gaz350b Posted June 13, 2017 Posted June 13, 2017 (edited) We find that machines that update as part of our imaging process do not get effected from modern apps curruption. Which causes start menu failure as it is also a modern app. We had a small issue where we imaged 90 machines when our update service was broken and 70% of these machines because corrupt once hey recived updates. My theory is that this corruption only happens after modern apps have been removed (we do this at the end of the image process) once updated. has anyone had this Morden App/start menu corruption on machines where they have NOT removed any modern apps????? We have also found out that removing modern apps also breaks Applocker policy creation. Edited June 13, 2017 by gaz350b
ADMaster Posted June 14, 2017 Posted June 14, 2017 Just subscribing to keep an eye on this. I had an applocker issue where removing the apps with ntlite before imageing broke applocker. I remove modern apps with a script during OSD near the end of the process. Can you explain more about cannot create applocker policies, don't they get pulled from GPO? I don't think I've tried to edit my applocker GPO since updating. Is the issue only on 1703 or what version?
Squelch Posted June 14, 2017 Posted June 14, 2017 We had the corruption both with and without modern apps. At first we removed them during the build process and then we stopped doing that and just disabled them with software restrictions in a GPO. Since building to 1703 I have not yet seen a broken start menu, it's too soon to say if 1703 fixes the issue or not but so far so good.
gaz350b Posted June 14, 2017 Author Posted June 14, 2017 (edited) Can you explain more about cannot create applocker policies, don't they get pulled from GPO? I don't think I've tried to edit my applocker GPO since updating. Is the issue only on 1703 or what version? We were unable to create/update GPO using the admin tools on machines where the modern apps were removed as the wizard that you use crashes. we can confirm this is an issue on both 1607 and 1703 when modern apps are removed (on the machine where you are managing the Group policy). I'm not sure if this also effects the application of these policies to machines themselves. We hadn't got that far as we are still using SRP. Edited June 14, 2017 by gaz350b
ADMaster Posted June 14, 2017 Posted June 14, 2017 We were unable to create/update GPO using the admin tools on machines where the modern apps were removed as the wizard that you use crashes. we can confirm this is an issue on both 1607 and 1703 when modern apps are removed (on the machine where you are managing the Group policy). I'm not sure if this also effects the application of these policies to machines themselves. We hadn't got that far as we are still using SRP. I saw a similar thread to this when researching my own applocker issue, but mixed results. Do you have the latest updates installed? I have May's installed build 10.0.15063.332. I've not had any reason to update my applocker policy yet, so I created a new test gpo. I was able to add rules to it just fine, no crashes, I tried exe publisher rule and packaged app. I have most modern apps removed via script during osd.
ADMaster Posted June 15, 2017 Posted June 15, 2017 I spoke to soon on this. Creating a rule for everyone works fine. However when I attempt to select a group it crashes. The quick fix for me was to RDP into the DC still running 2012 r2 and update the policy. Hopefully this will be fixed soon.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now