Hi,
i followed the recommendations from my previous question and set all rules to "RESTRICTED". I saved this configuration locally to a test machine. However, I can still download, install, and run applications such as Amazon Music and Spotify.
I understand that some applications can be installed even without administrative privileges. Another way to test....I found the following:
Add a Denied Item
To add an item, select the Denied Items node and click the Add Itemdrop-down arrow on the Rule Items ribbon, select Deniedand select the type of Denied Item you want to add.
This task prevents all users accessing an application on a network share:
- Select the Denied Items node in Rules> Group> Everyone.
- Click Add Item in the Rule Items ribbon and select Denied.
- Select File.The Add a File dialog displays
- Enter or browse for an application, for example, regedit.exe.The selected application is listed in the Denied Items work area.
- Attempt to run the selected application.The application is denied and a message box displays with the notification that the application is not authorized.
I added "Amazon Music.exe," "spotify.exe", and "dropbox.exe" into the denied items node and saved this configuration locally to a test machine. This worked! Upon launching the application, a box pops saying that test.user is not authorized run the application.
I cannot imagine that is the only and best way to block applications??!