Trying to whip Win10 Enterprise into shape for our environment and just did my first Applocker policy (created the rules on a Win10 machine, exported and imported into my policy on our domain controllers). It worked mostly as expected. On the account of which the policy was created, I get "application blocked by your administrator" message when clicking on a live tile of a blocked application. On subsequent new user profiles, I see a different behavior - the tile just gets grayed out when it is clicked on, no message or anything. Subsequent log-out/log-ins, the app will be "lit up" again until it is clicked and becomes gray. The only thread I can find on this is here: . I was under the impression that subsequent logins wouldn't even SEE the blocked applications, but not to get even the blocked message is just worthless. Anyone seen this before?