facing:
1. If we added an additional rule to the above, with a more explicit path, such as %LocalAppData%\Microsoft\*.exe and set it to allowed, how are the rules evaluated? Would the more general rules take precedence, or would the more explicit rules take precedence? Do disallow rules take precedence over allow rules?
2. We have since changed the policy to apply only to users. Now, when I try to install an application via an MSI installer, I get an error stating:
"The system administrator has set policies to prevent this installation"
We have no other policies related to software installation, so could it be that something of the SRP is left over, still preventing me (an admin) from installing an application? No SRP events are triggered at this time

Many thanks

James


Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>