Inventors:
Peter David Beauregard - Dover NH, US
Andrey Kolishchak - Luxembourg, LU
Shannon E. Jennings - Exeter NH, US
Robert F. Hogan - Portsmouth NH, US
International Classification:
G06F 21/00
G06F 15/16
Abstract:
To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a token of a process. The rule may include an application-criterion set and changes to be made to the groups and/or privileges of the token. The rule may be set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers or users. When a GPO containing a rule is applied to a computer, a driver installed on the computer may access the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule, the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.