Jump to content

Recommended Posts

Posted

Anyone finding Applocker rather unreliable in 10?

 

For example, the Edu version of 10 comes with Skype Preview (of course, why wouldn't you want that with Edu!) and the dism commands to remove it leave it on the menu.

 

So, I thought I'll just stop it running, when they start it it create the processes SkypeApp.exe and SkypeHost.exe - both of these are blocked in Applocker but still run.

 

Looking at the Applocker logs, it says the Microsoft.SkypeApp was allowed to run - so whats the point of having executable rules if it ignore them?

 

Of course, I can't add the packaged app in Applocker as GPMC crashes when you browse the list - same bug from 1607 but I would have thought the executable rule will work anyway!

Posted (edited)

Basically we have SkypeApp.exe and SkypeHost.exe as Blocked for Everyone (doesn't need to be everyone, but I was trying all ways!) in the Executable Rules.

 

As the Program Files folder has a default rule to allow, I also added both of those as Exceptions to that rule.

 

SRP was so reliable, applocker seems to be so variable I'm losing faith in it.

 

Checking the logs, it shows 'MICROSOFT.SKYPEAPP was allowed to run.' in the Packaged-App Execution log, and I can't put a rule in for those as MMC crashes out.

 

Does a Packaged App rule overrule a Executable rule I wonder?

Edited by Sheridan
Posted

LOL - Applocker just ignores what I put in!

 

It logs 'The AppLocker policy was applied successfully to this computer.' in which Skype is blocked as an executable, a packaged app and an exception to the allow rules and it still runs

 

Maybe your'e right, Microsoft ignore their own rules....

Posted
I'll dump the gpo when I'm back in the office - we do have a default allow rule for packaged apps - but then specifically deny the ones we don't use/need.
Posted

Microsoft.Skypeapp is not Skypeapp.exe and Skypehost.exe. Those are "Classic Desktop" applications, not Universal Windows Platform "apps".

 

Create a Packaged App Rule to deny "Skype - Microsoft.Skypeapp". It's separate from Executable rules but still found under AppLocker in Group Policy. I have several deny policies for social and gaming UWP apps located there, all working fine.

Posted
Microsoft.Skypeapp is not Skypeapp.exe and Skypehost.exe. Those are "Classic Desktop" applications, not Universal Windows Platform "apps".

 

Create a Packaged App Rule to deny "Skype - Microsoft.Skypeapp". It's separate from Executable rules but still found under AppLocker in Group Policy. I have several deny policies for social and gaming UWP apps located there, all working fine.

 

I've done both methods, executable and Packaged app rules. The skypeapp.exe and skypehost.exe run when you open the App (visible when checking the task list) so I thought at least one method would stop it from running!

Posted

And it also happens when trying to whitelist webex components - the path "%OSDRIVE%\PROGRAMDATA\WEBEX\*" is whitelisted for Everyone, but the event viewer logs the error "%OSDRIVE%\PROGRAMDATA\WEBEX\WEBEX\T31_TC\ATMGR.EXE was prevented from running" which contradicts itself!

 

I think I'll remove applocker and leave SRP on instead, that seems to work consistently.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...