Windows 10: Using AppLocker through GPO disables Teams and Right-Click feature

Discus and support Using AppLocker through GPO disables Teams and Right-Click feature in AntiVirus, Firewalls and System Security to solve the problem; I am trying to use AppLocker to prevent MalwareBytes from being installed and/or being run. However, when I enable it, it also blocks Teams from... Discussion in 'AntiVirus, Firewalls and System Security' started by CEB_HexUSFed, Aug 6, 2021.

  1. Using AppLocker through GPO disables Teams and Right-Click feature


    I am trying to use AppLocker to prevent MalwareBytes from being installed and/or being run. However, when I enable it, it also blocks Teams from running and I can't right-click on a task bar icon any longer although a shift-right-click will still workHas anyone seen anything like this before???Thanks!Carl

    :)
     
    CEB_HexUSFed, Aug 6, 2021
    #1

  2. AppLocker GPOs marked as applied but Rules are not enforced

    Hi Community,

    We have been experiencing a problem with AppLocker GPOs in a Windows 10 Environment.

    The Domain functionality level is: Server 2012R2

    Domain Controllers are running: Windows Server 2016

    Workstations are running: Windows 10 Enterprise Build 17134

    We have 2 GPOs; one containing DLL AppLocker Rules and one containing EXE, Script, Appx etc.. Rules.

    When running a gpupdate /force on an affected workstation and getting the gpresult the GPOs appear to be applied and are marked as winning however the contents of C:\Windows\system32\Applocker files are not being updated and recent rules added to both GPOs
    are not being applied. i.e. a new application which has been whitelisted will not run for the user albeit being specified in the applied GPO.

    Can someone please shed some light into this issue?

    Help is highly appreciated!

    Kind regards,

    Jason
     
    Jason Buhagiar, Aug 6, 2021
    #2
  3. JiriOlsar Win User
    Start menu/ms-settings not working Windows 10

    Yes I can see that, but I'm running Windows 10 Home edition.

    To terminate AppLocker rule enforcement


    • Backup the Group Policy Object (GPO) that contains the currently applied AppLocker rules.

    • Delete all the AppLocker rules on that GPO. For steps how to do this, see the topics in

      AppLocker Policy Procedures
      .

    • Push out the GPO that now contains the empty AppLocker policy to the affected client computers. For steps how to do this, see

      Refresh an AppLocker Policy
      .

    • Disable the AppLocker service (appidsvc) on all the affected client computers. Optionally, you can restart the service. For steps how to do this, see

      Configure the Application Identity Service
      . Alternatively, you can disable the AppLocker service using Group Policy instead of locally.

    • Optionally, if you want to update the computers with another set of AppLocker rules (and the service has been enabled), you force a Group Policy update for the revised AppLocker policy. For steps how to do this, see

      Refresh an AppLocker Policy
      .

    There is no Group policy object editor available here. Also
    AppIDSvc
    is stopped and can't be manually started. Error: "The operation could not be completed. The dependency service or group failed to start" due to fact, that AppLocker is not available in Home and Pro edition.

    So why is it blocking the reinstallation, I don't know?
     
    JiriOlsar, Aug 6, 2021
    #3
  4. AvanadeR Win User

    Using AppLocker through GPO disables Teams and Right-Click feature

    AppLocker FileHash

    Hi All,

    I have an issue which I can't find a proper solution for. I'm using AppLocker in an environment which also contains a SIEM solution. What I want to forward to the SIEM solution is 'blocked applications by AppLocker'. The issue is that I don't have enough
    information from the standard events. There's a filename, location etc. but what I really would like is a hash of the file which is blocked. So if mimikatz is renamed to client.exe and run in C:\Temp I can use the hash to see if it's malicious.

    There's an "audit-mode" option in AppLocker which logs the fileHash, but then it doesn't block the application since it's auditing only. I can't create two GPO's which one GPO is set to enforced and the other to audit, because enforced takes precedence over
    the audit and no audit gets logged.

    How do I get the hash of the file and AppLocker to work at the same time?

    I know the "fileHash" property in AppLocker is an Authenticode Hash of the file and I can't get my head around why Microsoft doesn't log a SHA hash for every blocked application.

    With kind regards,
     
    AvanadeR, Aug 6, 2021
    #4
Thema:

Using AppLocker through GPO disables Teams and Right-Click feature

Loading...
  1. Using AppLocker through GPO disables Teams and Right-Click feature - Similar Threads - Using AppLocker through

  2. Question about AppLocker features

    in Windows 10 Gaming
    Question about AppLocker features: I received a stopcode_died error message after setting msconfig to safe mode boot. I had changed some settings directly in applocker>packaged app rules, through the group policy manager as the owner of the computer workstation. What I want to know is what bootup and login...
  3. Question about AppLocker features

    in Windows 10 Software and Apps
    Question about AppLocker features: I received a stopcode_died error message after setting msconfig to safe mode boot. I had changed some settings directly in applocker>packaged app rules, through the group policy manager as the owner of the computer workstation. What I want to know is what bootup and login...
  4. Question about AppLocker features

    in Windows 10 BSOD Crashes and Debugging
    Question about AppLocker features: I received a stopcode_died error message after setting msconfig to safe mode boot. I had changed some settings directly in applocker>packaged app rules, through the group policy manager as the owner of the computer workstation. What I want to know is what bootup and login...
  5. Disable right click drag menu

    in Windows 10 Network and Sharing
    Disable right click drag menu: Hello! So I find this annoying feature on my Windows. Every time I try to right click a file, I accidentally keep dragging it instead of right clicking and then pulls up this menu:How do I disable this feature? Thanks!...
  6. Disable right click drag menu

    in Windows 10 Gaming
    Disable right click drag menu: Hello! So I find this annoying feature on my Windows. Every time I try to right click a file, I accidentally keep dragging it instead of right clicking and then pulls up this menu:How do I disable this feature? Thanks!...
  7. Disable right click drag menu

    in Windows 10 Software and Apps
    Disable right click drag menu: Hello! So I find this annoying feature on my Windows. Every time I try to right click a file, I accidentally keep dragging it instead of right clicking and then pulls up this menu:How do I disable this feature? Thanks!...
  8. Disable Options in Micorosft Office using GPO

    in Windows 10 Ask Insider
    Disable Options in Micorosft Office using GPO: [IMG] Does anyone know how to disable the Options on Microsoft Office using the Group Policy Editor? https://preview.redd.it/lwfi5gb5n0w41.png?width=1440&format=png&auto=webp&s=283d9da0ad5702307945c938e661938d23d07daf submitted by /u/m_beps [link] [comments]...
  9. Use "alt" for right click

    in Windows 10 Ask Insider
    Use "alt" for right click: Especially in Windows explorer, just like win7. submitted by /u/BBQ_Sauce_ [link] [comments] https://www.reddit.com/r/Windows10/comments/fntagd/use_alt_for_right_click/
  10. Mouse Right Click Back Feature

    in Browsers and Email
    Mouse Right Click Back Feature: Hi All, I posted a similar topic a short time ago..nobody ever replied to that, so I thought I'd try again. In internet explorer..when you clicked the right mouse button you were presented with (as I remember) back plus other option's, I posted a similar message in the...