Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Deny Execute (Blacklist) policies should target specific applications unless being used in conjunction with whitelist policies. Targeting no applications will target all applications with conditions.
  2. To ensure blacklist policies do not affect system or service applications: from the Arellia Management Console click on Policies, open Policies->Arellia->Application Control->Policies and select your Blacklisting Policy.
  3. Select they hyperlink next to Exclude Any: Image Removed Image Added
  4. Then select Arellia->Application Control->Filters->Dynamic Filters->Application Context-> "LocalSystem and Service application" and move that to the right side. Doing so should prevent the blacklist policy from stopping and Windows Services and Programs from running. This will allow you to update a policy and recover from a bad Deny Execute (blacklist) condition.

...