@Andy Ful (another feature request
)
After recent Christmas, I helped a few family members moving the 2-3 year old PC's of the kids of wealthy family members to the kids of less fortunate family members. An easy trick of making those PC's fly again was by adding an SSD. In the spirit of Christmas I paid the SSD of the first family member (luckily it stopped after four PC's, so It stayed within limits cost wise). Installing Windows 1809 from scratch turned out the easiest way (less time spend) of accomplishing this. I also installed free-office (of softmaker)*
Using Hard_Configurator and Defender_Configurator (I always add folder of D partition where I put their data but did not enable Protected Folders).Because I don't want to get called every time, I removed H_C and D_C after the job and manualy changed SRP (Safer) registry settings making sure the SRP:
- is valid for all executables except DLL's
- is valid for all users except Administrators
- removed the values EXE, MSI, MSU, LNK from Executables from registry Multi-MZ field
I manually add a "DENY TRAVERSE FOLDER/EXECUTE FILE" for EVERYONE to their Downloads/Documents/Movies/Pictures/Videos user folders (on data partition D) and on root folder of Public user. I also have two reg-files which lock some settings of Chrome and Edge by manually setting the registry keys of corresponding Edge/Chrome group policies (and set some Chrome flags increasing security).
Finally I disable IE11 and WMP and install VLC from Windows Store and set Edge as default for PDF.
Although not as strong as a default deny. This zero config/zero really is a great addition to any average JOE/JANE home user pc setup. Under normal usage this does not put any functional restriction on the usability of their PC, but reduces the attack surface substantially. Best of all IMO that it uses Windows internal mechanisms (spend no cpu cycles or money on extra software).
Any chance of inspiring you to make it a special version of Hard_Configurator, called ZERO_configurator?
Regards Kees
P.S. *
Another reason to use it this way is that FREE OFFICE does not run nicely in a default deny SRP. On internet revews still mention that free-office does not allow you to save files in M$Office formats, just go into FILES section in OPTIONS for each application and set it default save format as DOCX (in Textmaker), XLSS (in Planmager), etc. Also you can download free Hunspell spellingcheck in free version Softmaker website.