Jump to content

Recommended Posts

Posted

Morning.

 

For some reason when I enable applocker on some particular computers I can't get to the logon screen. I only had it set for audit initially and it did it once on bootup but a hard reboot solved it. Now I've enable just the exe rule as enforce and its spins around then goes to a black screen and flashes for a second over and over again.

 

Can someone post what their rules look like so I can compare. I was hoping the default rules would let me log on but as soon as they are enabled my computers die.

 

PS. Its DWN.exe that its saying is blocked. I've tried allowing this with a path and hash rule but its still not working.. or maybe the policy isnt refreshing as I am locked out. I can still get to the event logs on the remote comptuers.

Posted

Have you got the default rules in Applocker?

 

Allow Everyone All files located in the Windows Folder

Allow Everyone All Files located in the Program Files folder

Posted

Yep, when its set to audit I can see its blocking loads even withthe default rules in place.

 

%SYSTEM32%\NET1.EXE was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

 

%PROGRAMFILES%\REALTEK\AUDIO\HDA\RAVBG64.EXE was allowed to run but would have been prevented from running if the AppLocker policy were enforced.

 

When I enforce the rule I cant log on

 

%SYSTEM32%\DWM.EXE was prevented from running.

Posted

Tried on a different client without ABTutor.

 

Just so I am not being simples... I've created a policy to enable the App identity service and one with the rules on it all linkied the the computers OU.. sound right?

 

Its almost like the computer is starting the APPLOCKER service before any rules are enabled and it wont refresh them as they are blocked.

 

Might try sticking a local policy on with the defautl rules and testing.

  • 6 years later...
Posted

I had the same issue, had an AppLocker policy to allow %SYSTEM32%/DWM.EXE for Admins group, but DWM.EXE was still being blocked when trying to RDP!

 

Weirdly enough, changing from Admins group to "Everyone" seemed to help. I'm not sure why as my user is definitely a part of the Admins group, maybe it had something to do with the order of operations on logging in via RDP? Like DWM.EXE is called before Windows recognizes the user as part of a specific group? I don't know..

Posted
I had the same issue, had an AppLocker policy to allow %SYSTEM32%/DWM.EXE for Admins group, but DWM.EXE was still being blocked when trying to RDP!

 

I’ll bite. Why on earth would you want to restrict who can execute dwm? (Which is what an explicit/specific allow for admin rule implies)

 

Also I think dwm might be one of those processes that in some circumstances is started by the system before changing its context to the current user, which (if I am right) would be why it didn’t work - logon via RDP can make things weirder than usual.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...