Top 20 PolicyPak Powers

The Top Twenty Things you cannot do with GP, SCCM, Altiris or Intune…but you can with PolicyPak!

20. Manage application settings

in the box

You can only manage applications that ship with ADMX files like Microsoft Office, Google Chrome, Microsoft EMET, and… not much else.

With PolicyPak

You can manage over 200 applications , including:
  • Firefox
  • Java
  • Internet Explorer
  • OpenOffice
  • Adobe Products
  • Flash
  • AutoCad
  • Lync
  • … and hundreds more!

19. Pre-Defined STIG security, ready for import

STIGs contain technical guidance to “lock down” information systems or software that might otherwise be vulnerable to a malicious computer attack.

in the box

There’s a need to manually craft image with settings pre-baked in (which users can usually just work around).

With PolicyPak

You can manage the following STIGs straight away:
  • Java
  • Microsoft Office
  • Internet Explorer 8, 9, 10, 11
  • Outlook
  • Windows 7, 8, 8.1
  • Lots more and
  • More as they are released by the US government

18. Set up default browsers and open websites in the right browser

in the box

It’s not possible for IT to set which default browser to use, and ensure that setting is locked down. Users can always “Say Yes” constantly changing the default browser, which generates helpdesk issues.

Users also open up the “wrong” browser for their websites. How many times can you answer the same question about which browser to use for what website?

With PolicyPak

  • Internet Explorer
  • Chrome
  • Firefox
  • Microsoft Edge
  • Any other browser

Plus, PolicyPak auto-remediates even if users change it.

Additionally, PolicyPak will open up the right browser based upon your rules. Open up IE for some pages, Firefox for others, and so on.

17. Perform UI lockdown to most applications

in the box

User Interface lockdown is only supported for some applications – those applications which ship with an ADMX file.

With PolicyPak

User Interface lockdown is supported for most applications, via our pre-configured Paks, including the following applications:

  • Java
  • Firefox
  • WinZip
  • Lync
  • Adobe Reader / Writer

16. Automatically remediate IT settings

in the box

When computers are offline, no Microsoft Group Policy settings of any kind are auto-remediated. When computers are online, only Group Policy Preferences are auto-remediated.

With PolicyPak

Every kind of setting is automatically remediated, whether online or offline. That includes:

  • All application settings
  • All Group Policy Preference settings
  • All Group Policy Security settings

15. Take ownership of registry portions and files

in the box

This isn’t available at all: end-users, scripts and bad-guys can always overwrite settings and files.

With PolicyPak

This is available for all applications, and for Registry or Files, meaning that you own the registry or file, not your end-users.

14. Target policies and settings

in the box

Targeting is only available for Group Policy Preferences.

Targeting settings for Admin Template policies
Targeting settings for applications

With PolicyPak

Targeting is extended to all Microsoft settings and all application settings. That includes hundreds of applications via Application Manager, and over 3000 Group Policy Settings via other components of PolicyPak Suite.

13. Deliver User-Side policy settings to Computers

in the box

Delivering User-Side policy settings to computers requires Loopback. This blocks normal processing, can lead to unexpected settings and longer login times when used.

With PolicyPak

You can apply any USER setting to the COMPUTER without any speed penalty. We offer “loopback without loopback.”

12. Keep GPPreferences working

in the box

If a User deletes shortcuts, VPN settings, etc, the computer goes offline, meaning you have a helpdesk call. There’s no way to automatically fix it without some kind of intervention.

With PolicyPak

If a User deletes shortcuts, VPN settings, etc, the computer goes offline, and then PolicyPak catches it and auto-fixes it. No intervention required, and minimised downtime

11. Change settings based upon conditions

in the box

Proxy setting and configuration files are static and un-changing. You can’t change them based on conditions.

With PolicyPak

Proxy settings and configuration files are flexible. You can change them or apply them based upon who / what / where a person or computer is.

10. Choice in delivery mechanism

in the box

You can deploy the following:

  • ADMX (in the box and add-in)
  • Group Policy Preferences
  • Group Policy Security settings

With PolicyPak

you can deploy :

  • ADMX (in the box and add-in)
  • Group Policy Preferences
  • Group Policy Security settings
  • Application settings

With any of your choice of delivery mechanisms:

  • Use Group Policy infrastructure or
    • SCCM
    • Altiris
    • Intune
    • Etc.
  • Or PolicyPak Cloud

9. Deliver settings to non-domain-joined machines

in the box

There’s no way to deliver settings “en masse” to non-domain / BYOD joined machines.

With PolicyPak

You can get true Group Policy as a Service thanks to our PolicyPak Cloud technology. This allows you to enable BYOD, for domain-joined and NON-domain joined machines.

You can use this to deliver:

  • Application settings
  • Microsoft Group Policy settings
  • Group Policy Preference settings
  • Group Policy Security settings

8. Ensure settings get delivered and un-delivered correctly

in the box

There’s the problem of ADM/ADMX tattooing. Here’s a video demo of the problem: https://www.policypak.com/video/group-policy-understanding-adm-admx-files-tattooing-and-what-to-do-about-it.html

With PolicyPak

There’s no tattooing, and your settings get properly reverted when required.

7. Deliver settings to real and virtualized applications

in the box

Virtualized apps cannot get Group Policy settings. That means there’s no support for:

  • App-V 4.6 or 5.0
  • ThinApp 4 or 5
  • Symantec SWV
  • Spoon.net

With PolicyPak

All these technologies are supported :

  • App-V 4.6 and 5.0 (and side-by-side)
  • ThinApp 4 and 5 (and side-by-side)
  • Symantec SWV
  • Spoon.net

Virtualized apps auto-remediate, lockdown, and properly revert.

6. Deliver settings dynamically to all systems

in the box

There’s no way to deliver Group Policy or application settings based upon what system type the user is on.

With PolicyPak

You can dynamically set settings in real-time, whether that’s:

  • Desktops
  • Laptops
  • VDI
  • RemoteApps
  • RDS/ Terminal Services / Citrix

5. Stop Annoying Pop-Ups

in the box

There’s no way to dynamically deliver settings to applications after they are deployed.

With PolicyPak

You can kill Pop-Ups dead.

4. Manage Firefox completely

in the box

There’s nothing in Group Policy, SCCM, Intune or Altiris to manage Firefox.

With PolicyPak

You can manage all the following Firefox settings:

  • Home page
  • Security
  • about:config settings
  • Block / Allow Pop-ups
  • Permissions: Camera, Mic, etc.
  • Add/Remove Bookmarks
  • Manage / Block Extensions
  • Add / Remove Certificates dynamically
  • Prevent Saving Passwords
  • Prevent Firefox Sync
  • And TONS more AND prevent user changes!

3. Manage Java completely

in the box

There’s nothing in Group Policy, SCCM, Intune or Altiris to manage Java.

With PolicyPak

You can do all of the following with Java:

  • Prevent Java from
    • updating
    • prompting about “Out of Date”
  • Disable Java completely if needed
  • Specify
    • Trusted Security Certs
    • Exception Site list
    • Security Levels
  • …And TONS more AND prevent user changes!

2. Manage Internet Explorer completely

in the box

With Group Policy ADMX settings are per IE version and always locked down. With Group Policy Preferences, settings can be worked around by the user. Settings for Internet Explorer Maintenance have been deprecated, while with Internet Explorer Admin Kit once more, the settings can be worked around by user.

With PolicyPak

Nearly every Internet Explorer setting is configurable. You can manage per user or per computer. We have an amazing IE 11 Compatibility Mode. Plus:

  • Install / Remove certificates
  • Set proxy and LAN settings dynamically
  • Flexibly Merge or Replace:
    • Favorites
    • Site to Zone assignment
    • Content Advisor sites
    • Per-site Privacy
  • Pop-Up Blocker

1. Manage nearly any application with PolicyPak DesignStudio

in the box

There are no tools to manage your commercial or home-grown applications.

With PolicyPak

You get PolicyPak DesignStudio, completely for free. This is the same utility we use in-house to provide the pre-created Paks. It allows you to create new Paks for your own applications, plus open and modify existing free pre-created Paks.

PolicyPak DesignStudio features a familiar interface, allowing you to create Paks for both internal applications and commercial applications.

Bonus: Free reporting on PolicyPak Settings

in the box

You can run GPMC “one by one” reports, but that’s it. There’s no definition of “compliance”: you have to interpret the reports yourself to work that out.

With PolicyPak

Group Policy Compliance Reporter gives you “All at once” reports, on unlimited computers simultaneously. It allows you to define what counts as compliance and gives you easy red/green reporting to see which machines are out of compliance at a glance.

Summary

PolicyPak + Group Policy, SCCM, Intune, or Altiris

PolicyPak doesn’t “compete” or “replace” what you have (Group Policy, SCCM, Intune, Altiris, etc.). Instead, PolicyPak manages application settings once software is deployed. PolicyPak increases your security by increasing your ability to manage security settings on your desktops, laptops, VDI, and RDS/ Citrix

PolicyPak + Group Policy, SCCM, Intune, or Altiris
  • Use your own system (SCCM, Intune, Altiris, etc)
    • to deploy application settings (Firefox, Java, Internet Explorer, etc.)
    • to deploy Group Policy settings (Group Policy, Group Policy Preference, Security)
  • PolicyPak Cloud delivers to non-domain joined (or domain joined) machines
  • PolicyPak includes free Group Policy Compliance Reporter for PolicyPak settings

Sign up for our webinar to find out more.