One of the cooler things that you can do with Group Policy in an Active Directory environment is set Software Restriction Policies, or SRP’s. These are rules that basically say things like “nobody’s allowed to run AnnoyingProgramSetup.exe”. You can get more sophisticated and create rules such as “nobody’s allowed to run VBS scripts, but we’ll make an exception for GOODSCRIPT.VBS.” Because SRP’s are implemented via Group Policy, you can tailor them to different Organizational Units, sites, and domains.
One of the new capabilities touted for Windows 7 clients is something called “AppLocker,” which purports to do pretty much the same thing as Software Restriction Policies. AppLocker appears to be a bit more sophisticated in that it can detect application versions, as long as they are present in the application’s digital signature. For example, one might create a rule that says “go ahead and let people run recent versions of COOLAPP, which are OK, but not older versions, which we know are buggy.” If the application’s digital signature doesn’t contain version information, however, it seems that this capability won’t work. That may or may not be a problem, depending on what type of software you’re trying to block.
Maybe there are cool aspects of AppLocker that will become clearer as time progresses, but as far as I can see right now, it’s little more than a feature name change. And not even a good one, at that – “AppBlocker” would have been more accurate! (If, admittedly, a little harder to pronounce.)
Recent posts:




