Restrict an Application's Process Rights
This scenario describes the process involved in restricting an application's process rights. This sample scenario guides you through the necessary steps, using the default Limit Internet Explorer and Outlook process rights policy.
Scenario Description
In this scenario, the end user has:
...
With this configuration, Internet Explorer has inherited administrative rights from the user and is therefore able to stop Windows Services.
Scenario Resolution
To access the Application Control Policies page:
- In the Symantec Management Console, on the Home menu, click Arellia > Application Control
- In the left pane, select Policies > Application Control > Application Control Tasks > Application Control Policies > Limit Internet Browser and Mail Client Process Rights
To prevent Internet Explorer from stopping Windows services, perform the following steps:
...