Posted on 02-28-2014 01:39 PM
We are successful with blocking any apps outside of the specific folders that we allow using a configurations profile. Using the restrictions - Apps feature. We Allow the following folders:
/Applications Folder
/var
/usr
/private
We allow these folders for any system apps that may need to run outside of the Applications folder.
I have disallowed the opening of apps from the following folders:
/Library/Application Support/App Store
/Library/Caches
Students were opening apps from these folders because every other folder is writable and thus, they were able to open apps from these folders
This works very well except we found out that Microsoft AutoUpdate won't run. Even if I add the parent directory(/Library/Application Support/Microsoft/MAU2.0) is still says it doesn't have permission. I have added the .app and even the file embedded in the package. I am still unable to get microsoft Auto Update to run. If I add the /Library folder to the Allowed folders list. It will run but then it opens up the Caches or App Store folder to have apps run from them even though they are still in the disallow folder. This is very confusing and any insight into this would be greatly appreciated. Thanks for your time. First time posting here so I hope I am making sense.
Posted on 02-28-2014 02:29 PM
What if you Allow:
/Library/Application Support/Microsoft
Posted on 03-03-2014 06:26 AM
Hi, thanks for your response. Adding (/Library/Application Support/Microsoft) to the allowed folders list as well as Adding the Application Support folder didn't resolve the issue.
Posted on 03-03-2014 08:41 AM
I wonder if it is trying to get to LaunchAgents and LaunchDaemons. That may be the other folder in Library.
Posted on 03-03-2014 08:53 AM
I just added the LaunchAgents and Launch Daemons folders to the allowed list. Issue still persist. The error I am getting is the same error I get when any other app that is restricted is blocked. "
You don't have permission to use the application "Microsoft AutoUpdate."
For more information, contact the person who set up your account.
Posted on 03-03-2014 05:35 PM
The Microsoft AutoUpdate application has no dependencies on other applications. If it's still blocked then the issue is more than likely with the profile. If you view it in System Preferences or System Information does it appear correct? If you remove the profile from a test machine does the application launch?