Configuring Foldr Apps from the Server – App Profiles

The Foldr server is able to apply specific client settings to client apps on a per user/group basis using App Profiles.  App Profiles are available for both Windows and macOS Foldr apps.

When using App Profiles, it is important to consider that the server always ‘wins’ – Any configuration specified on the server will override local settings on the client.

App Profiles could be useful if you needed to apply a specific change to the app for an individual or a group of users, without having to redeploy the client app or push out other client settings to the registry via Group Policy or script.

Windows configurable options

See this KB for specific information around each option

App Profile
Value Client Registry key equivalent
config.av.required 1 or 0 RequiresAntivirus
config.av.grace 1 or 0 AVGraceMinutes
config.av.update_grace 1 or 0 AVUpdateGraceMinutes
config.bitlocker.required 1 or 0 N/A
config.drive_type_removable 1 or 0 DriveTypeRemovable
config.process_filtering.enabled 1 or 0 N/A server-side only
config.process_filtering.mode 1 or 0 1 = blacklist mode
0 = whitelist mode
config.process_filtering.processes enter process names, one per line N/A server-side only
config.ransomware.rename_checking.required 1 or 0 DetectRenameThreat
config.ransomware.extension_checking.required 1 or 0 DetectExtensionsThreat

macOS configurable options

See this KB for specific information around each option

App Profile Setting
Value Client Registry key equivalent
config.gatekeeper.required 1 or 0 GATEKEEPER_REQUIRED
config.filevault.required 1 or 0 FILEVAULT_REQUIRED
config.ransomware.rename_checking.required 1 or 0 DETECT_RENAME_THREAT
config.ransomware.extension_checking.required 1 or 0 DETECT_EXTENSIONS_THREAT
config.process_filtering.enabled 1 or 0 N/A server-side only
config.process_filtering.enabled 1 or 0 N/A server-side only
config.process_filtering.mode 1 or 0 1 = blacklist mode
0 = whitelist mode
config.process_filtering.processes enter process names, one per line N/A server-side only
config.scripts.mount script as required N/A server-side only
config.scripts.unmount script as required N/A server-side only

Configuring App Profiles

An App Profile can be created and configured as required and then applied to either everyone or specific users or groups.

In the following example we will create an App Profile for the Marketing department and enforce the client to be using BitLocker encryption and enforce a process filter in blacklist mode so only Windows Explorer, Word and Excel can interact with the drive.  You can specify options for both Windows and macOS in the same profile if required.

To create the App Profile navigate to Foldr Settings > Devices & Clients tab > App Profiles.

Click +Add New

Give the profile a suitable name and configure as required.

Next, click the Users & Groups tab

Search for the group or user that you wish to apply the profile.  Multiple users or groups may be selected as required.

The profile can optionally be applied to clients based on their location using the ‘On these IPs and subnets‘ field.  IP addresses, subnets or network ranges can be specified here, otherwise the profile will apply to all locations.  For more information regarding location based permissions and the syntax to configure network addresses, see the following KB article

Need more help?

Get in touch and we'll be happy to assist you, [email protected]

© Minnow IT. Registered in England and Wales with company number 07970411.

Made with in Bristol, UK

<