| Internet access per process | Large deployment config man
Posted: Sun Apr 03, 2011 8:22 am
Hi I've been looking at sandboxie for a possible corporate wide deployment - approx 500 desktops initially, going up to 2000 or so. I don't believe the following features exist (but maybe wrong).
1) Is there a way to push a sandboxie policy out to a large number of desktops that are in windows domains?
2) Block internet access except a specified process ?
For example, I run a sandbox for my email client which I have to allow internet access out of to be able to receive email etc. I receive a PDF with malware in an email. When I launch the PDF by double clicking the extension I believe this would launch in the same sandbox as my email client. While sandboxie hopefully would stop the malware being able to install anything long term (i.e remain after reboot if I set the sandbox to delete after the last application is closed), the malware would still be able to run and attempt to download further code etc. Ideally I'd like to be able to configure sandboxie to sandbox process "outlook.exe" in my configured "email" sandbox and only allow internet access to "outlook.exe"
1) Is there a way to push a sandboxie policy out to a large number of desktops that are in windows domains?
2) Block internet access except a specified process ?
For example, I run a sandbox for my email client which I have to allow internet access out of to be able to receive email etc. I receive a PDF with malware in an email. When I launch the PDF by double clicking the extension I believe this would launch in the same sandbox as my email client. While sandboxie hopefully would stop the malware being able to install anything long term (i.e remain after reboot if I set the sandbox to delete after the last application is closed), the malware would still be able to run and attempt to download further code etc. Ideally I'd like to be able to configure sandboxie to sandbox process "outlook.exe" in my configured "email" sandbox and only allow internet access to "outlook.exe"