Jump to content

Recommended Posts

Posted

Hi all,

 

I took over at a UTC a while back and havent had to do much to applocker. But now I am getting requests to install new software, one of which I am having issues with. So I wanted to disable applocker temporarily to test something and the start menu on the school PCs stop working. Re-enabling applocker makes the start menu work again??

 

Any ideas??

 

Cheers

Posted
you might find there is another applocker policy further up the ou tree. last applied wins with GPO's and so by disabling it the one further up kicks in possibly?
  • Thanks 1
Posted
Those two apps are a core part of the whole new start menu\tiles\search UI. Did you disable the policy link or just delete all the entries in the application control policy section?
  • Thanks 1
Posted
Those two apps are a core part of the whole new start menu\tiles\search UI. Did you disable the policy link or just delete all the entries in the application control policy section?

 

I just disabled the policy link. I have been going through the GPOs but cannot find another applocker policy. *Headache*

Posted
Have a look also for a software restriction policy. Similar concept to applocker but configured elsewhere in Group Policy: it's in Computer/User Configuration > Policies > Windows Settings > Security Settings > Software Restriction Policies.
  • Thanks 1
Posted
Does the policy whitelist the startmenu or blacklist it? The policy could be one of two or more, a default block somewhere and this policy whitelisting/ enabling the start menu
  • Thanks 1
Posted
We found that disabling cortana broke the start menu, so there must be a part of the applocker policy blocking it, or a a part whitelisting it that is now disabled. Have you created creating a default new applocker policy and applying that? That just allows Windows programs etc.
  • Thanks 1
Posted

Hi all,

 

Thanks for the advice I created a new applocker policy, added the defaults and used one or two entries from the old one that made sense the rest i scrapped. All seems to working as it should and even a couple of programs that wouldn't work are working now. So all good. Many thanks for your help.

  • 5 weeks later...
Posted

Sorry to bump a resolved thread. I have decided to look into the Applocker policy today as it looks like it would solve a few issues we have here. After generating the default allow rules, any deny policy I create (Publisher, File Hash or Path) either 1. doesn't work, 2. breaks the start menu so it doesn't open or 3. works and blocks the app and also breaks the start menu.

 

After further investigation I found that without any deny rules that I create, the default allow settings that are generated are breaking the start menu as well, i'm hoping by posting here someone may have an idea for me, Google is getting me nowhere.

 

We are running Windows 10 LTSB 2016 Enterprise on the workstations.

Posted
Have you checked the applocker section in event viewer. The default rules enable all uwp apps that are signed. Roaming Profiles can also break the start menu in 1607 which is the same as LTSC.
Posted
Managed to solve it at the end of the day yesterday. It turned out that the issue I was having was occurring because I hadn't generated default allow rules for all 4 sections (executables, installers, scripts and packaged apps). Only creating default allow rules for executables was causing the start menu issues among other issues, but it is working now which I am very pleased about.
  • 1 month later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...