How to set up AppLocker restrictions on Windows 10 Pro?

Page 2 of 2 FirstFirst 12

  1. Posts : 68,937
    64-bit Windows 11 Pro for Workstations
       #11

    I haven't played with SRPs either, but I found this below that may help.

    https://docs.microsoft.com/en-us/win...ction-policies
      My Computers


  2. Posts : 186
    Xp, Vista, 7, 8.1, 10
    Thread Starter
       #12

    Brink said:
    I haven't played with SRPs either, but I found this below that may help.

    https://docs.microsoft.com/en-us/win...ction-policies
    I dug a little bit more into SRPs and unfortunately they are pretty much useless. The best you can do is deny access based on the hash of a file. What good can that do :)

    So going back to this suggestion:

    Brink said:
    You can also use Option One below to block application (exe) files using group policy. I just tested on my Windows 10 Pro.

    Applications - Prevent Running Specified Programs - Windows 7 Help Forums
    This is the only working solution I can do some restrictions with.

    So quick question to you. How do I know what was blocked? Otherwise it just shows the message box that something was blocked.

    In the AppLocker I could go to the Event Viewer and see what process was blocked.
      My Computer


  3. Posts : 68,937
    64-bit Windows 11 Pro for Workstations
       #13

    ahmd said:
    So quick question to you. How do I know what was blocked? Otherwise it just shows the message box that something was blocked.
    In the AppLocker I could go to the Event Viewer and see what process was blocked.

    You'll be able to see the list of apps you added in the gpedit policy setting.
      My Computers


  4. Posts : 186
    Xp, Vista, 7, 8.1, 10
    Thread Starter
       #14

    Brink said:
    You'll be able to see the list of apps you added in the gpedit policy setting.
    OK, I'll need to re-phrase it. So I added some process names to that list. Stuff like:

    mmc.exe
    explorer.exe
    srvchost.exe
    ...
    etc.

    But then, for instance, I was adding a network printer and it gave me a dialog box that that action was blocked by the administrator. So how do I know which process was blocked (that is not yet on my list, so I can add it)?

    In other words, how do I run it in an "audit" mode?
      My Computer


  5. Posts : 68,937
    64-bit Windows 11 Pro for Workstations
       #15

    I'm not aware of an audit mode for this other than knowing what process runs what you were trying to open.

    Most likely, this was for mmc.exe.
      My Computers


  6. Posts : 186
    Xp, Vista, 7, 8.1, 10
    Thread Starter
       #16

    mmc.exe is for the snap-in console. It has nothing to do with network printers.

    Too bad, Microsoft dropped the ball on this one too. Damn, such a great idea but such a bad implementation. (Typical MSFT.)

    BTW. Several hours later and I got it. (It was rundll32.exe. They use it to start all kinds of control panel windows.) So now I have 50 other processes to learn this manual way
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 07:06.
Find Us




Windows 10 Forums