Jump to content

Recommended Posts

Posted

Hi All,

 

I'm at the stage of configuring AppLocker ready for our Windows 10 deployment. For everything up to and including Windows 7, we have used Software Restriction Policies, so this is my first experience with AppLocker.

 

I'm trying to get straight in my head the best way to do this. In this article (https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-allow-and-deny-actions-on-rules), Microsoft state that it isn't recommended to have the default allow rules in place, and then use a block rule to block certain files. My original plan was to use the default rules to allow all the executables in Windows and Program Files, and then block things like regedit etc that I don't want users to have access to. But it seems I shouldn't be doing this.

 

So what is everyone doing, and how is it working for you? It seems the recommended approach would be to use the collection tool to pick-up all of the executables in Windows and Program Files, creating individual whitelist rules for each - and then just deleting the rules for the programs you don't want to run. This seems a bit tedious - not to mention a pain to manage when windows updates and new Windows builds introduce new and replacement executables?

 

All input appreciated!

 

Thanks

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...