Top
Systemwalker Desktop Patrol Operation Guide: for Administrators
FUJITSU Software

2.6.1 Settings

After setting the control of executable file, if the specified software is executed at client, the following operations can be performed.

Set the detection and prohibition of executable file according to the following procedure.

  1. Set executable file and message

  2. Set software operation status collection

  3. Application of client policy

  4. Log on CT again


2.6.1.1 Set Executable File and Message

Specify the detection settings of executable file on client PC and the executable file that is warned/prohibited being used in client. In addition, specify the message to be displayed when the executable file is started.


The procedure is as follows.

  1. Login to the main menu and click Environment Setup.

    The Environment Setup window is displayed.

  2. Click Policy Groups.

    The following window is displayed.

  3. Click the Customize various policies button.

    The following window is displayed.

  4. Select the Basic Operation Policy tab, and click the link of policy name.

    The following window is displayed.

  5. Click the Common settings tab.

    Click Control of Executable File, and the following items will be displayed.

    Item

    Description

    File Name

    Specify the name of the file for execution control using up to 129 fullwidth characters or 259 halfwidth characters. The last four characters must be ".exe".

    Add button

    One line of the field for which the control of executable file can be specified will be added.

    Delete button

    Delete the control of executable file specified at the line of deletion button.

    Control

    (Note 1)

    Select the control.

    • Warning

      Display the message when the executable file is started.

      The message content is specified in Warning.

    • Execution Prohibition

      When the executable file is started, exit it by force.

      When displaying message at the time when execution is prohibited, select Display message when execution is prohibited and specify the message content.

    • Detection and Warning

      Display message when the executable file is detected and when the executable file is started.

      Specify the message content in Detection and Warning.

    • Detection and Execution Prohibition

      Display a message when the executable file is detected, and exit the executable file by force when it is started.

      Specify the message displayed at detection in Detection.

      When message needs to be displayed at execution prohibition, select Display message when execution is prohibited and specify the message content.

    Message to display

    (Note 2)

    Specify the message to be displayed when the executable file is started using up to 512 fullwidth characters or 1024 halfwidth characters. It cannot be omitted.

    After (%ProgName%) is recorded in the text of message, when the software specified in the executable file name is started, the executable file name will be displayed.

    Specify the message to be displayed when the executable file is detected using up to 512 fullwidth characters or 1024 halfwidth characters. It cannot be omitted.

    After (%ProgName%) is recorded in the text of message, when the software specified in the executable file name is started, the executable file name will be displayed.

    In addition, after (%ProgName%) is recorded, the folder name where the detected file is located will be displayed in message text.

    When displaying message at the time when the start of executable file is prohibited, select "Display message when execution is prohibited" and specify message content using up to 512 fullwidth characters or 1024 halfwidth characters. It cannot be omitted.

    After (%ProgName%) is recorded in the text of message, when the software specified in the executable file name is started, the executable file name will be displayed.

    Note 1)

    Same executable file name cannot be specified in Warning and Execution Prohibition.

    In inventory collection, when the executable file on client PC is detected, the detection message will be displayed.

    The detection message will be displayed in the information at every time of inventory collection until uninstallation.

    Note 2)

    The following variables can be used in messages.

    • %ProgName%

      Display the detected file name in the text of message. This variable can be used in the following messages.

      • Warning message

      • Detection message

      • Execution prohibition message

    • %ProgFolder%

      The folder name where the detected file is located will be displayed in the text of message. This variable can be used in the following messages.

      • Detection message

  6. Confirm settings and click the Apply button.

    The settings are saved.

Note

For detection of executable fie, only the following fixed drives will be detected.

  • Built-in hard disk

  • Network connection hard disk using the "NDAS" technology

  • Part of USB connected hard disk (Note)

However, the executable file in the Recycle Bin of Windows cannot be detected. However, the executable files exist in the folder within the Recycle Bin of Windows can be detected.

Note) The conditions of USB connection hard disk that can be detected are as follows.
Select this drive in Windows Explorer, select Type of the General tab in the hard disk properties window displayed in File > Properties, and the hard disk displayed as Local Disk here can be detected.


2.6.1.2 Set the Collection of Software Operation Status

In order to perform warning and execution prohibition of the start of executable file, it is required to specify the software operation status collection to Yes in the collection conditions of client policy. In addition, when the executable file can be detected only, this setting is not required.

Check in the main menu about whether the software operation status collection has been set.

Settings of Collected Items of Environment Setup > Policy Groups > Customize Various Policies > Basic Operation Policy tab > Inventory Information tab of the main menu.


2.6.1.3 Apply Client Policy

When information in "2.6.1.1 Set Executable File and Message" and "2.6.1.2 Set the Collection of Software Operation Status" mentioned above is set to CT when the client policy is applied.

The client policy is applied according to the schedule set in the main menu. For schedule, confirm in the main menu.

Settings of Collection Schedule of Environment Setup > Policy Groups > Customize Various Policies > Basic Operation Policy tab > Inventory Information tab of the main menu


2.6.1.4 Log on CT Again

The setting of "2.6.1.1 Set Executable File and Message" and "2.6.1.2 Set the Collection of Software Operation Status" mentioned above will be effective when log on to the PC again after the client policy has been applied to CT.

Log on to each PC again at the timing when operation starts.