question

YUKIABE-9181 avatar image
0 Votes"
YUKIABE-9181 asked Mark-Heitbrink answered

AppLocker is not effect in Windows 10 Pro 20H2

Thank you for looking this question. I would use Applocker in Win10 Pro 20H2.

Using Applocker, it prohibit to run downloaded files by User (as MSI Installer, *.exe).

1) I created a GPO by GPMC on Windows Server 2019.
GPO is include that Everyone cannot run any application in "C:\program files*"

2) GPO is linked to OU that it belong to the target windows 10 client pc.

3) it run "gpupdate /force" and restart windows 10 pc

4) I test that applocker prohibited application is run. but there is a no effect. any application is lunched



My question is that
Is Not Windows 10 Pro 20H2 support AppLocker?

How version of windows 10 is support AppLocker?

With regards

windows-10-generalwindows-10-securitywindows-group-policy
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
To understand the issue more clearly, would you please run the command :gpresult /h report.html and share a screenshot here?(Please hide the private information).
Best Regards,

0 Votes 0 ·
YUKIABE-9181 avatar image
0 Votes"
YUKIABE-9181 answered

Thank you for your response.

I've run command and paste results
Please advice

===

59355-image.png



image.png (41.1 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

YUKIABE-9181 avatar image
0 Votes"
YUKIABE-9181 answered FanFan-MSFT commented

After then, I tried to disable fast startup as referred below linked documents.

https://docs.microsoft.com/ja-jp/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/jj573586(v=ws.11)?redirectedfrom=MSDN

And, it effected any GPO to target PC.

I'll try applocker a bit more.

With regards

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,
When you run the command ,need to run cmd as administrator and type the command :gpresult /h report.html.
Then you can see the computer settings on this computer.
Or you can just see the user settings.
Best Regards,

0 Votes 0 ·

Hi,
 
Just want to confirm the current situations.
If there's anything you'd like to know, don't hesitate to ask.

Best Regards,

0 Votes 0 ·
YUKIABE-9181 avatar image
0 Votes"
YUKIABE-9181 answered YUKIABE-9181 edited

Thank you for your response.

Applocker is Effected in Win 10 Pro 20H2.

The only reason was that the GPO was not working in fast mode.

It solved.

With regards.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Mark-Heitbrink avatar image
0 Votes"
Mark-Heitbrink answered

Hi YUKIABE-9181,

The Group Policy solution shouldn´t work on the professional SKU. Group Policy requires Enterprise..

Applocker on Professional needs the CSP which is not that easy to apply.

https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/requirements-to-use-applocker
See the notes:
[...] You can only manage AppLocker with Group Policy on devices running Windows 10 Enterprise,

https://msendpointmgr.com/2020/09/20/does-applocker-work-in-windows-10-pro-yes-it-does/

You can use Software Restriction Policies on Professional.

Mark

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.