Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Application Sandboxing is a feature of an action in Application Control Solution (ACS) that limits the environments in which certain code can execute. In other words, it means running The sandbox runs a process in a Job that job object that limits its ability to interact with other processes, as well as limiting some specific types of interactions with the operating system, such as:

  • Reading or writing from the clipboard
  • Shutting down the system
  • Adjusting display settings

 

 To further lock down applications in the sandbox, you can adjust process rights to add a restricted SID. (For more information, go to Adjust process rights - restricted SID.)

Tip
titleNote

Some of the

...

Internet-facing apps today (such as

...

Internet Explorer, Chrome, Word, and Adobe Reader) already implement their own extended sandboxing. As such,

...

the sandboxing feature would not apply to them.

 

Further reading that Application Sandboxing in Windows can be found atFor further reading about application sandboxing in Windows, go to:

...

"They restrict the process so they’re not allowed to Write to the Windows and everything and they have their own API set to…in essence they can’t use the Windows API set and have to use a restricted API set that the Parent sets up to communicate back to a trusted process to do any user interaction or anything like that."

"You can place multiple apps in the same sandbox, but the process rights is another level of security on the sandbox."

...

Create sandbox action

To create a sandbox action, do the following steps:

  1. In the Thycotic Security Manager, click the Policies tab.
  2. In the file library in the left pane, navigate to Thycotic Solutions > Application Control > Actions.
  3. Right-click the Actions folder, click New, and then click Sandbox Action.
    Image Added
  4. In the Create Item dialog box, give the sandbox a Name and Description.

  5. Click Save.

    Image Added

  6. In the right-pane, set the Restrictions by selecting the check boxes.
  7. Click Save.
    Image Added

You can find the new action at the bottom of the list of Actions folders.