# ActiveX Qs for corporate network admins

**URL:** <https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662>\
**Category:** Factual Questions\
**Created:** [April 10, 2005, 2:19pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662 "2005-04-10T14:19:59Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![puggyfish](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@puggyfish](https://boards.straightdope.com/u/puggyfish)\
**Post date:** [April 10, 2005, 2:19pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/1 "2005-04-10T14:19:59Z")

</div>

A company is rewriting a piece of business software as a web application for clients lacking the server capabilities to host the current version. The web version would use an ActiveX control. They have informally talked to me about the project and are asking about typical Internet Explorer security policies on corporate networks. If the Internet security setting is High or customised to block them, ActiveX controls will pose problems. Medium is OK as the control is signed.

Would any of you corporate net admins care to say what level you set IE security to on users’ computers? Do you let users modify these settings?  
Thanks

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [April 10, 2005, 2:43pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/2 "2005-04-10T14:43:56Z")

</div>

Never mind settings on Internet Explorer, ActiveX controls (and Java) are flat-out blocked by our firewall.

---

<div class="post-metadata">

**Author:** ![SkipMagic](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skipmagic/32/20706_2.png) [@SkipMagic](https://boards.straightdope.com/u/SkipMagic)\
**Post date:** [April 10, 2005, 3:15pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/3 "2005-04-10T15:15:26Z")

</div>

We have it set on “High” and we enforce that through Group Policy, so general users cannot change that setting.

---

<div class="post-metadata">

**Author:** ![DarrenS](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DarrenS](https://boards.straightdope.com/u/DarrenS)\
**Post date:** [April 10, 2005, 5:58pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/4 "2005-04-10T17:58:37Z")

</div>

Bear in mind too that if the users are not running as “admin” they won’t be able to install Active-X controls. This is rarely an issue, though, as, unfortunately, most users habitually run as “admin”.

---

<div class="post-metadata">

**Author:** ![ouryL](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ouryl/32/6067_2.png) [@ouryL](https://boards.straightdope.com/u/ouryL)\
**Post date:** [April 10, 2005, 8:41pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/5 "2005-04-10T20:41:35Z")

</div>

In school, admin permissions were a pain at the computer labs. Only one set of computers could run the programs we wrote. :smack:

---

<div class="post-metadata">

**Author:** ![puggyfish](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@puggyfish](https://boards.straightdope.com/u/puggyfish)\
**Post date:** [April 11, 2005, 11:39am UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/6 "2005-04-11T11:39:13Z")

</div>

Thanks for that. So, with most of you tending to block ActiveX controls by default, do you have any procedure to let users run them if necessarily, or is it just tough luck?

---

<div class="post-metadata">

**Author:** ![puggyfish](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@puggyfish](https://boards.straightdope.com/u/puggyfish)\
**Post date:** [April 11, 2005, 11:39am UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/7 "2005-04-11T11:39:24Z")

</div>

Thanks for that. So, with most of you tending to block ActiveX controls by default, do you have any procedure to let users run them if necessary, or is it just tough luck?

---

<div class="post-metadata">

**Author:** ![dasgupta](https://avatars.discourse-cdn.com/v4/letter/d/e56c9b/32.png) [@dasgupta](https://boards.straightdope.com/u/dasgupta)\
**Post date:** [April 11, 2005, 1:21pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/8 "2005-04-11T13:21:00Z")

</div>

> [@puggyfish](#):
>
> Thanks for that. So, with most of you tending to block ActiveX controls by default, do you have any procedure to let users run them if necessary, or is it just tough luck?

We too block users from installing ActiveX stuff, but if it’s deemed important by the execs, I’ll install it for them.

This is generally limited to a few bank/payroll websites that our accounting department uses (or anything the execs want).

---

<div class="post-metadata">

**Author:** ![puggyfish](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@puggyfish](https://boards.straightdope.com/u/puggyfish)\
**Post date:** [April 11, 2005, 5:54pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/9 "2005-04-11T17:54:21Z")

</div>

> [@dasgupta](#):
>
> We too block users from installing ActiveX stuff, but if it’s deemed important by the execs, I’ll install it for them.
> 
> This is generally limited to a few bank/payroll websites that our accounting department uses (or anything the execs want).

How would you go about allowing a particular control to be run?

One idea we were thinking of was to ask admins to add the relevant server to Internet Explorer’s list of trusted sites. Is that the sort of thing that would be convenient to do for multiple computers on the network?

---

<div class="post-metadata">

**Author:** ![FatBaldGuy](https://avatars.discourse-cdn.com/v4/letter/f/ecd19e/32.png) [@FatBaldGuy](https://boards.straightdope.com/u/FatBaldGuy)\
**Post date:** [April 11, 2005, 9:09pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/10 "2005-04-11T21:09:41Z")

</div>

**Puggyfish** , are you talking about running this application over the **inter** net or on a company **intra** net (behind a firewall)? The answer to this may well influence the IT bigwigs in their decision.

---

<div class="post-metadata">

**Author:** ![puggyfish](https://avatars.discourse-cdn.com/v4/letter/p/3ab097/32.png) [@puggyfish](https://boards.straightdope.com/u/puggyfish)\
**Post date:** [April 12, 2005, 10:05am UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/11 "2005-04-12T10:05:34Z")

</div>

Primarily this question is about an **inter** net version. The existing version is an **intra** net version as such, although it may be rewritten to share more components with the internet version and may need to consider similar problems.

As you say, this difference affects security issues, but the problems are expected to be smaller with the intranet version. Hence, this thread is looking to tackle the difficult version first.

So, has anyone got any standard procedures for allowing ActiveX controls to be run from the Internet on their corporate network?

---

<div class="post-metadata">

**Author:** ![Quartz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/quartz/32/267_2.png) [@Quartz](https://boards.straightdope.com/u/Quartz)\
**Post date:** [April 12, 2005, 6:04pm UTC](https://boards.straightdope.com/t/activex-qs-for-corporate-network-admins/298662/12 "2005-04-12T18:04:26Z")

</div>

> [@puggyfish](#):
>
> How would you go about allowing a particular control to be run?
> 
> One idea we were thinking of was to ask admins to add the relevant server to Internet Explorer’s list of trusted sites. Is that the sort of thing that would be convenient to do for multiple computers on the network?

Not in my case, because the control is blocked at the firewall. If it had to be managed on a per-computer basis, it would be a nightmare.

Umm… You do have a firewall, don’t you?

Invest in a decent firewall and proxy server that will take care of this for you.
