Skip to main content

Hi Community,

we are rolling out Windows 11 at the moment and with each Windows 11 device we add the low flex policy (we call it our standard policy) to each client. Doing that, many people are complaining that applications they had on their former Windows 10 device are no longer there. Sure, we wanted to reduce the number of the overall applications used, as usually nobody knows how these apps made it to the machine of the user 😊

But -and this is the reason for starting this discussion- what we do not want is to granting higher permissions to the users.

What are your best practices to get this under control better? Some guidance on that would be really appreciated.

There are many options to accomplish this.

  1. Have a Software Restriction Policy (SRP)in place, and create a EPM Policy that enforces that policy and block it. This is more needed as many application can install in the context of a standard user.
  2. Use massages for when people launch software, link and describe the SRP 
  3. Configure JIT Application requests.

Consolidation of tools: Less applications is better, no reason for having 7 different PDF tools.

people have a tendency to think some software is “free” but running over EULA many License agreements changes when the software is used in an enterprise environment, so any new software is calling for a solid review of software running on company provided computers. If not doing so can be costly affair. 

Avoid leisure applications thick clients: samples “Spotify, Tidal, WhatsApp” etc. they all come with a risk for no reason. Users should run these on their cell phone and or other personal devices, and not add a risk to the company environment.

Review your policy design using analytics, pre-approve software with Allow- listing making it easier to see newly introduces software.

It is rare that I see a company reach the ultimate allow listing, and can switch the (default) Any application rule to show a “Allow Message “Support Desk)” message again, which is the default under your Low Flexibility workstyle. but getting to that point ensure you do not have anything unknown executed, of course with the exception of rules being misconfigured else where in policy that can be misused.

 


Reply