Provide Limited Program Access To Non-Administrative Users In Windows 7 With GPEDIT.MSC



AppLocker Specify exactly what is allowed to run on desktops with the AppLocker feature in Windows 7. AppLocker provides the flexibility to allow users to run the applications, installation programs, and scripts they need to be productive. Learn how you can realize the security, operational, and compliance benefits of application standardization by using AppLocker.

To use AppLocker You will need to open the Windows Group Policy Editor By Typing gpedit.msc in Run.


You can find AppLocker in Windows Setting > Security Setting > Application Control Policy > AppLocker

Now Click On Configure Rule Enforcement 


In Enforcement tab, select Configured under executable rule by keep Enforcement rule as it is.
Now Click on Apply > Ok


Now click on Executable Rule >  Right Click Executable Rule > Click On Create New Rule. >>


Select Deny and then Click on Select Button To select particular User or Group to which we have to restrict access of particular Program >>


Click On Advance Button To Select User or Group >>


Click On Find Now Button To View all User or Groups Associated with the Windows. Select the required User or Group from the list of users to provide deny action of particular Program to that user and click on Ok >>


Click on Path and Next >>


Click on Browse File Button To Select the .exe file of application which you want to Deny >>
Note : Similarly U can Select the folder of that application to Block its access.


Go through the C:/Program Files / <Folder Name of Application which is to be deny> / <Application File (.exe)> and click on Open as shown below >>


Now it showing Like this >>


In the Executable rule you can see Action is Deny for selected Application >> 



After Creating Rule Make Sure that Application Identity Service  is started and set this service to Automatic.
1.Run Type services.msc hit enter.
2.Find Application Identity Service from the List of all Services.
3.Right click on Application Identity Service Do Following Configuration :

Set Startup type as Automatic 


Now, If blocked user trying to Access the Blocked Program or Application, it get the Following Message:


If U have any problem related to any of the step U can ask me By posting Ur Comment Below >>

                                                                       Enjoy !!!!!!!!!!!

Share this article :
 

Post a Comment

 
Support : BILAL SHAIKH | BILAL SHAIKH | ALL TECHNO GEEKS
Copyright © 2011. All Techno-Geeks - All Rights Reserved
Template Created by BILAL SHAIKH Published by ALL TECHNO GEEKS
Proudly powered by Blogger