Jump to content

Recommended Posts

Posted

In a similar vein to this thread: http://www.edugeek.net/forums/windows-10/190996-cheeky-request-stealing-gpos.html I was wondering if anyone was using Applocker and was willing to share their policies?

 

At the moment, I just have the default rules in place which allow programs in Program Files, Program Files (x86) and %windir% to run but I was wondering if there were any gotchas or outliers which need putting too? I'd be very interested to see what people are doing.

 

TIA

Posted

Mine's very bare as we're still playing but a few other bits we added in.

 

So packaged apps -

DENY - Microsoft.Windows.HolographicFirstRun

DENY - Microsoft.Windows.Photos

DENY - Microsoft.PPIProjection

DENY - Microsoft.MicrosoftEdge

 

Executables -

DENY - %SYSTEM32%\WindowsPowerShell\v1.0\powershell_ise.exe

DENY - %SYSTEM32%\WindowsPowerShell\v1.0\powershell.exe

DENY - %windir%\Temp\*

Allow - "Random Server URLS" e.g. SIMs/Apps etc etc

 

Scripts -

Allow - "Netlogon" folder

 

That's all basically as it is currently but looking to test it further as time allows

 

Steve

  • Thanks 1
Posted

Short answer is lack of testing on my part with the time I had over Easter (We're running a 7/10 split of about 50/50 still) and the fact I know it doesn't work with SSO for O365 etc and I got fed up with people asking while emails didn't work during our testing :p

 

Long term wise we may re-enable it, but we already need IE and Chrome for certain websites, and seemed adding a third one in was unnecessary.

 

Steve

Posted

My policy is based on the National Cyber Security Centre's AppLocker guidance (which is quite long :) )...

 

www.ncsc.gov.uk/guidance/eud-security-guidance-windows-10-1709#applockerconfig (scroll down to the AppLocker configuration section)

 

I am also (slowly) going through the following Microsoft recommendations...

 

https://docs.microsoft.com/en-gb/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules

 

If you use Windows Defender this KB article is worth reading too...

 

https://support.microsoft.com/en-gb/help/4052623/update-for-windows-defender-antimalware-platform

  • Thanks 4

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...