Applocker not applying to Windws 10 Enterprise 20H2

EE-9037 526 Reputation points
2021-03-10T23:13:20.417+00:00

Hi,

I am running Windows 10 Enterprise version 20H2. We are using applocker in our environment. When I run the Group Policy result on this laptop, it confirms that my Applocker Policy is being applied successfully. However, when I open Application Control Policies under secpol, it is empty. Other computers on a different build are working. This is my first 20H2 build, so I have nothing else to compare.

The machine is in the correct OU, and GPO is being applied, but I don't see my policies. Is there a known issue with Applocker and Windows 10 Enterprise, 20H2? Any other suggestions on what to do? Thank you.

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,705 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,798 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Carl Fan 6,836 Reputation points
    2021-03-11T09:56:28.207+00:00

    Hi,
    Please refer the information below:
    AppLocker is not effect in Windows 10 Pro 20H2
    https://learn.microsoft.com/en-us/answers/questions/239693/applocker-is-not-effect-in-windows-10-pro-20h2.html
    Hope this helps and please help to accept as Answer if the response is useful.
    Best Regards,
    Carl

    0 comments No comments

  2. ItzikT 111 Reputation points
    2021-05-27T12:04:42.443+00:00

    I had the exact same issue, turns out it was the service Application Identity that refused to switch to Automatic rather than Manual.

    The only way I managed to fix it was force the service to Automatic startup using GPO.

    0 comments No comments

  3. EE-9037 526 Reputation points
    2021-05-27T15:35:02.937+00:00

    Thanks for the input. That is not the case for me. Application Identity is running, and we also have it set in GPO to Automatic to avoid that possibility.

    0 comments No comments