| NL-PO-WIN-C-AppLocker Laptops | |
| Data collected on: 2-9-2025 12:23:49 | |
| Domain | emea.tpg.ads |
| Owner | EMEA\langras.5-adm |
| Created | 24-10-2024 12:52:54 |
| Modified | 18-6-2025 10:36:44 |
| User Revisions | 6 (AD), 6 (SYSVOL) |
| Computer Revisions | 139 (AD), 139 (SYSVOL) |
| Unique ID | {c38f8d00-04b0-4022-bfe0-8a950e21c8a7} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| Laptops | No | Enabled | emea.tpg.ads/BE/Systems/Clients/Laptops |
| Laptops | No | Enabled | emea.tpg.ads/NL/Systems/Clients/Laptops |
| Laptops | No | Enabled | emea.tpg.ads/SR/Systems/Clients/Laptops |
| Name |
|---|
| None |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| EMEA\NL-L-SEC-Deny All AppLocker | Custom | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.MicrosoftEdgeDevToolsClient, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.NarratorQuickStart, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.Xbox.TCUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Winget.Source, from Microsoft Corporation | Publisher | No |
| Allow | Everyone | All signed packaged apps | Publisher | Yes |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (Store) Microsoft.WindowsStore, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.DesktopAppInstaller, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ParentalControls, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.MicrosoftStickyNotes, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.ZuneVideo, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.GamingApp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c5e2524a-ea46-4f67-841f-6a9465d9d515, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | NcsiUwpApp, from Microsoft | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BingWeather, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.ZuneMusic, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (Cortana) Microsoft.549981C3F5F10, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | Microsoft.ScreenSketch, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.WindowsMaps, from Microsoft Corporation | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Microsoft Copilot | Microsoft.Copilot, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.AsyncTextService, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.Apprep.ChxApp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.VP9VideoExtensions, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.XboxGamingOverlay, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.MicrosoftSolitaireCollection, from Microsoft Studios | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Paint, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.WindowsSoundRecorder, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | 1527c705-839a-4832-9118-54d4Bd6a0c89, from Microsoft Corporation | Publisher | No |
| Allow | BUILTIN\Administrators | All signed packaged apps | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Getstarted, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (Weather) Microsoft.BingWeather, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecHealthUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BingNews, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.SecHealthUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.ContentDeliveryManager, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.XboxGameOverlay, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.XGpuEjectDialog, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.SecureAssessmentBrowser, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.WindowsFeedbackHub, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (Terminal) Microsoft.WindowsTerminal, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.YourPhone, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.XboxSpeechToTextOverlay, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.GetHelp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (ClipChamp) Clipchamp.Clipchamp, from Microsoft Corp. | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | MicrosoftCorporationII.QuickAssist, from Microsoft Corp. | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.BingSearch, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.Windows.DevHome, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.XboxGameCallableUI, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | Microsoft.ECApp, from Microsoft Corporation | Publisher | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | (xbox) Microsoft.XboxIdentityProvider, from Microsoft Corporation | Publisher | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | EMEA\NL-L-SEC-AppLocker Allow Powershell | POWERSHELL_ISE.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | ZOOM, in ZOOM, from O=ZOOM VIDEO COMMUNICATIONS, INC., L=SAN JOSE, S=CALIFORNIA, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Notepad | NOTEPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | CLICKSHARE PRESENTSENSE, from O=BARCO N.V., L=KORTRIJK, S=WEST-VLAANDEREN, C=BE | Publisher | No |
| Allow | Everyone | SCREENMEET, from O=PROJECTOR.IS, INC., L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | GOTO, from O=LOGMEIN, INC., L=BOSTON, S=MASSACHUSETTS, C=US | Publisher | No |
| Allow | Everyone | JABRA DIRECT, from O=GN AUDIO A/S, L=BALLERUP, C=DK | Publisher | No |
| Allow | Everyone | UIPATH, from O=UIPATH, INC., L=NEW YORK, S=NEW YORK, C=US | Publisher | No |
| Allow | Everyone | Signed by O=ISLAND TECHNOLOGY INC., L=COPPELL, S=TEXAS, C=US | Publisher | No |
| Allow | Everyone | TELEKNOWLEDGE CONNECT, from O=TELEKNOWLEDGE CALL CENTER SOLUTIONS B.V., S=NOORD-HOLLAND, C=NL | Publisher | No |
| Allow | Everyone | GOOGLE CHROME, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | CLICKSHARE, from O=BARCO N.V., L=KORTRIJK, S=WEST-VLAANDEREN, C=BE | Publisher | No |
| Allow | Everyone | Signed by O=CITRIX SYSTEMS, INC., L=FORT LAUDERDALE, S=FLORIDA, C=US | Publisher | No |
| Allow | Everyone | GOOGLE UPDATER, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | GOTOMEETING, from O=LOGMEIN, INC., L=BOSTON, S=MASSACHUSETTS, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | POWERSHELL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | MICROSOFT EDGE UPDATE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | SLACK, from O=SLACK TECHNOLOGIES, LLC, L=SAN FRANCISCO, S=CALIFORNIA, C=US | Publisher | No |
| Allow | Everyone | Signed by O=CITRIX SYSTEMS, INC., L=FORT LAUDERDALE, S=FLORIDA, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Wordpad | WORDPAD.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Powershell | POWERSHELL, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | SNIPPINGTOOL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Powershell | POWERSHELL.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow ODBC | ODBCAD32.EXE, in MICROSOFT® WINDOWS® OPERATING SYSTEM, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | All files located in the Windows folder | Path | Yes |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.WindowsFeedback* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.MSPaint* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files (x86)\Common Files\Java\Java Update\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\Mozilla Firefox\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | c:\Program Files\WindowsApps\Microsoft.ScreenSketch* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\MICROSOFT\TEAMS\* | Path | No |
| Allow | Everyone | %OSDRIVE%\USERS\*\APPDATA\LOCAL\JXBROWSER\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | c:\Program Files\WindowsApps\Microsoft.WindowsTerminal* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\System32\osk.exe | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %HOT%\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files (x86)\Mozilla Firefox\* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Windows.Photos* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | %PROGRAMFILES%\WindowsApps\Microsoft.WindowsStore* | Path | No |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Windows\WinSxS\amd64_microsoft-windows-wordpad* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Anaconda3 | C:\ProgramData\Anaconda3\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow TAP Screenrecording Tool | c:\Program Files\Captura-Portable\* | Path | No |
| Allow | Everyone | All files located in the Program Files folder | Path | Yes |
| Deny | EMEA\NL-L-SEC-AppLocker Restricted | C:\Program Files\WindowsApps\Microsoft.Paint* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Snipping Tool | %SYSTEM32%\SNIPPINGTOOL.EXE | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All files | Path | No |
| Allow | Everyone | SetUserFTA.exe | Hash | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | Everyone | MICROSOFT TEAMS MEETING ADD-IN FOR MICROSOFT OFFICE, from O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US | Publisher | No |
| Allow | Everyone | All Windows Installer files in %systemdrive%\Windows\Installer | Path | No |
| Allow | Everyone | %PROGRAMFILES%\WINDOWSAPPS\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All Windows Installer files | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Scripts in Userprofile | %OSDRIVE%\USERS\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %HOT%\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Policy | Setting |
|---|---|
| Enforce rules of this type | True |
| Action | User | Name | Rule Type | Exceptions |
|---|---|---|---|---|
| Allow | EMEA\NL-L-SEC-AppLocker Restricted | %OSDRIVE%\Users\Public\Fsal\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Program Files folder | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %HOT%\* | Path | No |
| Allow | Everyone | (Default Rule) All scripts located in the Windows folder | Path | No |
| Allow | Everyone | \\Emea.tpg.ads\sysvol\emea.tpg.ads\Policies\*\User\Scripts\Logon\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow IT | %OSDRIVE%\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Unrestricted | %OSDRIVE%\USERS\* | Path | No |
| Allow | BUILTIN\Administrators | (Default Rule) All scripts | Path | No |
| Allow | Everyone | %OSDRIVE%\PROGRAMDATA\MICROSOFT\GROUPPOLICY\USERS\* | Path | No |
| Allow | EMEA\NL-L-SEC-AppLocker Allow Scripts in Userprofile | %OSDRIVE%\USERS\* | Path | No |
| Action | Update |
| Hive | HKEY_LOCAL_MACHINE |
| Key path | SOFTWARE\Policies\Microsoft\Windows\WindowsAI |
| Value name | DisableAIDataAnalysis |
| Value type | REG_DWORD |
| Value data | 0x1 (1) |
| Stop processing items on this extension if an error occurs on this item | No |
| Remove this item when it is no longer applied | No |
| Apply once and do not reapply | No |