gh5000 Posted January 14, 2020 Posted January 14, 2020 Hi guys, Can anyone see anything in the below GPO that would cause a Windows 10 install to mess up. Mess up = after a couple reboots after this GPO is enabled it doesn't get past the Windows Logo, spinny circle screen to get to the blue Please Wait page. When it gets to this point I can boot into safe mode ok, from there I have been able to disjoin from the domain and sometimes I'm back to square one. This GPO has been unmodified since Oct 2018. Before Christmas we preimaged some SSD's with 1903 and Dell drivers injected and when we came back in January the problem was present. I've since been able to recreate this problem on a completely blank image of 1809 and 1709 on the same computers (no drivers), and thinking it was a physical computer/driver issue I tried on a Hyper-V virtual machine but get the same problem - computer is fine for days with the GPO disabled, after a couple reboots with the GPO enabled it doesn't boot. The most confusing part for me is its been in place for a year with no problems when the school images a fat image with Acronis but not with a vanilla windows 7 image from DISM or MDT. Cheers Gavin
Sheridan Posted January 14, 2020 Posted January 14, 2020 Have you got a Deny for all executables in the Windows folder for students? I would have thought that would cause problems. We whitelist that folder and block specific executables within it. Same goes for Program Files folder as well.
mavhc Posted January 14, 2020 Posted January 14, 2020 I'm surprised anything works if you deny Windows and Program Files
tmoon-mint Posted January 14, 2020 Posted January 14, 2020 (edited) I dont see the default Applocker rules in there. For me I had to create the default Applocker rules and then deny the apps I didnt want my users to run. If I didnt put the default rules in the Start Menu didnt work. *Edit should probably mention you just right click in Applocker and "Create default rules". Edited January 14, 2020 by tmoon-mint 2
gh5000 Posted January 14, 2020 Author Posted January 14, 2020 I'm surprised anything works if you deny Windows and Program Files Yeah, I had been glossing over anything related to the students group as I wasn't logging on as them when the problem occurs. But your point remains about how this is applied to every other computer in the school and anything is working! For my own dignity I will say this policy was here before I started supporting the school! I just found worse - there is an applocker policy applied to the IT suites OU that has BUILTIN\Administrators DENY Executables to path .......wait for it..... * (All exe files on the computer)
gh5000 Posted January 14, 2020 Author Posted January 14, 2020 I dont see the default Applocker rules in there. For me I had to create the default Applocker rules and then deny the apps I didnt want my users to run. If I didnt put the default rules in the Start Menu didnt work. *Edit should probably mention you just right click in Applocker and "Create default rules". Thanks - as you'll see from my above comment the policy is well and truly borked. A reflection on the IT as a whole at the school unfortunately.
Sheridan Posted January 14, 2020 Posted January 14, 2020 Sounds like it might be worth building a brand new applocker policy, and setting it up with the defaults, and then whitelist what you want to allow.
NicholasEsping Posted January 14, 2020 Posted January 14, 2020 Unless the AppLocker policy is assigned to everything I would just image the computer in a different OU and them move it when done.
gh5000 Posted January 14, 2020 Author Posted January 14, 2020 Unless the AppLocker policy is assigned to everything I would just image the computer in a different OU and them move it when done. I had put these computers into a new OU with block inheritance on and then started the process of turning GPOs off and on. Annoying thing was working out that it happed after X reboots, not straight away. I just fear that changing the setting where it has been applied to many computers for at least a year, might fuck them up too. So anything I setup will be going in a new OU with a reasonable app locker GPO applied.
mrcrazy04 Posted January 16, 2020 Posted January 16, 2020 If you’re after a good starting point, NCSC has published some AppLocker rules as part of their Windows 10 End User Device Security Guidance. The guidance is aimed primarily at large government organisations with single user devices, so the rest of is less likely to be relevant. The AppLocker rules should provide a good starting point though, as the default rules can be bypassed. https://www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/eud-security-guidance-windows-10-1809#applockerconfig If you want to make sure nothing breaks, you can configure it in audit mode initially, and then check the event logs to see if any essential software is being blocked before enforcing the rules. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now