Hey all
I am trying to think of the best course of
action on this problem:
Management wants to install certain applications on our
baseline. They want to restrict all users except those within certain
groups from running these applications.
possible solutions:
1. Set a machine software restriction policy that disallows
all from using the different executibles. Then create a user Software
restriction policy that allows the users in these groups to run the
programs. This policy would only apply to the
group.
2. Set a User software restriction policy as part of
the normal user policy settings that disallows users from the different
executibles. Create a second policy that applies only to the group with
permissions to use the program that allows the software to run.
Which do you think would be better. Also is my
thinking in the right place that the second policy will override the first
policy.
Jeff
