Preventing file downloads from SharePoint Web applications to non-compliant computers in IAG SP1 Update 2

Applies To: Intelligent Application Gateway (IAG)

This topic describes how you can use the application’s Download policy so that, unless the end user's computer meets the security policy requirements that you define, end users cannot do the following:

  • Download files.

  • Use the Edit in Datasheet option.

Users who are blocked are notified accordingly.

To prevent file download operations

  1. On the desktop of the computer running IAG, click Start, point to All Programs, point to Whale Communications IAG, and then click Configuration.

  2. If a password is required, enter it, and then click OK.

  3. In the Configuration console, on the Application Properties dialog box, click the General tab, and then click Edit Policies.

  4. On the Policies dialog box, under the Policies group box, select the SharePoint 2007 Download policy, and then click Edit.

  5. On the Advanced Policy Editor dialog box, you can either edit the policy in order to comply with your corporate policy, so that noncompliant computers (such as computers that don't run a firewall) are blocked, or you can change the policy value to False so that all endpoint computers are blocked.

    Note

    By default, the value of the policy is True, and it does not prevent download operations from endpoint computers.

    You edit policy components on the Advanced Policy Editor dialog box by doing one or more of the following:

    • In the Components list, click a component; a component can be either an existing expression or an existing variable. The selected component appears in the box on the right.

    • In the box, use VBScript-syntax free text in order to add or edit rules and rule components, as required; you can also delete rules and rule components in the box.

    Use the AND, OR, NOT, and parentheses operators in order to create a combination of as many components as you require.

    For more information, see "Endpoint Policies" in the Intelligent Application Gateway User Guide.

    Note

    You can use the Default Web Application Download policy as a basis for your definitions.

    On the Advanced Policy Editor dialog box, click OK, and then, on the Policies dialog box, click Close.

  6. On the Application Properties dialog box, on the General tab, in the Download list, click the SharePoint 2007 Download policy, click OK, and then in the Configuration console, click the Activate Configuration icon. The download operations described in this topic will be blocked, on the client side and on the server side, for endpoint computers that do not comply with the security policy that you define here.

    Note

    This procedure ensures full correlation of the SharePoint 2007 Download policy on both the client and server sides. If you want to cancel the policy, you must take the following steps in order to ensure that the same conditions apply to both the client and the server:

    • To cancel enforcement of the policy on the server side, on the Application Properties dialog box, on the General tab, select a Download policy other than SharePoint 2007 Download.

    • To cancel enforcement of the policy on the client side, redefine the value of the SharePoint 2007 Download policy as True.