Top
Systemwalker Desktop Keeper V14g Reference Manual
Systemwalker

1.25.6 Display Prohibition Settings Information (Operation Policy)

Functional Specification

Display prohibition settings information (operation policy).


Command Format

FSW11EJ7.EXE <Password> /D /Y [/Silent]

Option

<Password>:

Enter the password specified during installation of the client (CT).

/D:

Display information.

/Y:

Specify it when displaying prohibition settings information.

/Silent:

It is the option that is effective in the OS of Windows Vista® or higher. It can avoid displaying the following message after command execution.

Press any key to continue...

Return Value

0:

[Fixed Value]


Location for Saving Commands

When executing on the PC in which the OS is Windows Server® 2008 64-bit edition, Windows Server® 2008 R2, Windows Vista® 64-bit edition or Windows® 7 64-bit edition

%SystemRoot%\SYSWOW64\FSW11EJ7.EXE

When executing on the PC in which the OS is other than Windows Server® 2008 64-bit edition, Windows Server® 2008 R2, Windows Vista® 64-bit edition or Windows® 7 64-bit edition

%SystemRoot%\system32\FSW11EJ7.EXE

*%SystemRoot% is usually C:/Windows.


Authority Required for Execution/Execution Environment

Notes

Example of Use/Execution Results/Output Format

C:\>fsw11ej7.exe password /D /Y 
[User Information/Operation Policy Status/User Policy Query Status]
-User name        :  Administrator
-Domain name        :  DTK-DOMAIN
-User SID string     :  S-1-2-34-1234567890-1234567890-1234567890-100
-Run immediately after logon     :  1 (Inherit user policy of last time)
-Current running policy    :  0 (CT Policy)
-User policy receiving status :  2 (No user policy)
-Date and time of user policy reflection:  
[Prohibition Settings Information]
-Start prohibited application name
-Logon prohibition control
User group name of logon prohibition
-File export restriction switch:  1
 Display message during file export prohibition: 0
 Drive of monitoring object:  
 Drive type of monitoring object :  0
 Switch for File Export Utility:  1
 Specify the available days for startup      :  0
 Available days for startup        :  00000000 ~ 00000000
 Specify the available time for startup     :  0
 Available time for startup       :  0000 ~ 2359
 Available week for startup: Sunday, Monday, Tuesday, Wednesday, Thursday, Friday, Saturday
 Confirmation method of available date and time for startup    :  2
 Number of password characters during encryption   :  1 ~ 8
 Number of password attempts during encryption  :  0
 Number of days the password can be recovered during encryption: 0
 Specify encrypted file extension   :  0
 Encrypted file extension     :  ex_
 Prohibit the display of file format menu:  1
 Display removable media only  :  1
  Input switch of reasons for export  :  1
 File export original file backup  :  0
-Reading prohibition - Removable:  0
-Reading prohibition - DVD/CD   :  1
-Reading prohibition - Network:  0
 Number of registered folders that are allowed to access to network drive :  0 cases
 Path of the folder that is allowed to access to network drive 
-USB individual identification function      :  0
-Permission switch of all USB registered in Management Server:  1
-Disable switch of PrintScreen Key  :  1
-Printing prohibition switch   :  1
 Name of application that allows printing
-E-mail attachment prohibition      :  1
 Specify extension
-Recipient address confirmation switch during E-mail sending : 1
 Number of exclusion domains      : 2 cases
 Exclusion domain name
   Aaaaaaaaaa.aaaaaaaaaa.aaaaaaaaaa.jp.fujitsu.com
   dtk.com
-File operation log filtering switch  :  1
-Repeated log filter switch :  1
-Settings for window title log filter   :  1
 Number of settings for window title log filter :  0
 Object application name for window title log filter
-Screen capture setting    :  0
 Attached data saving location    :  0
 Number of settings for screen capture conditions:  0
 Object application name for screen capture condition 
 Screen capture-During Printscreen key prohibition :  Get 0 times
 Screen capture-During PrintScreen key operation:  Get 0 times
-URL access prohibition switch  :  1
  Number of settings for URL site prohibited to be accessed : 2 cases
  URL of site prohibited to be accessed 
   fujitsu.com
   fujitsu.co.jp
-FTP server connection prohibition switch  : 1
 Number of settings of FTP server allowed to be connected : 2 cases
 IP address of FTP server allowed to be connected 
   192.168.0.1
   192.168.0.2
-Web upload/download prohibition switch : 1
 Number of setting for URL of sites allow upload/download : 2 cases
 URL of site allow upload-download 
   fujitsu.com
   fujitsu.co.jp
-Clipboard operation prohibition switch:  0
-Clipboard operation prohibition backup original switch : 0
-Collection log switch     :  44031 (0-1-0-1-0-1-0-1-1-1-1-1-1-1-1-1-1)
-Sent E-mail content backup switch : 1
-Clipboard operation content backup switch:  0
-Printing monitor operation
 Warning         :  0
 Warning-Number of set pages  :  1
 Prohibit printing      :  0
 Prohibit printing-Number of set pages:  1000
 Aggregation unit        :  0
-Retry count of communication     :  3
-Communication timeout   :  300000

[E701-INF001] The Command has ended.

The following information will be displayed.

Item Name

Description

[User name]

It is the name of user that logs on to the client (CT) and executes command.

[Domain name]

It is the domain name or this computer name to be authenticated during logon.

[User SID string]

It is the unique internal code for identifying the user being managed in the OS.

[Run immediately after logon]

It is the policy status right after logon.

  • 0 (CT policy initialization): it is run according to CT policy and has nothing to do with the policy applied at last logon. It is same as the operation in V13.3.0 or earlier.

  • 1(Take over user policy of last time): Take over user policy of last time.

[Current running policy]

It is the policy that is running currently (during command execution).

  • 0 (CT policy)

  • 1 (User policy)

[User policy receiving status]

It is the application status of user policy.

  • 0 (Not received)

  • 1 (There is user policy)

  • 2 (There is no user policy)

[Date and time of user policy reflection]

It is the date and time when user policy has been applied.
When offline, the date and time when policy is received at last will be displayed.

[Start prohibition application name]

It is the application startup prohibition name specified in the [Application Startup Prohibition] tab when setting policy of Management Console.

[Logon prohibition control]

It is the group name prohibited from logon specified in the [Logon Prohibition] tab when setting policy of Management Console.

[File export restriction switch]

It is the information of radio button selected in the [File Export Prohibition] tab when setting policy of Management Console. It indicates whether to prohibit file export.

  • 1: When [No] is selected in [File Access Control]

  • 2: When [Yes] is selected in [File Access Control]

[Display message during file export prohibition]

It is the information of radio button selected in the [File Export Prohibition] tab when setting policy of Management Console. It indicates whether to display message during file export prohibition.

  • 0: When [Display message when prohibited] is not selected in [File Access Control]

  • 1: When [Display message when prohibited] is selected in [File Access Control]

[Drive of monitoring object]

It is the drive from A-Z specified in the [File Export Prohibition] tab when setting policy of Management Console.
It is not displayed when [No] is selected in [File Access Control].

[Drive type of monitoring object]

It is the information of [Removable] or [DVD/CD] selected in the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Removable] and [DVD/CD] are not selected

  • 1: When only [Removable] is selected

  • 2: When only [DVD/CD] is selected

  • 3: When [Removable] and [DVD/CD] are selected

[Switch for File Export Utility]

It is the information of radio button selected in [Export using File Export Utility] of the [File Export Prohibition] tab when setting policy of Management Console. It indicates whether the File Export Utility can be used. The export utility can be used in following cases except “1”.

  • 1: when [Not Allowed] is selected

  • 2: when [Allowed] is selected, and [Only encryption export is allowed] is selected

  • 3: when [Allowed] is selected, and [Only encryption export is allowed] is not selected

[Specify the available days for startup]

It is the policy information set in [Limit Period for Use] of [File Export Utility function setting] - [Set the date on which File Export Utility can be started] when setting policy of Management Console.

  • 1: Specify

  • 0: Not Specify

[Available days for startup]

It is the information of time when startup of export utility is allowed set in Limit Period for Use] of [File Export Utility function setting] - [Set the date on which File Export Utility can be started] when setting policy of Management Console.

  • YYYYMMDD - YYYYMMDD

(It is effective when the date specified when startup is allowed is 1. It is also displayed In the case of 0)

[Specify the available time for startup]

It is the information about the policy set in [Limit Period for Use] of [File Export Utility function setting] - [Settings of Date when Export Utility can be Started] when setting policy of Management Console.

  • 1: Specify

  • 0: Not Specify

[Available time for startup]

It is the information of time when the Export Utility can be started that is set in [Limit Time for Use] in [File Export Utility function setting] when Export Utility can be Started] when setting policy of Management Console.

  • HHMM - HHMM

(It is effective when the date when startup is allowed is 1. It is also displayed In the case of 0)

[Available week for startup]

It is the information of the day in a week when the Export Utility can be started that is set in [The day of a week on which it can be used] of [File Export Utility function setting] - [Set the date on which File Export Utility can be started] when setting policy of Management Console. The day on which startup is not allowed will not be displayed.

  • Sunday, Monday, Tuesday, Wednesday, Thursday, Friday, Saturday

[Confirmation method of available date and time for startup]

It is the information of policy set in [Date and Time Confirmation Method] of [File Export Utility function setting] - [Set the date on which File Export Utility can be started] when setting policy of Management Console.

  • 0: when [Date and time when CT is used] is selected

  • 1: when [Inquire Management Server] is selected and [Use Date and time of CT when it is unable to get] is selected

  • 2: when [Inquire Management Server] is selected and [Unable to start when it is unable to obtain] is selected

[Number of password characters during encryption ]

It is the information set in [Password Length] of [Detailed Settings of Encryption Export] of [File Export Utility function setting] of the [File Export Prohibition] tab when setting policy of Management Console.

  • Minimum number of characters - Maximum number of characters (Example: 1 - 128)

[Number of password attempts during encryption]

It is the policy information set in [Number of Password Attempts] of [File Export Utility function setting] - [Detailed Setting of Encryption Export] - [Decryption Restriction] when setting policy of Management Console.

  • 0: Not specify

  • 1 - 5: Indicates the number of password attempts.

[Number of days the password can be recovered during encryption]

It is the policy information set in [Number of days to decrypt] of [File Export Utility function setting] - [Detailed Setting of Encryption Export] - [Decryption Restriction] when setting policy of Management Console.

  • 0: Not specify

  • 1 - 999: Indicates the deadline of decryption.

[Specify encrypted file extension]

It is the policy information set in [File Export Utility function setting] - [Extension of encrypted file] when setting policy of Management Console.

  • 0: fixed as exe

  • 1: Specify Extension

[Encrypted file extension]

It is the information of extension of encrypted file set in [File Export Utility function setting] - [Extension of Encrypted File] when setting policy of Management Console.

  • Specify Extension (initial value is ex_)

(It is effective when [Specify encrypted file extension] is 1. It is also displayed In the case of 0)

[Prohibit the display of file format menu]

It is the information of [Unable to start the format function] selected in the [File Export Prohibition] tab when setting policy of Management Console.

  • 1: When [Unable to start the format function] is not selected

  • 2: When [Unable to start the format function] is selected

[Display removable media only]

It is the information of [Display only removable device and DVD/CD as export destination] selected [File Export Prohibition] tab when setting policy of Management Console.

  • 1: When [Display only removable device and DVD/CD as export destination] is not selected

  • 2: When [Display only removable device and DVD/CD as export destination] is selected

[Input switch of reasons for export]

It is the information of [Enter the reason for export] selected in [File Export Utility function setting] of the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Enter the reason for export] is not selected

  • 1: When [Enter the reason for export] is selected

[File export original file backup]

It is the information of [Backup Original File] selected in [File Export Log] in the [Log Switches] tab when setting policy of Management Console.

  • 0: When [Backup Original File] is not selected

  • 1: When [Backup Original File] is selected

[Reading prohibition-Removable]

It is the information selected in [Reading Prohibition] of the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Reading prohibition-DVD/CD]

It is the information selected in [Reading Prohibition] of the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Reading prohibition-Network]

It is the information selected in [Reading Prohibition] of the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Number of registered folders that are allowed to network drive]

Display the number of items set in [File Access Control - Detailed Settings] when setting policy of Management Console.

[Path of the folder that is allowed to access to network drive]

Display the permitted folder path of network drive set in [File Access Control - Detailed Settings] when setting policy of Management Console.

[USB individual identification function]

It is the information selected in [USB Device Individual Identification Function] of the [File Export Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Use] is selected

  • 1: When [Use] is selected

[Permission switch of all USB registered in Management Server]

It is the information selected in [Permission of Use of All USBs Registered in Management Server] of [File Export Prohibition - USB Device Individual Identification Function - Detailed Settings] when setting policy of Management Console.

  • 0: When [No] is selected

  • 1: When [Yes] is selected

[Disable switch of PrintScreen key]

It is the information selected in [Disabling PrintScreen Key] of the [Printing Prohibition] tab when setting policy of Management Console.

  • 1: When [No] is selected

  • 2: When [Yes] is selected

[Printing prohibition switch]

It is the information of the radio button of [Printing Prohibition] selected in the [Printing Prohibition] tab when setting policy of Management Console.

  • 1: When [No] is selected

  • 2: When [Yes] is selected

[Name of application that allows printing]

It is the name of application with printing permission specified in the [Printing Prohibition] tab when setting policy of Management Console.

[E-mail attachment prohibition] (Note 1)

It is the information of the radio button of [E-mail Attachment Prohibition] selected in the [E-mail Attachment Prohibition] tab when setting policy of Management Console.

  • 1: When [Do not Prohibit] is selected

  • 2: When [Prohibit (Permit Encrypted Files Only)] is selected

  • 3: When [Prohibit (Prohibit Specified Extension Only)] is selected

  • 4: When [Prohibit (Permit Specified Extension Only)] is selected

[Specify extension]

It is the extension name specified in the [E-mail Attachment Prohibition] tab when setting policy of Management Console.
When the value of [E-mail Attachment Prohibition] is 2, information will be output and displayed as “Extension with Prohibition of E-mail Attachment”.
When the value o [E-mail Attachment Prohibition] is 4, information will be output and displayed as the “Extension with Permission of E-mail Attachment”

[Recipient address confirmation switch during E-mail sending]

It is the information of radio button of [Confirm Recipient Address During E-mail Sending] selected in the [E-mail Sending] tab when setting policy of Management Console.

  • 0: When [Do not Confirm] is selected

  • 1: When [Confirm] is selected.

[Number of exclusion domains]

Display the number of items set in [List of Exclusion Domains] of the [E-mail Sending] tab.

[Exclusion domain name]

Display the domain name set in the[List of Exclusion Domains] of the [E-mail Sending] tab.

[File operation log filter switch]

It is the information of radio button selected in [File Operation Log Filter Operation Settings] of the [File Operation Process] tab when setting policy of Management Console. Display the setting of file operation log filtering conditions.

  • 1: When [Get All] is selected

  • 2: When [Get File Access on Removable Drive Only] is selected

  • 4: When [Get File Access on Network and Removable Drive Only]

[Repeated log filter switch]

Display the settings information of repeated log filtering operation of window title log.

  • 1: Filter disabled

  • 2: Filter is enabled

[Settings for window title log filter]

Display the settings of keyword log filter operation of window title log.

  • 1: When [Screening condition is not set] is selected

  • 2: When [Obtain matched logs only] is selected

  • 3: When [Exclude matched logs] is selected

[Number of settings for window title log filter]

Display the number of setting items of window title log filer condition.

[Object application name for window title log filter]

Display the process name and keyword of window title log filter condition.

[Screen capture setting]

Display the settings of screen capture function.

  • 0: When [Do not Use] is selected

  • 1: When [Use] is selected

[Attached data saving location]

Display the location for saving attached data (screen capture data, original file backup data).

  • 0: Save on the server (transfer to server)

  • 1: Save on the client (CT)

[Number of settings for screen capture conditions]

Display the number of setting items of screen capture condition.

[Object application name for screen capture conditions]

Display the process name, keyword and times of acquisition of screen capture condition.

[Screen capture-During PrintScreen key prohibition]

Display whether to screen capture during PrintScreen key prohibition.

  • Get 1 time: Perform screen capture.

  • Get 0 times: Do not perform screen capture

[Screen capture-During PrintScreen key operation]

Display whether to screen capture during PrintScreen key operation.

  • Get 1 time: Perform screen capture.

  • Get 0 times: Do not perform screen capture

[URL access prohibition switch]

It is the information of the radio button of [URL Access] selected in the [URL Access Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Specify access permission]

It is the information of the radio button of [Prohibit] selected in the [URL Access Prohibition] tab when setting policy of Management Console.

  • 0: When [Prohibit access to registered site] is selected

  • 1: When [Prohibit access to non-registered site] is selected

[Number of settings for URL of site prohibition to be accessed]

Display the number of items set in [List of Registered Sites] of the [URL Access Prohibition] tab. (It is effective when [Specify access permission] is 0.)

[URL of site prohibited to be accessed]

Display the URL set in [List of Registered Sites] of the [URL Access Prohibition] tab. (It is effective when [Specify access permission] is 0.)

[Number of settings for URL of site prohibition to be accessed]

Display the number of items set in [List of Registered Sites] of the [URL Access Prohibition] tab. (It is effective when [Specify access permission] is 1.)

[URL of site prohibited to be accessed]

Display the URL set in [List of Registered Sites] of the [URL Access Prohibition] tab. (It is effective when [Specify access permission] is 1.)

[FTP server connection prohibition switch]

It is the information of the radio button of [FTP Server Connection] selected in the [FTP Server Connection Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Number of setting for IP address of FTP server allowed to be connected]

Display the number of items set in [List of servers allowed to be connected] of the [FTP Server Connection Prohibition] tab.

[IP address of FTP server allowed to be connected]

Display the IP Address set in [List of servers allowed to be connected] of the [FTP Server Connection Prohibition] tab.

[Web upload/download prohibition switch]

It is the information of the radio button of [Upload and Download] selected in the [Web Upload and Download Prohibition] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Number of setting for URL of sites allow upload/download]

Display the number of items set in [List of sites that allow uploading and downloading] of the [Web Upload and Download Prohibition] tab.

[URL of sites allow upload-download]

Display the URL set in [List of sites that allow uploading and downloading] of the [Web Upload and Download Prohibition] tab.

[Clipboard operation prohibition switch]

It is the information of the radio button of [Prohibit Clipboard Operation between Different Environments] selected in the [Virtual Environment Setup] tab when setting policy of Management Console.

  • 0: When [Do not Prohibit] is selected

  • 1: When [Prohibit] is selected

[Clipboard operation prohibition backup original switch]

It is the information of [Backup Original File] of [Prohibit Clipboard Operation between Different Environments] selected in the [Virtual Environment Setup] tab when setting policy of Management Console.

  • 0: When it is not selected

  • 1: When it is selected

[Collection log switch]

It is the value converted the following binary bit array into decimal based on the information in the selected [Log Switches] tab when setting policy of Management Console.

[yes] is “1” and [no] is “0” in each item. In addition, the bit No. 0 is the value at the most right of the window.

Bit No. 0: Application Startup Log

Bit No. 1: Application Termination Log

Bit No. 2: Window Title Obtaining Log

Bit No. 3: E-mail Sending Log

Bit No. 4: Command operation Log

Bit No. 5: Device Configuration Change Log

Bit No. 6: Printing Operation Log

Bit No. 7: File Export Log

Bit No. 8: File Operation Log

Bit No. 9: Logon/Logoff Log

Bit No. 10: 0 (is “0”)

Bit No. 11: Linkage Application Log

Bit No. 12: 0 (is “0”)

Bit No. 13: PrintScreen Key Operation Log

Bit No. 14: FTP Operation Log

Bit No. 15: Web Operation Log

Bit No. 16: Clipboard Operation Log

[Sent E-mail content backup switch]

It is the information of [E-mail Content Can be Viewed] selected in the [Log Switches] tab when setting policy of Management Console.

  • 0: When [E-mail Content Can be Viewed] is not selected (Do not keep)

  • 1: When [E-mail Content Can be Viewed] is selected (Keep)

[Clipboard operation content backup switch]

It is the information of [Backup Original File] selected from [Clipboard Operation Log (Virtual Environment)] in the [Log Switches] tab when setting policy of Management Console.

  • 0: When [Backup Original File] is not selected

  • 1: When [Backup Original File] is selected

[Warning]

It is the information set in [Operation when the set number of pages for printing is reached] of the [Eco Monitoring Settings] when setting policy of Management Console.

  • 0: When [Warning] is not selected (Not Warn)

  • 1: When [Warning] is selected (Warn)

[Warning-Number of set pages]

It is the information set in [Operation when the set number of pages for printing is reached] of the [Eco Monitoring Settings] when setting policy of Management Console.

  • Range of 1 - 999999

[Prohibit printing]

It is the information set in [Operation when the set number of pages for printing is reached] of the [Eco Monitoring Settings] when setting policy of Management Console.

  • 0: When [Prohibit Printing] is not selected (Not Prohibit)

  • 1: When [Prohibit Printing] is selected (Prohibit)

[Prohibit printing-Number of set pages]

It is the information set in [Operation when the set number of pages for printing is reached] of the [Eco Monitoring Settings] when setting policy of Management Console.

  • Range of 1 - 999999

[Aggregation unit]

It is the information set in [Unit for aggregating number of printing pages] of the [Eco Monitoring Settings] when setting policy of Management Console.

  • 0: When [Daily] is selected

  • 1: When [Weekly] is selected

  • 2: When [Monthly] is selected

[Retry count of commuication]

It is the retry times for the communication between client and Management Server.

[Communication timeout]

It is the timeout value (milliseconds) of the communication between client and Management Server

Note 1) When all of the following conditions are satisfied, [Do not Prohibit] will be set as operation policy. Therefore, “1” is displayed.

・When Management Console is V14.0.0 or later

・When [Prohibit (Permit Specified Extensions Only)] is selected in the [E-mail Attachment Prohibition] tab of policy setting

・When the client (CT) is V13.3.0 or earlier