Sheridan Posted July 10, 2017 Posted July 10, 2017 Its been a couple of days since Windows 10 broke something, but this is a new one. Editing an applocker group policy, when you click the 'Select' button to define the users to which the rule will apply, it bombs out with the following really helpful error: Server stack trace: at Microsoft.ManagementConsole.Internal.SnapInMessagePumpProxy.OnThreadException(Object sender, ThreadExceptionEventArgs e) at System.Windows.Forms.Application.ThreadContext.OnThreadException(Exception t) at System.Windows.Forms.Control.WndProcException(Exception e) at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam) at System.Windows.Forms.UnsafeNativeMethods.DispatchMessageW(MSG& msg) at System.Windows.Forms.Application.ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(IntPtr dwComponentID, Int32 reason, Int32 pvLoopData) at System.Windows.Forms.Application.ThreadContext.RunMessageLoopInner(Int32 reason, ApplicationContext context) at System.Windows.Forms.Application.ThreadContext.RunMessageLoop(Int32 reason, ApplicationContext context) at System.Windows.Forms.Form.ShowDialog(IWin32Window owner) at Microsoft.Security.Srp.Ux.SrpUxRuleListView.CreateManualRule(RuleType ruleType) at Microsoft.ManagementConsole.View.DoAction(Int32 actionId, Boolean selectionDependent, Int32 selectionId, IRequestStatus requestStatus) at Microsoft.ManagementConsole.View.ProcessRequest(Request request) at Microsoft.ManagementConsole.ViewMessageClient.ProcessRequest(Request request) at System.Runtime.Remoting.Messaging.StackBuilderSink._PrivateProcessMessage(IntPtr md, Object[] args, Object server, Object[]& outArgs) at System.Runtime.Remoting.Messaging.StackBuilderSink.SyncProcessMessage(IMessage msg) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData& msgData, Int32 type) at Microsoft.ManagementConsole.Internal.IMessageClient.ProcessRequest(Request request) at Microsoft.ManagementConsole.Executive.RequestStatus.BeginRequest(IMessageClient messageClient, RequestInfo requestInfo) at Microsoft.ManagementConsole.Executive.SnapInRequestOperation.ProcessRequest() at Microsoft.ManagementConsole.Executive.Operation.OnThreadTransfer(SimpleOperationCallback callback) So don't update to 1703 if you're using applocker!
mullet_man Posted July 30, 2017 Posted July 30, 2017 I've just ran into this bug. Happens on Windows 2016 too. Does it still work if I edit the GPO using a 1607 machine?
computer_expert Posted July 30, 2017 Posted July 30, 2017 I had this editing an applocker GPO from server 2012 (not r2) machine. Worked fine editing from a 2012R2 machine though...
KibosJ Posted July 31, 2017 Posted July 31, 2017 I get this all of the time, such a pain to edit applocker now I get it on Server 2016 too.
mullet_man Posted July 31, 2017 Posted July 31, 2017 I get this all of the time, such a pain to edit applocker now I get it on Server 2016 too. Have you got it working at all? I might try a 2012r2 machine or 1607 one?
KibosJ Posted July 31, 2017 Posted July 31, 2017 Have you got it working at all? I might try a 2012r2 machine or 1607 one? Nope, for now I just have seperate Applocker policies with security filtering enabled.
skell Posted August 2, 2017 Posted August 2, 2017 Clear the cache in GPMC. close and reopen. Works for a while, then fails again. Complete PitA.
mullet_man Posted August 3, 2017 Posted August 3, 2017 Clear the cache in GPMC. close and reopen. Works for a while, then fails again. Complete PitA. Ah ok I’ll try that, just need to google how you do it as I’ve never done that before.
free780 Posted August 4, 2017 Posted August 4, 2017 Some people have resorted to powershell as a workaround.
skell Posted August 4, 2017 Posted August 4, 2017 @mullet_man In GPMC File > Options Delete Files Also, updating to the latest insider build seems to fix it.
Arthur Posted August 8, 2017 Posted August 8, 2017 Editing an applocker group policy, when you click the 'Select' button to define the users to which the rule will apply, it bombs out Fixed in the latest CU. https://support.microsoft.com/en-us/help/4034674/windows-10-update-kb4034674 This update includes quality improvements. No new operating system features are being introduced in this update. Key changes include: Addressed issue where the policies provisioned using Mobile Device Management (MDM) should take precedence over policies set by provisioning packages. Addressed issue where the Site to Zone Assignment List group policy (GPO) was not set on machines when it was enabled. Addressed issue where the AppLocker rules wizard crashes when selecting accounts. Addressed issue where the primary computer relationship is not determined when you have a disjoint NetBIOS domain name for your DNS Name. This prevents folder redirection and roaming profiles from successfully blocking your profile or redirects folders to a non-primary computer. Addressed issue where an access violation in the Mobile Device Manager Enterprise feature causes stop errors. Security updates to Microsoft Edge, Microsoft Windows Search Component, Microsoft Scripting Engine, Microsoft Windows PDF Library, Windows Hyper-V, Windows Server, Windows kernel-mode drivers, Windows Subsystem for Linux, Windows shell, Common Log File System Driver, Internet Explorer, and the Microsoft JET Database Engine. 1
Sheridan Posted September 7, 2017 Author Posted September 7, 2017 This was still happening for me on both 10 and 2016 despite the latest CU being installed as above. But oddly it hasn't done it this week!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now