"Run only allowed" GP prevents zen apps

I've just started to experiment with restricted Windows Group Policies an ZMC 10.3. I cant seem to get any restricted applications to run from the nal window like they did in zen 4, 6, or 7 while using the "Run only allowed windows applications" group policy setting.
Before I only had to allow nalwin.exe and nalshell.dll but this no longer appears to work. Other people have posted this issue with versions as new as 10.2 and the "fix" was to allow nalshell.dll but I've already done that.
What am I missing? I dont actually get the usual restriction message like if i tried to run an program from the start menu that isnt allowed, but instead zen give an unspecified error. The apps run just fine using a GP that doesnt have "run only allowed" set.
Any help is appreciated.

I think it would be difficult to get a bug created that said:
"ZCM honors Windows Security Policies"
It was certainly never the intentional design to allow this.
Rogue Process Mgmt was the tool to perform the feature you are
describing in lieu of using the Microsoft GPO.
I'm not aware of any products that do or would advertise this feature,
since a security patch could fix it at any time.
The best bet would be to use file rights to actually control what user's
launch in combination with limiting where programs can be launched.
(Such as from %ProgramFiles%, etc..)
On 6/14/2010 1:56 PM, jkillebrew wrote:
>
> Does this still have something to do with changes in 10.2?
>
> Im not sure how its a security issue, but it certainly works well for
> us, allowing us to restrict users to only run applications from within
> the application window and nothing outside other than a very limited
> list of applications defined by the GP which would include things like
> nalwin.exe, antivirus related items, and maybe office applications that
> would need to be opened by file association.
>
> The greater security hole is that this policy can be defeated by
> renaming a program to the same as something allowed since it works by
> the file name, but students dont know that and dont know what files I
> have allowed so it hasnt been a problem so far.
>
> Thanks for any help you can provide. I'd really like to use ZCM but
> this is going to be a deal breaker for us if we cant get it working. We
> are already struggling to remove duplicate usernames across different
> OUs to support ZCM (makes no sense not to support this if edir allows
> it) so this is just another major stumbling block.
>
> BTW, there are numerous examples of this type of use of GP and zen all
> over the place. People have posted examples on their blogs and I even
> read a cool solutions article suggesting this setup, though this was all
> with 7 or older.
>
>
> craig_wilson;1987251 Wrote:
>> I actually misread your earlier posting.
>>
>> I thought you were having an issue launching the ZEN Components
>> themselves, rather than the the Windows Policy Locking preventing the
>> launch of Apps from NAL.
>>
>> I was not aware that ever worked and am a little surprised it ever
>> did.
>> In fact, I would consider it a fairly significant security hole in the
>> Windows policy that I did not know existed and would be concerned
>> about
>> trying to exploit it.
>>
>> I know ZDM had it's own version, called Rogue Process Management, but
>> that does not exist in ZCM. It may be possible to try and create an
>> enhancement request to get this feature re-added.
>>
>> In 10.0 that shipped, this feature would not really have worked the
>> way
>> ZCM was designed, but could at least work in theory now.
>>
>>
>>
>> On 6/14/2010 11:46 AM, jkillebrew wrote:
>>>
>>> I cannot get approval to open a SR because this isnt in production.
>> We
>>> are just trying to migrate our existing policies over from zen 4& 7
>>> with XP to similar policies using zen 10.3 and Windows 7 to see if
>> we
>>> can possible stick with Novell or if we have to move to a new
>> product.
>>> We must keep restricted policies in place because we use this for
>> K-12
>>> schools where students are malicious.
>>>
>>> So far the only fix is to add the application to the allowed list in
>>> the GP every time we create a new app which would be a huge pain the
>>> butt and would cause great delays in getting new apps deployed since
>>> have to wait for the GP to propogate at login while the app would
>> often
>>> arive ahead of the new GP. This would also allow everyone to run the
>>> application even if they dont have that bundle, unless we are going
>> to
>>> start managing more granular GPs, maybe hundreds of separate ones,
>> and
>>> we would have to keep notes on what GPs have access to what
>>> applications. I'd move to another product before I'd go that route.
>>>
>>> It should be fairly easy to recreate i think.
>>>
>>>
>>> craig_wilson;1987169 Wrote:
>>>> There was a change in ZCM 10.3 in how some of the ZCM Processes
>> Launch.
>>>> They are no longer child processes under explorer and they are
>>>> actually
>>>> started by one of the other ZCM services.
>>>>
>>>> It is possible that this could be related to the issue you are
>> seeing.
>>>>
>>>> Just be sure to let me know if you can't create an SR, because I
>> may
>>>> use
>>>> spare time to try and dupe and follow this up.
>>>>
>>>> However, my preference would be me to try and follow an SR you have
>>>> created.
>>>>
>>>> Just let me know.
>>>>
>>>> On 6/14/2010 10:26 AM, jkillebrew wrote:
>>>>>
>>>>> Thanks for the suggestion. At least one person with 10.2 had it
>>>> working
>>>>> according to another thread on this forum so I was hoping it was
>>>> just
>>>>> something simple. Unfortunately I think we have to pay per
>> incident
>>>> so I
>>>>> cant open a CSR.
>>>>>
>>>>> I tried Procmon on both a pc with and without restrictions and
>>>> compared
>>>>> line by line but they seem to be identical. Something is happening
>>>>> within Zen that isnt showing up on procmon and i dont know how
>> else
>>>> to
>>>>> see what is going on by hind the scenes.
>>>>>
>>>>>
>>>>> craig_wilson;1987046 Wrote:
>>>>>> If you are able to open a Service Request, I would recommend
>> doing
>>>>>> this.
>>>>>> I am not sure if the Agent is tested with that policy, but I
>> think
>>>> it
>>>>>> would be a good idea to get an official method documented.
>>>>>>
>>>>>> In the mean time, I would recommend trying the following........
>>>>>>
>>>>>> Disable the Policy and configure PROCOMON to run from startup.
>>>>>> Use this to see what processes and items launch and run.
>>>>>>
>>>>>> Try adding those items to your list.
>>>>>>
>>>>>> (Note: If you can and do make an SR, please drop me a note at
>>>>>> Craig_d_Wilson at Yahoo, and I will make sure it gets into the
>>>> hands
>>>>>> of
>>>>>> somebody who understands the issue.)
>>>>>>
>>>>>> --
>>>>>> Craig Wilson - MCNE, MCSE, CCNA
>>>>>> Novell Knowledge Partner
>>>>>>
>>>>>> Novell does not officially monitor these forums.
>>>>>>
>>>>>> Suggestions/Opinions/Statements made by me are solely my own.
>>>>>> These thoughts may not be shared by either Novell or any rational
>>>>>> human.
>>>>>
>>>>>
>>>>
>>>>
>>>> --
>>>> Craig Wilson - MCNE, MCSE, CCNA
>>>> Novell Knowledge Partner
>>>>
>>>> Novell does not officially monitor these forums.
>>>>
>>>> Suggestions/Opinions/Statements made by me are solely my own.
>>>> These thoughts may not be shared by either Novell or any rational
>>>> human.
>>>
>>>
>>
>>
>> --
>> Craig Wilson - MCNE, MCSE, CCNA
>> Novell Knowledge Partner
>>
>> Novell does not officially monitor these forums.
>>
>> Suggestions/Opinions/Statements made by me are solely my own.
>> These thoughts may not be shared by either Novell or any rational
>> human.
>
>
Craig Wilson - MCNE, MCSE, CCNA
Novell Knowledge Partner
Novell does not officially monitor these forums.
Suggestions/Opinions/Statements made by me are solely my own.
These thoughts may not be shared by either Novell or any rational human.

Similar Messages

  • Run only allowed application gpo and ie 11 on remote desktop server (terminal server)

    I configured win 2008 R2 server as Remote desktop server (terminal server) and I have domain GPO that's applying to this server. when I configure "Run only specified Windows application" IE 11 does not work.
    I have iexplore.exe as allowed application.
    when new user profile is created it setup and user can open other listed application fine but soon as IE 11 launched the IE windows loads up and after about 15-20 seconds it closes.
    if I remove the "Run only specified Windows application" policy then everything works fine.
    I am trying to figure out if any other .exe I have to allow in order for this to work properly?
    nothing in event viewer about ie crashing.
     

    > "Run only specified Windows application"
    Don't use this setting... This only restricts explorer.exe from
    launching applications. If you manage to create a cmd file or open a
    command prompt, this policy is useless.
    Better switch to AppLocker :)
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • How do I make an iPad or iPod touch only allow access to one App? I need to create a one application device for a child.

    I need to lock the iPad or Itouch down so only one application is running or available to start.  One, for ease of use by a 3 year old and two, in order to make the use of the iPad as an AAC device allowable in a classroom setting. There is concern that the other games, etc will be a distraction.
    Thank-you!

    You can enable Restrictions, also known as Parental Controls, on an iPhone, iPad, or iPod touch to prevent access to specific features. This article provides an overview of the types of Restrictions that are available, as well as how to enable or disable Restrictions on your device.
    http://support.apple.com/kb/HT4213

  • I am only allowed to pin one app tab. How do I pin as many app tabs as i want?

    I can't pin more than one app tab. How do i pin more than just one?

    Change iTune Store
    http://support.apple.com/kb/HT1311

  • Is there a way to have an iPad run only 1 app at a time?

    I am a tech support person and teachers are asking me if we can have a students iPad run only one app at a time. For instance, a group of students in biology would be allowed to run only the app for their biology book.
    Students have gotten so distracted during classtime with iMessage, web browsing, videos and games that it becomes virtually impossible to keep them on task in the classroom.
    I am aware of adding profiles to the devices, but this profile would only be for the biology class. It would then have to be removed or deactivated upon leaving the class.

    You can restrict iPads running iOS 6 to a single app via Guided Access:
    http://support.apple.com/kb/HT5509
    but that requires reconfiguration of the iPads whenever you want to set it up or deactivate or change it. There may be a mobile device management (MDM) system that would allow you to push out such changes "on the fly" but I can't say with certainty. Someone else here or in the iPad in the Enterprise forum may know.
    Otherwise it may be necessary to implement an administrative solution such as banning use of iPads in class or enforcing consequences should a student be using the iPad for inappropriate functions.
    Regards.

  • My pages app is only allowing me to type in CAPS.  How do I get it back to normal?

    My "pages" app is only allowing me to type in uppercase.  How do I turn that off to type with upper and lower case?

    Wow! That's a new one. Try quitting Pages and then reset your iPad.
    Double click the Home button to show the screen with running and recently used apps. Each app icon will have a sample page above it. Flick up on the page (not the app icon) and the page will fly away and the app icon will disappear. This quits that app. Then reset your device. Press and hold the Home and Sleep buttons simultaneously until the Apple logo appears. Let go of the buttons and let the device restart. See if that fixes your problem.

  • I downloaded an album on itunes using my new itouch; but it's only allowing me to put three songs at any one time into the music app...how can i get it to just move them all in there?

    i downloaded an album on itunes using my new itouch; but it's only allowing me to put three songs at any one time into the music app...how can i get it to just move them all in there?

    hi philly, thanks for getting back to me, especially on such a busy day.
    I don't think that's quite the issue though. I bought an album and it appears in 'my purchases' within the itunes app. Yet, in order to listen to the music, i must use the 'music' app and in this application, there are only three tracks displayed at any one time from my downloaded album.
    I can 'download all' from the 'my purchases' section but that still doesn't help, it just keeps the last three tracks downloaded in the music app.
    I have the 'icloud' enabled and wondered if it had anything to do with that.
    i have successfully downloaded another full album totally into the music app, but this first album is causing me problems.

  • Hi I have an iTunes account with my uk debit card but am currently in Australia, can I buy and use an iTunes/app store gift card in AU$ or am I only allowed to acces the store in gbp£ ?

    Hi I have an iTunes account with my uk debit card but am currently in Australia, can I buy and use an iTunes/app store gift card in AU$ or am I only allowed to acces the store in gbp£ ? Cheers

    I had the same error when trying to update my apps on my ipod touch. I tried to input my security code numerous times to no avail. I also made sure my billing address was the same as what my bank had on file. To fix the issue I went into iTunes, logged onto the iTunes store, went to account settings and reviewed my recent purchases. Turned out that I had made a recent purchase and didn't have enough money left on my credit card to pay for it at the time. I paid off the credit card, and then input my security code once more and now it works fine. I've heard that some debit or pay as you go credit cards require a minimum balance, so make sure you have at least that amount in your account.

  • How can I only allow free apps to be downloaded?

    How can I only allow free apps to be downloaded to my IPhone 4S?

    Sorry, but there's no way I know of to restrict downloading to free apps only. You can turn off purchasing of apps completely, but if purchasing is allowed, it's open other than by age range. You can of course remove any purchase method, but I don't believe that blocks the purchase; you just end up owing money.
    Regards.

  • Hi, I have macbook Pro, running Leopard OS X. I partitioned my hard drive a while ago to install windows and only allowed myself 10 Gig of data. Anyway, i deleted windows and want another OSX on there instead. How do i make this partition bigger please??

    Hi, I have macbook Pro, running Leopard OS X. I partitioned my hard drive a while ago to install windows and only allowed myself 10 Gig of data. I deleted windows after i realised i wasnt enjoying using it at all and wasted my hard drive. I now decided that i want another OSX on there instead yet i have only allowed myself 10 gb on the partition. I have ben thru some programms but am struggling on making this partition bigger.
    I only want it at 20gb but cant seem to make the partition bigger, only smaller or split it into further partition.
    Is there a way to do this, i have all installation discs from original OSX so think this could help.
    Any help please would be fantastic.
    Thanks Chris

    Hi, dragging the partition will only make smaller, not larger. In disk utility you can only split or make smaller the partitions. Yes i booted from installation disks also but still no help.
    And Brody, I am willing to erase the disc completely, infact jus started doing a backup in order to do so but that failed also. And the information you gave on partition a hard drive, Although very simple and i already know how to do this, but it wont let me make the partition bigger, and i dont want to make a new partition, just enlarge the one i already have, which i dont see possible from disk utility.
    Getting really frustrated now, even backing up is saying no to me. **** external being a douche.
    I dont mind erasing the hard drive but surely this must be doable without deleting the secondary partition back t a single volume, and re partitioning into 2 volumes again.
    Thanks again

  • Asset selections only allowed in repeat run

    Hi Experts,
    I am was posted Deprication 2009 with 12 periods from Planned posting run.
    When I am doing Deprication 2010 with 1 periods from Planned posting run for perticual period its work in test run u2018 T E S T R U N completed successfully , A document was created u2018, but when I remove the tick from test run system give.
    Error u201CAsset selections only allowed in repeat run Message no. AA734u201D
    Diagnosis
        Processing not possible because of errors in the parameters.
    System Response
        Processing cannot be continued.
    Procedure
        When performing a new posting run or a restart, you cannot limit it to
        the assets you want to be processed. You can only select assets in a
        repeat run. Start the program again with the appropriate parameters.
    Waiting for reply.
    In advance thanks
    Regards,
    Jemes
    Edited by: Jemes on Jun 8, 2010 3:21 PM
    Edited by: Jemes on Jun 8, 2010 3:23 PM

    When you run a planned, restart or unplanned depreciation run you can ony run it  only for all the assets in the real run
    When you have run the planned or unplanned depreciation it create records in the system for all the assets and there are errors then you should run the restart for all the assets.
    The repeat run you use when you have changed 1 or some assets in the old month and wand only to rerun for these assets the depreciation run.
    In a test run you can run it for only some assets but  as no test you have to run it for all the assets (only for the repeat run you can make a selection in the real run)

  • HT1766 How do I permanently delete the information of a single app from the Cloud? It only allows me to "Remove" or "Install".

    I have tried to delete the information associated with an App after I deleted it, but it stays in the Cloud and only allows me to either "Install" (back) or "Remove" (from the iPhone, but not from the Cloud)

    Hi,
    Not sure if this will be of use... but here's the LInk to NavFree Support:
    http://www.navmii.com/Support/

  • E-mail Attachments are only allowing me to open in e-mail as opposed to PDF, PPT, GIF or any app that is relevant to the attachment.

    E-mail Attachments are only allowing me to open in e-mail as opposed to PDF, PPT, GIF or any app that is relevant to the attachment.

    Meaning if you use the "tap and hold down on the attachment" you are not getting the "Open In" option? Or should we just keep guessing about what might be happening?
    If that is what is happening, deom the home screen .... quit the mail app completely in the recent tray by double tapping the home button to bring up the recents tray - and then tap and hold down on the mail app icon in the recent tray until it wiggles, then tap the red minus sign to quit the app. Restart the iPad and then try the "tap and hold down" on an attachment again.
    If you mean that something else is wrong or happening - share the information.

  • How can i share m3u8 downloaded video to wats app through video d/l app. application only allow to add mp4 videos to the camera roll and only mp4 video i am able to share. kindly suggest appropriate sollution. Thanks

    how can i share m3u8 downloaded video to watsapp through video d/l app. application only allow to add mp4 videos to the camera roll and only mp4 video i am able to share. kindly suggest appropriate solution. Thanks

    Hello Achates:
    I did not read the rather long post. If you wish to reinstall OS X 10.4, use your software install DVD. Backup is essential. To minimize your risk, I would use an archive and install:
    http://docs.info.apple.com/article.html?artnum=107120
    In that way, you will have a fresh copy of OS X and your current settings will be preserved.
    Incidentally, I do not agree that the printer problem is best solved by reinstalling OS X. I have had HP printers for sometime and, on one occasion, had difficulty after an upgrade. HP technical support walked me through uninstalling all traces of the HP driver and then reinstalling.
    Barry

  • Extension only allows me to view tutorials, how do I launch app?

    extension only allows me to view tutorials, how do I launch app?

    John I figured it out, sorry, I thought the programs where actually
    launched via the navigation bar, I did not realize one needed to launch the
    various projrams via the applications file.
      image: logo
      Chris Dardaris General Partner, TheLOOM
      Tel: 610-656-6599
    [email protected]  | www.theloomphilly.com
    Click
    here!<http://s.wisestamp.com/links?url=http%3A%2F%2Fr1.wisestamp.com%2Fr%2Flanding%3Fpromo%3D40% 26amp%3Bdest%3Dhttp%253A%252F%252Fwww.wisestamp.com%252Femail-install%253Futm_source%253De xtension%2526utm_medium%253Demail%2526utm_campaign%253Dpromo_40&sn=

Maybe you are looking for

  • Not Found error

    After setting up the test perl script to access our site, I get the following error: "The requested URL /WebObjects/Core.woa/Browse/cfcc.edu was not found on this server." Was our site expired due to the fact we haven't logged in for a while?

  • I can't drag and drop tabs or bookmarks in Firefox. I do not have Torbutton either.

    I know some people were having issues with certain add-ons like torbutton. I actually don't have any add-ons installed for Firefox. I have tried resetting Firefox, restarting it in safe mode, disabling all of my plugins, and reinstalling it all toget

  • How to restore accidently removed iPhoto library from Trash?

    I have iPhoto Library Manager (version 3.5.5) and am employing it successfully with my iMac (OS X 10.5.8) to manage my iPhoto Library [iPhoto '09 version 8.1 (415)] which I have divided into 47 libraries at about 4 GB each. This morning I accidently

  • Problems using 'IN' clause

    I'm making a procedure, and it has a cursor. This cursor receive some parameters and one of them is a list of numbers, the list can't be a VARCHAR2 with ',' or ';' as separator, because it doesn't work, if I use a defined type like 'vet IS TABLE OF N

  • Filed overlap with oracle reports 6i

    We have Oracle financials 11.5.7; we decided to convert some reports to have PDF output. We have bilingual reports ; it means we have two label with PL-SQL to display the good label depending on the language). The report run correctly in english; how