ITManLT Posted June 10, 2020 Posted June 10, 2020 Hello All, We're just about to try moving from the antiquated Software Restriction Policies to AppLocker to follow previous advise and best practice (we've had issues with SRP in the past so want to move away from it). Just after some advice/guidance and if anyone can send a screenshot of their basic config as a starting block that would be great. Also - do you apply 1 AppLocker GPO to all users, all computers (with it being a computer policy not user policy) - or do you just apply it to your Students / Staff groups etc? (currently using 1903 but working on a 1909 image to deploy soon if that makes any difference). Thanks for any advice.
TechMonkey Posted June 10, 2020 Posted June 10, 2020 We have a seperate GPO that is applied to all devices that contains the AppLocker rules. Stops any confusion. When you set them you can select the type then right click and it gives you the option to Automatically Generate Rules. This will give you the foundation and then add yours on top.
chazzy2501 Posted June 10, 2020 Posted June 10, 2020 Remember that to actually use Applocker you need to set a computer GPO to start the Application Identity service as it's disabled by default. ((why?)) appidsvc Oh and you have to configure the rule enforcement to actually enforce the rules you put in place. urrgh.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now