Apply protection rules

Prev Next

You can define protection rules when changing or creating a protection policy or rule group.

Task

  1. Select MenuPolicyPolicy Catalog.
  2. Select Solidcore 8.x.x: Change Control for the product.
    You can create a policy or duplicate an existing one.
  3. Read-protect files and directories.
    1. Select a policy from the list, then click Add on the Read-Protect tab. The Add File dialog box appears.
    2. Specify the file or directory name and indicate whether to include or exclude from read protection.
    3. Click OK.
  4. Write-protect files and directories.
    1. Select a policy from the list, then click Add on the Write-Protect File tab. The Add File dialog box appears.
    2. Specify the file or directory name and indicate whether to include or exclude from write protection.
    3. Click OK.
  5. Specify trusted programs permitted to override the read and write protection rules.
    1. Click Add on the Updater Processes tab. The Add Updater dialog box appears.
    2. Enter the location of the file.
    3. Enter a unique identification label for the executable file.
    4. Specify conditions that the file must meet to run as an updater:
      • Select None to allow the file to run as an updater without any conditions.
      • Select Parent to allow the file to run as an updater only if it is started by the specified parent.
    5. Indicate whether to disable inheritance for the updater. For example, if Process A (that is set as an updater) starts Process B, disabling inheritance for Process A makes sure that Process B doesn't become an updater.
    6. Indicate whether to suppress events generated for the actions performed by the updater. Typically, when an updater changes a protected file, a File Modified event is generated for the file. If you select this option, no events are generated for changes made by the updater.
    7. Click OK.