| NL-PO-WIN-C-AppLocker Audit Mode | |
| Data collected on: 2-9-2025 12:14:57 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\langras.5-adm |
| Created | 31-7-2024 09:57:38 |
| Modified | 1-11-2024 07:18:28 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 201 (AD), 201 (SYSVOL) |
| Unique ID | {2690e18d-8a1a-4535-af44-cc54b11444cb} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| None | |||
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\NL-L-SEC-Deny All AppLocker | Custom | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.MicrosoftEdgeDevToolsClient, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.NarratorQuickStart, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Winget.Source, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | All signed packaged apps | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.DesktopAppInstaller, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ParentalControls, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c5e2524a-ea46-4f67-841f-6a9465d9d515, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | NcsiUwpApp, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.AsyncTextService, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.Apprep.ChxApp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.VP9VideoExtensions, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | 1527c705-839a-4832-9118-54d4Bd6a0c89, from Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | All signed packaged apps | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecHealthUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Windows.PrintDialog, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ContentDeliveryManager, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.XGpuEjectDialog, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecureAssessmentBrowser, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BioEnrollment, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BingSearch, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.DevHome, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.XboxGameCallableUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.ECApp, from Microsoft Corporation | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | POWERSHELL_ISE.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | Signed by O=ISLAND TECHNOLOGY INC., L=COPPELL, S=TEXAS, C=US | Publisher | No |
| Allow | Everyone | Signed by O=CITRIX SYSTEMS, INC., L=FORT LAUDERDALE, S=FLORIDA, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | SLACK, from O=SLACK TECHNOLOGIES, LLC, L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | SIGHTCALL, from O=SIGHTCALL, INC, S=CALIFORNIA, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | WORDPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | NOTEPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | ONEDRIVE.EXE, in MICROSOFT ONEDRIVE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | PWSH.DLL, in POWERSHELL, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | SNIPPINGTOOL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | GOOGLE CHROME, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | POWERSHELL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.WindowsFeedback* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.MSPaint* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files (x86)\Common Files\Java\Java Update\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\Mozilla Firefox\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | c:\Program Files\WindowsApps\Microsoft.ScreenSketch* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | Allow IEX Azure logon (%OSDRIVE%\USERS\*\APPDATA\LOCAL\JXBROWSER\*) | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files\WindowsApps\Microsoft.WindowsTerminal* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\System32\osk.exe | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files (x86)\Mozilla Firefox\* | Path | No |
| Allow | Everyone | All files located in the Program Files folder | Path | Yes |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\Microsoft OneDrive\OneDrive.exe | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Windows.Photos* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | %PROGRAMFILES%\WindowsApps\Microsoft.WindowsStore* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\WinSxS\amd64_microsoft-windows-wordpad* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files\WindowsApps\Microsoft.WindowsTerminal* | Path | No |
| Deny | S-1-5-21-513466819-3096973226-347852806-1513486 | c:\Program Files\Captura-Portable\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | %OSDRIVE%\USERS\*\APPDATA\LOCAL\MICROSOFT\TEAMS\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Paint* | Path | No |
| Allow | Everyone | All files located in the Windows folder | Path | Yes |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All files | Path | No |
| Allow | Everyone | SetUserFTA.exe | Hash | No |
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | C:\WinAuth\WinAuth.exe | Hash | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | MICROSOFT TEAMS MEETING ADD-IN FOR MICROSOFT OFFICE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | All Windows Installer files in %systemdrive%\Windows\Installer | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All Windows Installer files | Path | No |
| Allow | Everyone | %PROGRAMFILES%\WINDOWSAPPS\* | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Program Files folder | Path | No |
| Allow | Everyone | \\Emea.tpg.ads\sysvol\emea.tpg.ads\Policies\*\User\Scripts\Logon\* | Path | No |
| Allow | EMEA\NL-L-SEC-User Exceptions and Settings Gall & Gall | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | EMEA\NL-L-SEC-User Exceptions and Settings AH | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | Everyone | %OSDRIVE%\PROGRAMDATA\MICROSOFT\GROUPPOLICY\USERS\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Windows folder | Path | No |
| Allow | EMEA\SR-L-SEC-User Exceptions and Settings AH | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | EMEA\NL-L-SEC-User Exceptions and Settings Etos | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\TEMP\*\getpaths.cmd | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All scripts | Path | No |
| Allow | Everyone | RemoveEdgeCookies.bat | Hash | No |