Jump to content

Recommended Posts

Posted

I've created an AppLocker Computer Policy which only allows software to run from certain drives.

 

In the Delegation Tab of Group Policy Management I've set a DENY policy for Domain Admins.

 

But if I log on to the PC as the local administrator the policy still applies.

 

I presume there is a way around this....

Posted

Seriously think I'm going to go back so Software Restriction Policies!

 

And then work out other methods to block the Apps I don't want the students to run!

Posted

Are you running the programs as admin? (UAC wise) if not it'll still hit the "normal" part of the admin account.

 

But on a side note doesn't deny always override allow in applocker? So not sure your local admin way would work anyway

 

Steve

Posted
Are you running the programs as admin? (UAC wise) if not it'll still hit the "normal" part of the admin account.

 

But on a side note doesn't deny always override allow in applocker? So not sure your local admin way would work anyway

 

Steve

 

The DENY was on the "Apply Policy" part of the GPO.

 

I thought this would stop it applying - but unsure, because it's applying to the COMPUTER OU....how does it then not apply if it's DENYing Domain Admins when it does n't know who is logged on yet...My understanding of functionality here may not be up to speed.

Posted
Noooooooooooooooooo!!! Don't do that! :)

 

 

There isn't any need to do that. Get rid of the Deny, then check the following PDF for details on how to setup AppLocker correctly.

 

Application Whitelisting Using Microsoft AppLocker (Alt. Link)

 

Thanks I will have a read.

 

But before I do...

 

Is it possible to create an Applocker policy on the computer OU that does not apply if a domain admin logs on OR does the policy always apply and it's at the applocker level that it knows not to adhere to the restrictions if a domain admin or local administratorl logs in?

Posted
Thanks I will have a read.

 

But before I do...

 

Is it possible to create an Applocker policy on the computer OU that does not apply if a domain admin logs on OR does the policy always apply and it's at the applocker level that it knows not to adhere to the restrictions if a domain admin or local administratorl logs in?

 

By default Applocker affects all users including Admins, I created an 'Applocker all' group and added my staff and pupil groups into that, then I set the permissions with the applocker policy to only apply to 'applocker all' so admins are unaffected.

Posted
By default Applocker affects all users including Admins, I created an 'Applocker all' group and added my staff and pupil groups into that, then I set the permissions with the applocker policy to only apply to 'applocker all' so admins are unaffected.

 

Hi,

 

I don't quite understand - I thought if you created "whitelist" rules then by default everything else was blocked.

 

So if you have created an

 

"Allow : Applocker Group : Name of Rule : Path" policy

 

which white lists which areas of your network/local PC that you want them to be able to run programs from, then won't by default all other locations and groups be disallowed from running programs from every other location?

Posted
Hi,

 

I don't quite understand - I thought if you created "whitelist" rules then by default everything else was blocked.

 

So if you have created an

 

"Allow : Applocker Group : Name of Rule : Path" policy

 

which white lists which areas of your network/local PC that you want them to be able to run programs from, then won't by default all other locations and groups be disallowed from running programs from every other location?

 

So what have you got in here?

Applocker Permis.JPG

Posted
If I attempt to create new executable rule then I get the exact same dialogue box as you.

 

So, I change everyone to my 'applocker all' group, as this group only contains staff and pupils, it only affects them and not admins. If you leave that as everyone it will affect everyone including admins, does that make sense?

Posted
So, I change everyone to my 'applocker all' group, as this group only contains staff and pupils, it only affects them and not admins. If you leave that as everyone it will affect everyone including admins, does that make sense?

 

I think I get the logic now...

 

I'll give it one more chance ;)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...