Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 19 Next »

What's Covered

Create an Environment Variable Filter

Create an Environment Variable Action

Create a Blank Application Control Policy

Test the New Policy

 

Using Application Control Solution you can override UAC prompts for end-users. You can create custom messages that require users to submit a reason for requesting administrator rights, which replace UAC prompts for credentials.

You can create three types of custom messages: (For details on how to create this custom message, go to

  1. Self-Elevation Without Adding Administrator Rights will capture the reason and close the application. (For details on how to create this custom message, go to [READY] Self-Elevation Without Adding Administrator Rights.) 
  2. Self-Elevation will capture the reason and allow end users to automatically have administrator rights. (For details on how to create this custom message, go to [READY] Self-Elevation.)
  3. Request Elevation will capture the reason and go through an approval process with the help desk. (For details on how to create this custom message, go to [READY] Request Elevation.)

 

Overriding UAC prompts is a three-step process:

  1. Create an Environment Variable Filter.
  2. Create an Environment Variable Action, which you'll use to prevent the UAC prompt from appearing.
  3. Create a Blank Application Control Policy.
  4. Test the New Policy

Create an Environment Variable Filter

To create an Environment Variable Filter, do the following steps:

  1. In the Security Manager Console, click the Policies tab.
  2. In the file library in the left pane, navigate to Policies > Arellia Solutions > Application Control > Filters > Dynamic Filters > EnvironmentalVariables. 
  3. Right-click Environment Variables and click New > Environment Filter.
  4. In the Create Item dialog, enter a Name and Description.



  5. Set the variable Name to __APPINFO_RUNADMIN and set the Value of 1.
  6. In the Match Type menu choose Partial.
  7. Click Save.

Create an Environment Variable Action

To create an Environment Variable Action, do the following steps:

  1. In the file library in the left pane, navigate to Policies > Arellia Solutions > Application Control > Actions > Environment Variables.
  2. Right-click Environmental Variables and click New > Set Environment Variable Action.
     
  3. In the Create Item dialog, enter a Name and Description


     
  4. Set the Environmental Variable Name to __APPINFO_RUNADMIN
  5. Leave the Value field empty. 
  6. Click Save.

Create a Blank Application Control Policy

Next, create a Blank Application Control Policy by doing the following steps:

  1. In the file library in the left pane, navigate to navigate to Policies > Arellia Solutions > Application Control > Policies. 
  2. Right-click Policies and click New > Blank Application ControlPolicy. 
     
  3. In the Create Item dialog, enter a Name and Description 


     
  4. In the right pane under the Applications to Control, click the Applications link and choose the new Environment Variable Filter. (Optionally you can change this so only certain applications or certain users will see the overridden UAC prompt.)
  5. Under Conditions (optional), click the Exclude any and add the Administrators filter to stop child processes (which inherit elevation) from triggering this policy.
  6. Click the Application Actions tab.
  7. To the right of Applications, select Application action and then click the Select link.
  8. In the Select Items dialog box, select the following:
  9. The Environment Variable Action you created previously.
    1. Add Administrator Rights.
    2. Justify Application Elevation Dialog (this will behave like Self-Elevation).
    3. Justify Application Elevation (kill process) Dialog (will behave like Self-Elevation Without Adding Administrator Rights).
    4. Approval Request Form Action (will behave like Request Elevation).
  10. Click Save

Test the New Policy

To test the new policy, do the following steps:

  1. Update the policies on an endpoint. 
  2. Test the policy by right-clicking Command Prompt and click Run as administrator.

Instead of seeing UAC, you will see the custom message shown in the following screenshot.

The recorded response will then be sent to the Arellia Management Server where it can be reviewed by the help desk team.

 

  • No labels