Jump to content

Recommended Posts

Posted

Hi,

 

Well Software Restriction Policy (SRP) is deprecated since windows 10.

When we try to use AppLocker we get the blue pop-ups to say software has been blocked (but the only way to see what software is in the Event Log), and there's no way to hide this.

 

We've found it's unusable for exam accounts, because there's so much that is blocked.  We didn't have this issue with SRP, because it did it all silently.

 

What are other people using to block software in Windows 11 ?

Posted

AppLocker is great once you have it up and running, I would recommend it. We ditched SRP completely once we had AppLocker configured right.

 

Run it in audit mode & collect what you need to allow that is being blocked. Then test with dummy computers/user accounts

 

You can allow by publisher to allow all the Microsoft windows & Microsoft corporation apps (appx, windows store apps), then explicitly Deny what you want to block.

 

More and more things in Windows 11 are moving to appx (store) apps, even some drivers are pulled from the store now.

 

 

Posted (edited)

I've had a few problems with Applocker so far:

 

1.  I want to block silently, like SRP did.  But there doesn't seem to be any way to do this.

2.  I try to sign things from Microsoft as Allowed, but I still get onedrive FileSyncConfig/FileCoauth blocked.  

3.  Update software runs as current user, from the AppData. Autodesk, Onedrive, Chrome

 

The reason I switched from SRP is because it's deprecated, and isn't supposed to work on Windows 11.

 

I think we're going back to SRP, until we can get all the fixes.  But if it stops working for 25H2, I wouldn't be surprised.

Edited by User3204
Posted
16 hours ago, User3204 said:

I've had a few problems with Applocker so far:

 

1.  I want to block silently, like SRP did.  But there doesn't seem to be any way to do this.

2.  I try to sign things from Microsoft as Allowed, but I still get onedrive FileSyncConfig/FileCoauth blocked.  

3.  Update software runs as current user, from the AppData. Autodesk, Onedrive, Chrome

 

The reason I switched from SRP is because it's deprecated, and isn't supposed to work on Windows 11.

 

I think we're going back to SRP, until we can get all the fixes.  But if it stops working for 25H2, I wouldn't be surprised.

We explicitly allow these executables to run, seems to do the trick for onedrive.

image.png.5349c25a5059a74a4385f674f2da473a.png

 

image.png.13c6b0225bb6b634bfa2c805f6948fb5.png

 

Ideally you need to run in audit mode & collect logs to see what is being blocked.

 

 

 

Posted

The one that tripped me up when setting up AppLocker is getting the rules generated automatically adds the version currently installed on the device. For example, if I have Chrome version 138.0.7204.97, then it will pick that as the lowest version to allow. If that's the latest version then any machine that isn't bang up-to-date as of implementing the policy will have that application blocked. I got around this by removing the version (asterisk in the file version field, as pictured above) fixed most of the initial issues I was having.

Posted

I'd say blocking silently is an issue as the user, and then the tech, have no clue why an application is not working.  Can't remember the number of times trying to make something work and then remembering to check AppLocker logs and find it was that, especially if it isn't the main app.  Makes sense to have something that tells the user that this will not work and to not bother.

  • Like 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...