Jump to content

Recommended Posts

Posted

Hi guys,

 

Can anyone see anything in the below GPO that would cause a Windows 10 install to mess up. Mess up = after a couple reboots after this GPO is enabled it doesn't get past the Windows Logo, spinny circle screen to get to the blue Please Wait page. When it gets to this point I can boot into safe mode ok, from there I have been able to disjoin from the domain and sometimes I'm back to square one.

 

This GPO has been unmodified since Oct 2018. Before Christmas we preimaged some SSD's with 1903 and Dell drivers injected and when we came back in January the problem was present. I've since been able to recreate this problem on a completely blank image of 1809 and 1709 on the same computers (no drivers), and thinking it was a physical computer/driver issue I tried on a Hyper-V virtual machine but get the same problem - computer is fine for days with the GPO disabled, after a couple reboots with the GPO enabled it doesn't boot.

 

The most confusing part for me is its been in place for a year with no problems when the school images a fat image with Acronis but not with a vanilla windows 7 image from DISM or MDT.

 

Annotation 2020-01-14 110941.png

 

Cheers

Gavin

Posted

Have you got a Deny for all executables in the Windows folder for students? I would have thought that would cause problems. We whitelist that folder and block specific executables within it.

 

Same goes for Program Files folder as well.

Posted (edited)

I dont see the default Applocker rules in there. For me I had to create the default Applocker rules and then deny the apps I didnt want my users to run. If I didnt put the default rules in the Start Menu didnt work.

 

*Edit should probably mention you just right click in Applocker and "Create default rules".

Edited by tmoon-mint
  • Thanks 2
Posted
I'm surprised anything works if you deny Windows and Program Files

 

Yeah, I had been glossing over anything related to the students group as I wasn't logging on as them when the problem occurs. But your point remains about how this is applied to every other computer in the school and anything is working! For my own dignity I will say this policy was here before I started supporting the school!

 

I just found worse - there is an applocker policy applied to the IT suites OU that has BUILTIN\Administrators DENY Executables to path .......wait for it..... * (All exe files on the computer)

Posted
I dont see the default Applocker rules in there. For me I had to create the default Applocker rules and then deny the apps I didnt want my users to run. If I didnt put the default rules in the Start Menu didnt work.

 

*Edit should probably mention you just right click in Applocker and "Create default rules".

 

Thanks - as you'll see from my above comment the policy is well and truly borked. A reflection on the IT as a whole at the school unfortunately.

Posted
Unless the AppLocker policy is assigned to everything I would just image the computer in a different OU and them move it when done.

 

I had put these computers into a new OU with block inheritance on and then started the process of turning GPOs off and on. Annoying thing was working out that it happed after X reboots, not straight away.

 

I just fear that changing the setting where it has been applied to many computers for at least a year, might fuck them up too. So anything I setup will be going in a new OU with a reasonable app locker GPO applied.

Posted

If you’re after a good starting point, NCSC has published some AppLocker rules as part of their Windows 10 End User Device Security Guidance. The guidance is aimed primarily at large government organisations with single user devices, so the rest of is less likely to be relevant. The AppLocker rules should provide a good starting point though, as the default rules can be bypassed.

 

https://www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/eud-security-guidance-windows-10-1809#applockerconfig

 

If you want to make sure nothing breaks, you can configure it in audit mode initially, and then check the event logs to see if any essential software is being blocked before enforcing the rules.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...