Hello all,
I've got a number of laptops that staff use on and offsite on a regular basis. They're trusted users so can install software they see fit and the software on them updates regulary, such as Flash, Google stuff etc.
They have a policy set on the server, and firewall is set to block by default, this is so all new apps are flagged up and I can add them to the global policy and make sure they're not using anything too risky, rather than them being able to have an interactive policy that gets overwritten every time they update!
My question is thus:
When I get something appear in the event viewer, I "create rule" and "allow all activity" for the application for the shear simplicity of it.
Does this pose a security threat? Should I be creating a specific rule for each application to only let it access the internet in a certain manner? And would this potentially allow all inbound activity too for a possibly corrupt/infected application from an outside source?
Thanks,
Ben
This thread was automatically locked due to age.