BeyondTrust News Events

DesktopStandard Upgrades PolicyMaker™ Application Security, a Group Policy Extension for Implementing ‘Least Privilege’ Security

Adds support for end-user installation of approved ActiveX and Microsoft Installer components

Portsmouth, NH – January 3, 2006 – DesktopStandard Corporation today announced the release of PolicyMaker™ Application Security (PMAS) 2.0, a major upgrade to the patent pending software solution that enables network administrators to enforce the security principle of Least Privilege on Windows desktops via Microsoft’s Group Policy change and configuration management system. PMAS was the first product to make it possible to reduce or elevate permissions on a per-application or per-task basis, removing longstanding barriers to implementation of the security best practice of Least Privilege.

With this add-on to the Group Policy Management Console (GPMC), administrators can adjust application privilege levels to the lowest possible point in order to limit damages stemming from network attacks or user error. The ability to control security at such a granular level also helps organizations comply with regulatory mandates such as the Sarbanes-Oxley, HIPAA and Gramm-Leach-Bliley acts.

The product allows administrators to:

  • Elevate the permission level for restricted users who are performing selected tasks or running applications that require higher privileges than those to which the user is normally entitled. This eliminates the need to raise each user’s privilege levels for all applications which would expose the network to unnecessary risk.
  • Reduce the permission level for administrators working on general applications, such as Internet Explorer and Microsoft Outlook. This avoids the use of full administrative permissions for applications that do not have such a need, and without the need to log out and then in as a different user, use the Windows RunAs utility to work under a second user account, or invoke other complicated procedures that reduce productivity.
  • Allow restricted users to install approved ActiveX controls while running Internet Explorer in their restricted user security context. This new feature makes restricted user scenarios much more practical, as many organizations have extensive libraries of ActiveX controls or allow use of such controls that install from approved third party sites – including Adobe’s Acrobat Reader for example.
  • Provide self-service software installation points for restricted users, greatly reducing administrator workload in supporting unmanaged software installation without compromising security. Many organizations have libraries of software packages that end-users may elect to install by simply browsing to them on a network location. This new feature makes it a simple task to support secure elevated permissions installation of such executable and Windows Installer packages.

According to DesktopStandard CTO Eric Voskuil, “Windows provides a Group Policy setting that allows administrators to specify that all Windows Installer packages install with administrator permissions. The use of this feature effectively makes the end-user an administrator, as any package they choose to install will run with administrator permissions. With PolicyMaker’s secure self-service installation points, software installations are elevated only for packages that the network administrator has placed into the approved network shares.”

Martin Larsson, System Administrator for Ongame e-solutions AB, stated that, "We have now deployed PolicyMaker Application Security to 350 desktops and are more than satisfied! It allows us to keep our users restricted instead of having to make them local administrators, and it's easy to install and implement. Combined with PolicyMaker Standard Edition's ability to eliminate logon scripting and manual configuration, it saves us a lot of time when new hires start at the company. We're excited about the new features and the ability to provide self-service installation points, which should greatly reduce our software deployment costs." Ongame is one of Sweden's fastest growing companies and was named IT Company of the Year 2005 by Swedish business weekly Veckans Affärer.

The complete suite of PolicyMaker products offers a total of 24 extensions to the Group Policy system that has been integrated with Active Directory since the release of Windows 2000. These extensions complement the 11 native extensions that ship with Windows. All PolicyMaker products seamlessly integrate with Microsoft’s Group Policy Management Console, including backup, restore, import, copy, edit, and RSoP capabilities. PolicyMaker settings can be targeted using any of 25 graphical filtering categories.

Pricing, Specifications and Availability
PolicyMaker Application Security 2.0 is available immediately from DesktopStandard and authorized resellers. Pricing starts at $27 per seat for enterprises with less than 1,000 computers, including one year of upgrade assurance and technical support. PolicyMaker supports Windows 2000, XP and 2003 Server, Terminal Server, MetaFrame and all versions of Outlook, Office and Internet Explorer.

About DesktopStandard Corporation
DesktopStandard Corporation is the leading developer of Group Policy-based enterprise desktop management products. The company has more than 3,500 customers, more than 4 million desktops under management and a worldwide network of integrators and resellers. DesktopStandard is a Microsoft Gold Certified ISV.

DesktopStandard has provided a long string of innovative and integrated Group Policy firsts. PolicyMaker Standard Edition was the first product based on Group Policy Extension (first released in 2003), eliminating the need for logon and startup scripting. PolicyMaker Software Update (2004) was the first Group Policy-based patch management product. PolicyMaker Application Security (2004) was the first product to allow administrators to assign permissions to applications and tasks, enabling Least Privilege on Windows. PolicyMaker Share Manager (2005) was the first product to provide Group Policy support for file servers and Windows Server 2003 Access-Based Enumeration. GPOVault (2005) was the first product to integrate Group Policy change control and offline editing into Microsoft’s Group Policy Management Console (GPMC).

DesktopStandard products have won many prestigious awards, including the “Most Innovative Product of 2005” (Windows IT Pro Readers’ Choice Awards), “Most Valuable Product” (Redmond Magazine), “Best Product of 2005 - Policy Management” (MSD2D People’s Choice Security Award), and the “2004 Active Directory Product of the Year” (SearchWin2000.com).

For more information, visit www.desktopstandard.com.

DesktopStandard, PolicyMaker and GPOVault are the trademarks or registered trademarks of DesktopStandard Corporation. Other product and company names herein may be trademarks of their registered owners.

rounded