smarties11 Posted May 18, 2018 Posted May 18, 2018 Hi All, I'm at the stage of configuring AppLocker ready for our Windows 10 deployment. For everything up to and including Windows 7, we have used Software Restriction Policies, so this is my first experience with AppLocker. I'm trying to get straight in my head the best way to do this. In this article (https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-allow-and-deny-actions-on-rules), Microsoft state that it isn't recommended to have the default allow rules in place, and then use a block rule to block certain files. My original plan was to use the default rules to allow all the executables in Windows and Program Files, and then block things like regedit etc that I don't want users to have access to. But it seems I shouldn't be doing this. So what is everyone doing, and how is it working for you? It seems the recommended approach would be to use the collection tool to pick-up all of the executables in Windows and Program Files, creating individual whitelist rules for each - and then just deleting the rules for the programs you don't want to run. This seems a bit tedious - not to mention a pain to manage when windows updates and new Windows builds introduce new and replacement executables? All input appreciated! Thanks
Steve21 Posted May 18, 2018 Posted May 18, 2018 Lazy mode saves re-writing -> http://www.edugeek.net/forums/windows-10/195403-applocker-post-your-policies.html#post1670704 Combined with the standard allow programfiles etc Steve 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now