Registered member login:
Register Now
Altirigos » Notification Server and Solutions » Application Control » Help with Application Control

» Current Poll
Vista?
Staying on XP until Windows 7 - 71.74%
99 Votes
Already on Vista - 10.87%
15 Votes
Planning an upgrade to Vista soon - 10.14%
14 Votes
Other (please explain) - 7.25%
10 Votes
Total Votes: 138
You may not vote on this poll.
» Stats
Members: 6,822
Threads: 9,759
Posts: 47,761
Top Poster: Nick (4,800)
Welcome our newest member, TommyGun
» Online Users: 29
2 members and 27 guests
blt, skiierj
Most users online at once 294, 06-30-2007 at 01:24 PM.
» January 2009
S M T W T F S
28293031 1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Reply
Old 04-24-2008, 01:05 PM   #1 (permalink)
 
Status: Junior Altiris Admin
Join Date: 08-27-2007
Location: Work
Posts: 14


Question Help with Application Control

So I finally started playing around with Application Control so we can start removing admin rights on user's local machines. For a "test" I decided to use Windows Disk Defragmenter and Elevate Process Rights Policy to allow a user without admin rights to run it. For the life of me I can not get it to work. I have also tested the Run Deny for Firefox and it works so I know the client computer is getting the policies. I'll give you a run down of what I have done.

-Created a user in our domain for testing purposes with only "User" rights.

-I started Disk Defrag and watched what process was started. The result being dfrgntfs.exe which is located in C:\WINDOWS\system32.

-In that location is also dfrg.msc and dfrgfat.exe.

-First I Created a collection here:


-Then created a folder here for Defrag:


-Then created filters for each shown here:

(I know .mcs isn't a executable but it was one attempt at getting this to work.)





-Next I created an Policy


I then added my "Test Pig" to that collection, updated the client's agent and tested. No luck. I have spent 2 days on this and defrag still won't run.

NOTE: I created a filter for mmc.exe to run with admin rights for testing purposes and added it to the Defrag policy. Now when I start Defrag I get the pop-up message that mmc.exe was stated with elevated rights yet defrag still gives me the message"You must have Administrator privileges to defragment a volume." Then I created another collection for mmc.exe,created its own policy and added the filter to the policy then pointed it at the mmc.exe collection. Finally added the test computer to that collection too and tested...no go still.

I'm sure I'm missing something trivial but I'm at a loss. HELP!

treyjack is offline   Reply With Quote
Old 04-24-2008, 05:37 PM   #2 (permalink)
 
Status: Junior Altiris Admin
Join Date: 08-27-2007
Location: Work
Posts: 14


Anyone?
treyjack is offline   Reply With Quote
Old 04-24-2008, 07:22 PM   #3 (permalink)
 
Nick's Avatar
 
Status: Altiris Architect (Site Founder)
Join Date: 01-01-2005
Location: RDU, North Carolina, USA
Posts: 4,800


Treyjack,

I'm away from my office right now so I can't test it in my lab to compare for you.

Everything appears right though. Just as a thought though, have you tried using the policy without the %SystemRoot% variable?
__________________
Scire potentia est (knowledge is power)
Nick is offline   Reply With Quote
Old 04-25-2008, 09:31 AM   #4 (permalink)
 
Status: Junior Altiris Admin
Join Date: 08-27-2007
Location: Work
Posts: 14


Quote:
Originally Posted by Nick View Post
Treyjack,

I'm away from my office right now so I can't test it in my lab to compare for you.

Everything appears right though. Just as a thought though, have you tried using the policy without the %SystemRoot% variable?
Yep, I've tried without the variable and even with that line blank so the filter wouldn't be as specific. I've tried just about every different way I can think of.
treyjack is offline   Reply With Quote
Old 04-25-2008, 03:55 PM   #5 (permalink)
 
Status: Junior Altiris Admin
Join Date: 08-27-2007
Location: Work
Posts: 14


What is Stage 2 Processing BTW?
treyjack is offline   Reply With Quote
Old 06-24-2008, 12:15 PM   #6 (permalink)
 
Status: Altiris Admin
Join Date: 01-03-2006
Location: Wisconsin
Age: 33
Posts: 61


Stage 2 Processing

According to the documentation:

Make the application subject to policies applicable to its
parent application. That is, the application that spawned
the process applicable to this policy.

I wish they would follow that up with a "for example". In my setup I do not have Stage 2 Processing enabled for any of my policies, and I'm not really clear on when I might want to.

As far as the issue that you are having, are you using Inventory Filtering in conjunction with some Dynamic Filters? I'm wondering if you have another policy getting applied after your "Add Administrative Rights" policy. The best way to determine that is to enable a message for all of your policies. You already have a message pop up for the Administrative Rights policy. You can also add a message to your "Allow Whitelist Execution", "Deny Blacklist Execution", etc. If you have more than one policy getting applied then you'll see several balloon tips pop up in sequence. This is great for troubleshooting, but terrible for end-users.

I'm curious, are you running 6.0 or 6.1? Version 6.1 added some really great features, although I still need to figure some of them out.
__________________
Jesse Kozikowski - Server Analyst II - Altiris Certified Engineer
Aspirus Wausau Hospital
jessek is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Powered by vBadvanced CMPS v3.0 RC2

All times are GMT -4. The time now is 08:27 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
vB.Sponsors
Altirigos