Windows 10: AppLocker: Deny one app for all except Publisher/another App

Discus and support AppLocker: Deny one app for all except Publisher/another App in Windows 10 Software and Apps to solve the problem; Hi, Windows 10 1809 Enterprise (corporate install) I need 2 versions of Java RE installed: an older version for a bespoke app and the latest version.... Discussion in 'Windows 10 Software and Apps' started by ldoodle, Dec 30, 2019.

  1. ldoodle Win User

    AppLocker: Deny one app for all except Publisher/another App


    Hi,

    Windows 10 1809 Enterprise (corporate install)

    I need 2 versions of Java RE installed: an older version for a bespoke app and the latest version. The old version must only be able to be used when called by the bespoke app and nothing else. And the new version must be used for all other apps but never by the bespoke app.

    Is this possible with AppLocker?

    Thanks

    :)
     
    ldoodle, Dec 30, 2019
    #1
  2. JonDupe Win User

    AppLocker Blocks Windows Store Apps Downloads

    For those of you who are suffering from the AppLocker issue...

    First, to set context. AppLocker is a built in security mechanism that allows you to control (Block or Allow) "stuff" from running on your computer. In the context of Modern Apps and the Store, it does not prohibit the use of the store, rather the download,
    installation, and launch of Modern\Universal Applications.

    At our company we have a good number of Windows 8.1 machines in the environment. We use AppLocker to restrict the use of all unknown "Modern Apps" by creating a global Deny rule. In order for all of the "built-in" Windows apps to load correctly (at fist
    login and on update), we had to configure the global deny rule with a wildcard(*) exceptions (you do this that have a values of "*" in the scope of the ). This is similar to a typical firewall configuration where you block everything then make your exceptions
    of stuff you want to allow. Once you have allowed exceptions, you need to have "allow" rules to pass through the global "deny" rule. That means that you have to create specific allow rules for the apps you want users to be able to download, install, and
    launch.

    We also have an allow rule for a specific user group that has '*' as the scope. This rule is necessary if you want to give certain users, such as your Desktop Admins, the ability to download, install, and run all modern apps. This was also an important piece
    for Developers trying to debug a modern app that they are developing. Without this rule developer will not be able to run their modern apps in Visual Studio. This all worked beautifully with Windows 8.1...along comes Windows 10...

    When we first starting building Windows 10 computers, at the time it was 1511, we added new rules to allow all of the new built-in apps. Life was good...or so it seemed. What we found was that any time a modern (or universal app) was trying to update,
    that the updates were being blocked with an 0x80073CF9 error in the store. There was also a corresponding event in the AppLocker logs about the blocked attempt.

    When 1607 came out we tested the issue again hoping that we'd find that it was magically resolved. As we starting re-testing this AppLocker issue when we found that users who were in the "Allow All Apps" group were getting denied the right to "install"
    software by Applocker (I put "install" in quotes intentionally. After doing some troubleshooting and testing on both 1511 and 1607, I found that on both versions the steps to install a modern app are slightly different than they were in Windows 8.1 and that
    AppLocker does not like the changes. In W10 and W8.1 when the apps from the store are first downloaded before they are installed. In Windows 8.1, the app is download under the logged in users context. In Windows 10, the download occurs under local SYSTEM
    and is then passed over to the user context to perform the install. I figured this my looking closely at the user whom the AppLocker log was written for.

    Since "SYSTEM" is not a member of the group that is allowed to use the app (download, install, and run), the action is not allowed to pass through the deny rule exception and AppLocker stops the download process resulting in the 0x80073CF9 error. Just to
    prove my theory I added a test rule to allow "NT AUTHORITY\SYSTEM" and everything stared working as they did in Windows 8.1. I was able to update installed apps and new apps from the store.

    Additionally, we happen to have a Microsoft consultant onsite so I had him run the same exact tests in his lab. He had the same exact issue. This was not a problem caused by a configuration or policy in our environment.

    The bottom line is that Microsoft changed the behavior of how apps are downloaded and installed from the Windows Store. This change broke the way AppLocker works. I REALLY hop that Microsoft fixes this. What I have mentioned in this post is not an acceptable
    workaround...I did this as a test.

    For security reasons, I HIGHLY DISCOURAGE anyone from giving "NT AUTHORITY\SYSTEM" permissions to install ANYTHING from the store.
     
    JonDupe, Dec 30, 2019
    #2
  3. Paola Gar Win User
    applocker publisher information cannot extracted Windows 10 only

    Hi,

    In order for us to know where the issue is coming from, we'd like to get the following information:

    • Is this the first time that you'll be using AppLocker in Windows 10?
    • Have you made any changes or applied an update to your device before the issue occurred?
    • What troubleshooting steps have you tried so far?
    • If possible, kindly send us a screenshot of the complete error message you're getting and the AppLocker you're using.

    Looking forward to your response.
     
    Paola Gar, Dec 30, 2019
    #3
  4. John_NL Win User

    AppLocker: Deny one app for all except Publisher/another App

    AppLocker Blocks Windows Store Apps Downloads

    It's now March 2017, this problem is dragging on since August 2015. I've installed Windows 10 Pro in total 4 times on two machines because of this issue.

    My conclusion is that some installer changes the working of AppLocker. But, Windows 10 Pro lacks the ability to change AppLocker settings (you cannot even switch on or off its identity service).

    Interestingly, the many people here on 'answers'.microsoft.com trying to answer this question all come up with the same suggestions that do not work (in my case):

    • wsreset.exe or run the troubleshooter for apps (https://support.microsoft.com/en-us...790db/run-the-troubleshooter-for-windows-apps)
    • Adjust the settings of AppLocker in Local Security Policy (in secpol.msc). This obviously does not work because Windows 10 Pro is not supposed to have AppLocker at all. AppLocker is only available in Enterprise versions.
    • Fiddle around with permission settings
    • Create c:\Windows\AppReadiness
    • Reinstall Windows 10 Pro

    The Pro in Windows 10 Pro stands for Probably.: Probably you need to reinstall.

    For Microsoft (if you want to do something):

    a. The trouble shooter mentions a 'possible' problem with the Store cache. But is does not offer/is unable to do a repair

    b. Doing a harddisk chkdsk could result in a blue screen of death and a subsequent repair of Windows (to a previous version).

    c. Sometimes (at least in my current installed system), it is possible to add a new user to the system, but that user's settings are defected. That user cannot use the start-menu at all, looks like an even more serious problem there.
     
    John_NL, Dec 30, 2019
    #4
Thema:

AppLocker: Deny one app for all except Publisher/another App

Loading...
  1. AppLocker: Deny one app for all except Publisher/another App - Similar Threads - AppLocker Deny app

  2. How to disable all windows functionalities except for one app ?

    in Windows 10 Gaming
    How to disable all windows functionalities except for one app ?: Hi,I am trying to use a computer as a monitor for an app.I want the local user to only be able to use one application, and nothing else no file explorer, no windows explorer, no apps, nothing.How could I achieve this ?Thank you !...
  3. How to disable all windows functionalities except for one app ?

    in Windows 10 Software and Apps
    How to disable all windows functionalities except for one app ?: Hi,I am trying to use a computer as a monitor for an app.I want the local user to only be able to use one application, and nothing else no file explorer, no windows explorer, no apps, nothing.How could I achieve this ?Thank you !...
  4. Disable Media Keys for Everything except one App

    in Windows 10 Gaming
    Disable Media Keys for Everything except one App: Hello,I don't like it when Explorer, Whatsapp, Firefox, Chrome or any other app intervene with my media keys when I simply try to pause the song on Spotify. Is there a way to set it up to so that it can only work with Spotify?Thanks...
  5. Disable Media Keys for Everything except one App

    in Windows 10 Software and Apps
    Disable Media Keys for Everything except one App: Hello,I don't like it when Explorer, Whatsapp, Firefox, Chrome or any other app intervene with my media keys when I simply try to pause the song on Spotify. Is there a way to set it up to so that it can only work with Spotify?Thanks...
  6. all the other apps except chrome is not opening

    in Windows 10 Software and Apps
    all the other apps except chrome is not opening: I have recently been experiencing te problem that all the other apps except chrome is not opening. Please help https://answers.microsoft.com/en-us/windows/forum/all/apps/cc058a96-02dc-4637-b177-d4fe2ab33329
  7. AppLocker Allowed Executable Runs Denied DLL

    in AntiVirus, Firewalls and System Security
    AppLocker Allowed Executable Runs Denied DLL: I am testing AppLocker's functionality to assess suitability for protecting a windows application from tampering. My goal is to test the robustness of its rules in the face of DLL hijacking. As a test I have a simple executable compiled from C# that displays a window and...
  8. App/addon/extension to send apps from one monitor to another?

    in Windows 10 Support
    App/addon/extension to send apps from one monitor to another?: [img] Task View should have these options but currently it's for virtual desktops only. I wonder if there's some app that can quickly send apps from one monitor to another? Context-menu right click -> choose option? I'm aware of keyboard shortcut win + shift + <- and win +...
  9. Windows UWP apps fail to start except one.

    in Windows 10 BSOD Crashes and Debugging
    Windows UWP apps fail to start except one.: - Hi! I'm Running 1803 and i get this weird error whenever i try to do anything with UWP Related app (Except one: State of Decay 2). It roughly opens up an error box stating "File system error -2147219196". I tried to enforce app re-rollout Get-AppXPackage | Foreach...
  10. AppLocker Blocks Windows Store Apps Downloads

    in Windows 10 Software and Apps
    AppLocker Blocks Windows Store Apps Downloads: Hello -- I've Windows 10 Pro x64, and I did a clean install a few days ago because of a similar issue. Now, Windows Store does open up and installed apps run just fine; however, I'm not able to download new apps or update existing ones. Downloads get aborted with error...