Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To further lock down applications in the sandbox, you can adjust process rights to add a restricted SID. (For more information, go to [REVIEW] Adjust Process Rights ImprovementsAdjust process rights - restricted SID.)

Tip
titleNote

Some of the Internet-facing apps today (such as Internet Explorer, Chrome, Word, and Adobe Reader) already implement their own extended sandboxing. As such, the sandboxing feature would not apply to them.

For further reading about Application Sandboxing application sandboxing in Windows, go to:

Create

...

sandbox action

To create a sandbox action, do the following steps:

  1. In the Thycotic Security Manager Console, click the Policies tab.
  2. In the file library in the left pane, navigate to Arellia Thycotic Solutions > Application Control > Actions.
  3. Right-click the Actions folder, click New, and then click Sandbox Action.
    Image RemovedImage Added
  4. In the Create Item dialog box, give the sandbox a Name , Description and Classification.

    Tip
    titleNote
    The Name is the identifier you give to the action in Arellia Management Server; the Classification is the system-wide identifier in Windows

    and Description.

  5. Click Save.
    Image Removed
    Image Added

  6. In the right-pane, set the Restrictions by selecting the check boxes.
  7. Click Save.
    Image RemovedImage Added

You can find the new action at the bottom of the list of Actions folders.

...