So we are trying to replace our current AppLocker GPO from our Hybrid.
Using Configuration Profile in Intune and Device Configuration Profiles / Custom.
So our Value * looks like this :
<RuleCollection Type="Exe" EnforcementMode="Enabled">
<FilePathRule Id="921cc481-6e17-4653-8f75-050b80acca20" Name="(Default Rule) All files located in the Program Files folder" Description="Allows members of the Everyone group to run applications that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">
<FilePathCondition Path="%PROGRAMFILES%*" />
<FilePathRule Id="a61c8b2c-a319-4cd0-9690-d2177cad7b51" Name="(Default Rule) All files located in the Windows folder" Description="Allows members of the Everyone group to run applications that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">
<FilePathCondition Path="%WINDIR%*" />
<FilePathRule Id="fd686d83-a829-4351-8ff4-27c7de5755d2" Name="(Default Rule) All files" Description="Allows members of the local Administrators group to run all applications." UserOrGroupSid="S-1-5-32-544" Action="Allow">
<FilePathCondition Path="*" />
However, it does not seem to be working.
Even in Event Viewer I get the Event ID of 8001 stating that : The AppLocker policy was applied successfully to this computer.
But it doesn't seem to apply regardless?
What am I doing wrong here?