How i can block APP in Endpoint security | App Control for Business (Preview)

Danissimode 40 Reputation points
2023-11-24T15:00:33.7066667+00:00

please explain how to prohibit the installation of browsers that can be installed by users with standard rights? as far as I understand, the correct way is to configure App Control for Business. But I don't understand how to leave all settings as standard and block only certain app publishers by the "publisher" attribute. it is important for me not to turn on anything unnecessary. when generating XML, can I remove for example all rules from the WDAC Wizard table and leave only the Deny app rule?

Microsoft Security | Intune | Other
{count} votes

Answer accepted by question author
  1. Crystal-MSFT 54,201 Reputation points Microsoft External Staff
    2023-11-27T02:20:20.2866667+00:00

    @Danissimode, Thanks for posting in Q&A. Based on my researching, I find Intune's endpoint security App Control for Business policies manage which apps on your managed Windows devices are allowed to run. Any apps that aren't explicitly allowed to run by a policy are blocked from running.

    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-app-control-policy#get-started-with-app-control-for-business-policies

    For your scenario, it seems you want to just block one app. You can consider AppLocker to block one app.

    https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-using-applocker-to-create-custom-intune-policies-for/ba-p/364981

    From the picture you provided, I find the firefox.exe under Tor Browser can't get the publisher information. You can download the firefox.exe file from their official article to see if it has publisher information. If still not, you can contact their support to see if they can add the publisher information in the app.

    Then you can consider using File hash :instead to see if it can block the app.

    https://social.technet.microsoft.com/wiki/contents/articles/5211.how-to-configure-applocker-group-policy-to-prevent-software-from-running.aspx

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.