| KE-PO-WIN-C-Enterprise Windows Applocker Control | |
| Data collected on: 2-9-2025 10:38:55 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\tentolouris.5-adm |
| Created | 9-8-2022 10:48:00 |
| Modified | 9-2-2023 15:40:58 |
| User Revisions | 1 (AD), 1 (SYSVOL) |
| Computer Revisions | 120 (AD), 120 (SYSVOL) |
| Unique ID | {e5da6ea4-da4d-4187-9440-4a037bc32190} |
| GPO Status | User settings disabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | Yes | Enabled | emea.tpg.ads/KE/Systems/Clients |
| Name |
|---|
| EMEA\KE-L-SEC-Clients Windows Enterprise Settings |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\Domain Admins | Edit settings, delete, modify security | No |
| EMEA\Domain Computers | Read | No |
| EMEA\KE-G-ORG-OU Admins | Edit settings, delete, modify security | No |
| EMEA\KE-L-SEC-Clients Windows Enterprise Settings | Read (from Security Filtering) | No |
| EMEA\tentolouris.5-adm | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| ROOT\Enterprise Admins | Edit settings, delete, modify security | No |
| Owner |
| Type | Name | Permission | Apply To |
|---|---|---|---|
| Allow | BUILTIN\Administrators | Full Control | This folder, subfolders and files |
| Allow | CREATOR OWNER | Full Control | Subfolders and files only |
| Allow | NT AUTHORITY\SYSTEM | Full Control | This folder, subfolders and files |
| Allow | BUILTIN\Users | Read and Execute | This folder, subfolders and files |
| Allow | APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES | Read and Execute | This folder, subfolders and files |
| Allow inheritable permissions from the parent to propagate to this object and all child objects | Disabled |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | EMEA\KE-L-SEC-Apps Cortana Allowed | Microsoft.Windows.Cortana, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MicrosoftSway | Microsoft.Office.Sway, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps ScreenRecorderProWin10 Allowed | 57506winuwp.ScreenRecorderProForWin10, from winuwp | Publisher | No |
| Allow | Everyone | Microsoft.Windows.PeopleExperienceHost, from Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | Signed by * | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MicrosoftToDo Allowed | Microsoft.Todos, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MSAccountsControl Allowed | Microsoft.Windows.CloudExperienceHost, from Email, phone, or Skype | Publisher | No |
| Allow | Everyone | Microsoft.Windows.StartMenuExperienceHost, from ms-resource:StartMenuExperienceHost/PublisherDisplayName | Publisher | No |
| Allow | Everyone | windows.immersivecontrolpanel, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.Apprep.ChxApp, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.Windows.ShellExperienceHost, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps OneNote Allowed | Microsoft.Office.OneNote, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Snip & Sketch Allowed | Microsoft.ScreenSketch, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Photos Allowed | Microsoft.Windows.Photos, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | Microsoft.Windows.CloudExperienceHost, from Email, phone, or Skype | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps DesktopAppInstaller | Microsoft.DesktopAppInstaller, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Xbox Game Bar Allowed | Microsoft.XboxGamingOverlay, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.WindowsCalculator, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Search Allowed | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps WindowsCommunicationApps | microsoft.windowscommunicationsapps, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Sticky Notes Allowed | Microsoft.MicrosoftStickyNotes, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Windows.PrintDialog, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Camera Allowed | Microsoft.WindowsCamera, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps 3DPaint Allowed | Microsoft.MSPaint, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MSAccountsControl Allowed | Microsoft.AccountsControl, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Store Allowed | Microsoft.WindowsStore, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps PDF Reader Kdan Mobile Allowed | 0D9A1B2D.PDFReaderUWP, from Kdan Mobile Software Ltd. | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Groove Music Allowed | Microsoft.ZuneMusic, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps OneDrive Allowed | microsoft.microsoftskydrive, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Trello Allowed | 45273LiamForsyth.PawsforTrello, from Trello, Inc. | Publisher | No |
| Allow | Everyone | InputApp, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Whiteboard Allowed | Microsoft.Whiteboard, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-UNRestrict Applocker | Signed by * | Publisher | No |
| Allow | NT AUTHORITY\SYSTEM | Signed by * | Publisher | No |
| Allow | Everyone | Microsoft.LockApp, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | Microsoft.AAD.BrokerPlugin, from Assigned by your organization | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MicrosoftSmartCardManager | Microsoft.MicrosoftSmartCardManager, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | MicrosoftWindows.Client.CBS, from Microsoft Windows | Publisher | No |
| Allow | Everyone | WavesAudio.MaxxAudioProforDell2019, from Waves Audio | Publisher | No |
| Allow | Everyone | Microsoft.MicrosoftEdge, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps Calculator Allowed | Microsoft.WindowsCalculator, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | Microsoft.549981C3F5F10, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\KE-L-SEC-Apps MobilePASS Allowed | 05EB1CFA.SafeNetMobilePASS, from Gemalto Pte Ltd | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | MICROSOFT TEAMS UPDATE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | MICROSOFT TEAMS, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\KE-L-SEC-UNRestrict CMD & Powershell | %SYSTEM32%\conhost.exe | Path | No |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | %WINDIR%\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\* | Path | No |
| Allow | EMEA\KE-L-SEC-UNRestrict CMD & Powershell | %SYSTEM32%\cmd.exe | Path | No |
| Deny | EMEA\KE-L-SEC-Restrictive Applocker for Management | Restricted Access for MGMT | Path | Yes |
| Allow | Everyone | All files located in the Windows folder | Path | Yes |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | %WINDIR%\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\* | Path | No |
| Allow | Everyone | (Default Rule) All files located in the Program Files folder | Path | No |
| Deny | EMEA\KE-L-SEC-Restrict SnippingTool | %SYSTEM32%\SnippingTool.exe | Path | No |
| Allow | EMEA\KE-L-SEC-UNRestrict CMD & Powershell | %SYSTEM32%\WindowsPowerShell\v1.0\powershell_ise.exe | Path | No |
| Deny | EMEA\KE-L-SEC-Restricted Search on Start menu | %WINDIR%\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\* | Path | No |
| Allow | Everyone | * | Path | Yes |
| Allow | EMEA\KE-L-SEC-UNRestrict CMD & Powershell | %SYSTEM32%\WindowsPowerShell\v1.0\powershell.exe | Path | No |
| Allow | EMEA\KE-L-SEC-UNRestrict Applocker | * | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All files | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | (Default Rule) All digitally signed Windows Installer files | Publisher | No |
| Deny | EMEA\KE-L-SEC-Restrictive Applocker for Management | Restricted Access for MGMT | Path | Yes |
| Allow | Everyone | (Default Rule) All Windows Installer files in %systemdrive%\Windows\Installer | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All Windows Installer files | Path | No |
| Allow | Everyone | Allow All | Path | No |
| Allow | EMEA\KE-L-SEC-UNRestrict Applocker | * | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | (Default Rule) All scripts located in the Program Files folder | Path | No |
| Deny | EMEA\KE-L-SEC-Restrictive Applocker for Management | Restricted Access for MGMT | Path | Yes |
| Allow | Everyone | (Default Rule) All scripts located in the Windows folder | Path | No |
| Allow | Everyone | Allow All | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All scripts | Path | No |
| Allow | EMEA\KE-L-SEC-UNRestrict Applocker | * | Path | No |
| Policy | Setting | Comment | ||||||
|---|---|---|---|---|---|---|---|---|
| Specify settings for optional component installation and component repair | Enabled | |||||||
| ||||||||
| Policy | Setting | Comment |
|---|---|---|
| Block launching desktop apps associated with a file. | Disabled | |
| Block launching desktop apps associated with a URI scheme | Disabled | |
| Block launching Universal Windows apps with Windows Runtime API access from hosted content. | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Disable all apps from Microsoft Store | Disabled | |
| Turn off Automatic Download of updates on Win8 machines | Disabled | |
| Turn off the offer to update to the latest version of Windows | Disabled | |
| Turn off the Store application | Disabled |
| Policy | Setting | Comment |
|---|---|---|
| Do not connect to any Windows Update Internet locations | Disabled |