DesktopStandard last week released software that helps corporations secure end-user desktops by controlling the privileges they have on their own PCs on an application-by-application basis.
The company, formerly known as AutoProf, introduced PolicyMaker Application Security (PMAS), which is tightly integrated with Microsoft’s Active Directory to centrally control administrative rights per application on Windows desktops.
End users with administrative rights to their desktops pose a number of security risks, such as the ability to load new software, change settings or override administrative policies. Also, any malicious code that could infect the end-user desktop via programs such as Internet Explorer can elevate its activity up to local administrator, which would let the nefarious code do anything on the machine.
In Windows, administrative rights are either on or off system-wide, but PMAS fine-tunes that setting by using centrally managed controls via Active Directory’s Group Policy feature.
Group Policy, which is supported on Windows 2000, XP and Server 2003, works in conjunction with Active Directory. It lets administrators manage and customize desktop and server settings based on a set of policies stored in the directory.
PMAS adds an extension to Group Policy that lets administrators assign administrative rights just for desktop applications that need them to run.
“From a security perspective, we do not have to give an end user higher privileges than what they need,” says Nick Duda, senior systems administrator at VistaPrint in Lexington, Mass. “It secures our desktops and gives administrators more control over managing the network and our systems.”
VistaPrint, which has a call center in Montego Bay, Jamaica that serves its 4 million customers, gave 200 end users ultimate control of their desktops just so they could run a few custom applications that require administrative rights.
“Now we can attach and modify security privileges on individual applications, which is what we need in our environment. It allows us to take away admin rights and apply them specifically to a program,” Duda says.
PMAS centers on one extension it adds to the group policy feature in Active Directory. Administrators install the software on any administrative workstation, and the extension is added to Active Directory’s Group Policy store and replicated throughout a corporation’s directory infrastructure. Using Active Directory’s Group Policy editor, users then configure settings that apply to certain applications.
The settings are implemented in the background on the desktop when a user logs on.
PMAS costs $21 per seat, per 1,000 users.




