I have a 2003 R2 Citrix/TS server farm for remote access. The OU containing the 2 servers has a fairly restrictive GPO attached.
One thing I cannot seem to find a way to restrict is running .exe files. I have removed access to all local server drives, but they do have access to their network drive.
What is to prevent them, for example, from copying an .exe to one of their network drives while at work (such as VNCViewer.exe) and running them from home on the remote server? I know I can restrict by name, and there are some exe's that i DO want them to be able to run.
Is there a way to create a rule to prevent any programs from being run from a certain network drive? I would like them to be able to run any exe that is on U: (users do not have write access), but none that are on P: (where users DO have write access).
Thanks,
Andrew
Hard work often pays off over time, but procrastination pays off right now!
One thing I cannot seem to find a way to restrict is running .exe files. I have removed access to all local server drives, but they do have access to their network drive.
What is to prevent them, for example, from copying an .exe to one of their network drives while at work (such as VNCViewer.exe) and running them from home on the remote server? I know I can restrict by name, and there are some exe's that i DO want them to be able to run.
Is there a way to create a rule to prevent any programs from being run from a certain network drive? I would like them to be able to run any exe that is on U: (users do not have write access), but none that are on P: (where users DO have write access).
Thanks,
Andrew
Hard work often pays off over time, but procrastination pays off right now!