| NL-PO-WIN-C-AppLocker Desktops | |
| Data collected on: 2-9-2025 12:15:06 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\langras.5-adm |
| Created | 2-8-2024 08:11:46 |
| Modified | 18-6-2025 10:36:44 |
| User Revisions | 0 (AD), 0 (SYSVOL) |
| Computer Revisions | 206 (AD), 206 (SYSVOL) |
| Unique ID | {9d561786-4b01-42be-83c3-a48e9cdcb09c} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Clients | No | Enabled | emea.tpg.ads/BE/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/NL/Systems/Clients |
| Clients | No | Enabled | emea.tpg.ads/SR/Systems/Clients |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\NL-L-SEC-Deny All AppLocker | Custom | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.MicrosoftEdgeDevToolsClient, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.NarratorQuickStart, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Winget.Source, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | All signed packaged apps | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.DesktopAppInstaller, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ParentalControls, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c5e2524a-ea46-4f67-841f-6a9465d9d515, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | NcsiUwpApp, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.AsyncTextService, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.Apprep.ChxApp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.VP9VideoExtensions, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | 1527c705-839a-4832-9118-54d4Bd6a0c89, from Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | All signed packaged apps | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecHealthUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ContentDeliveryManager, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.XGpuEjectDialog, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecureAssessmentBrowser, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.Search, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BioEnrollment, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BingSearch, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.DevHome, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.XboxGameCallableUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.ECApp, from Microsoft Corporation | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | POWERSHELL_ISE.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | JABRA DIRECT, from O=GN AUDIO A/S, L=BALLERUP, C=DK | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | SNIPPINGTOOL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | Signed by O=CITRIX SYSTEMS, INC., L=FORT LAUDERDALE, S=FLORIDA, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | WORDPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | GOTOMEETING, from O=LOGMEIN, INC., L=BOSTON, S=MASSACHUSETTS, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Notepad | NOTEPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-User Exceptions and Settings All CSS | ONEDRIVE.EXE, in MICROSOFT ONEDRIVE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | SLACK, from O=SLACK TECHNOLOGIES, LLC, L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Deny MSEDGE | MSEDGE.EXE, in MICROSOFT EDGE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | GOOGLE CHROME, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | SCREENMEET, from O=PROJECTOR.IS, INC., L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | GOOGLE UPDATER, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | Signed by O=ISLAND TECHNOLOGY INC., L=COPPELL, S=TEXAS, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | PWSH.DLL, in POWERSHELL, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | POWERSHELL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.WindowsFeedback* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.MSPaint* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files (x86)\Common Files\Java\Java Update\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\Mozilla Firefox\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | c:\Program Files\WindowsApps\Microsoft.ScreenSketch* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\MICROSOFT\TEAMS\* | Path | No |
| Allow | Everyone | Allow IEX Azure logon (%OSDRIVE%\USERS\*\APPDATA\LOCAL\JXBROWSER\*) | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files\WindowsApps\Microsoft.WindowsTerminal* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | %SYSTEM32%\SnippingTool.exe | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\System32\osk.exe | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files (x86)\Mozilla Firefox\* | Path | No |
| Deny | EMEA\NL-L-SEC-User Exceptions and Settings All CSS | C:\Program Files\Microsoft OneDrive\OneDrive.exe | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Windows.Photos* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | %PROGRAMFILES%\WindowsApps\Microsoft.WindowsStore* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\WinSxS\amd64_microsoft-windows-wordpad* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files\WindowsApps\Microsoft.WindowsTerminal* | Path | No |
| Allow | Everyone | All files located in the Program Files folder | Path | Yes |
| Allow | Everyone | %OSDRIVE%\PROGRAMDATA\*\SQUIRRELTEMP\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Allow | Everyone | All files located in the Windows folder | Path | Yes |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Paint* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\SQUIRRELTEMP\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All files | Path | No |
| Allow | Everyone | SetUserFTA.exe | Hash | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | MICROSOFT TEAMS MEETING ADD-IN FOR MICROSOFT OFFICE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | Signed by O=PULSE SECURE, LLC, L=SAN JOSE, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | All Windows Installer files in %systemdrive%\Windows\Installer | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All Windows Installer files | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Allow | Everyone | %PROGRAMFILES%\WINDOWSAPPS\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Program Files folder | Path | No |
| Allow | Everyone | \\Emea.tpg.ads\sysvol\emea.tpg.ads\Policies\*\User\Scripts\Logon\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Windows folder | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All scripts | Path | No |
| Allow | Everyone | %OSDRIVE%\PROGRAMDATA\MICROSOFT\GROUPPOLICY\USERS\* | Path | No |
| Allow | Everyone | RemoveChromeCookies.bat | Hash | No |
| Allow | Everyone | RemoveEdgeCookies.bat | Hash | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\WindowsAI |
| Value name | DisableAIDataAnalysis |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |