Basics of deploying Windows AppLocker using Intune

Поділитися
Вставка
  • Опубліковано 3 гру 2024

КОМЕНТАРІ • 31

  • @__whitehawk__
    @__whitehawk__ 2 роки тому +2

    Awesome tutorial man. Worked like a charm for my AD!

  • @Schnitzer325ci
    @Schnitzer325ci 2 роки тому +1

    Thanks as always Rob 👍

  • @idatoo
    @idatoo 3 роки тому +1

    great video! can I whitelist a path? what i mean to say is, I would like a particular path that is exempt from applocker policies.

    • @directorcia
      @directorcia  3 роки тому

      You can whatever you wish with the appropriate policy.

  • @AN-ic7wp
    @AN-ic7wp 3 роки тому

    Hey Mate. Fantastic video and some great clear explanations. Can I ask what resource you used to locate the correct OMA-URA?

    • @directorcia
      @directorcia  3 роки тому +1

      docs.microsoft.com/en-us/windows/client-management/mdm/applocker-csp

  • @cybercole777
    @cybercole777 3 роки тому +1

    Great video thanks!

  • @kanjoracer4296
    @kanjoracer4296 3 роки тому

    Great video, exactly what i was looking for. What is the value I have to insert for msi?

    • @directorcia
      @directorcia  3 роки тому

      Sorry? value for MSI?

    • @nvidiashield495
      @nvidiashield495 2 роки тому

      I think he’s asking about the text you copied from your .xml file into the string window . You showed how to block .exe & .appx only.
      The .appx is 9 lines of text. To block .Msi do you just use that 1 line of text ?

    • @jamesmax7721
      @jamesmax7721 2 роки тому

      @@nvidiashield495 😎

  • @piersonmoran7324
    @piersonmoran7324 2 роки тому

    Hey Robert, how do you deploy the Managed Installer Applocker policy via intune. Is there a Custom URI for this? Like "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/Native/ManagedInstaller/Policy"? As you separate each policy . How do you deploy through Intune, the ?
    The Documents on MS website only mention how deploy through GPO or running a Script.
    cheers mate.

    • @directorcia
      @directorcia  2 роки тому

      I have no idea I'm sorry. Call MS.

  • @inlinesix6694
    @inlinesix6694 3 роки тому

    Thanks but how would you automate the reconfiguration of the Windows Service (with Intune) so you can actually deploy this out?

    • @directorcia
      @directorcia  3 роки тому

      Use PowerShell and the Microsoft Graph

    • @inlinesix6694
      @inlinesix6694 3 роки тому

      @@directorcia thanks. I created a small power shell script in Intune that turns on the service and sets it to automatic start. It’s working good so far.

    • @directorcia
      @directorcia  3 роки тому +1

      @@inlinesix6694 If u apply AppLocker via the Intune process I highlighted using the OMI URL, everything, including starting the service, is done for you. If you use Intune for AppLocker via the method I show there should be no need for additional scripting as Intune handles the lot. I would also suggest that you really should be using WDAC rather than AppLocker as that is newer technology amd WDAC is what MS recommends you use.

    • @inlinesix6694
      @inlinesix6694 3 роки тому +1

      @@directorcia you are right. I tried without the power shell script and all is working. I was considered MDAC but just have not spent the time researching how much is involved to just block google chrome from installing. The applocker was quick and easy though for my need.

  • @krishnakps3436
    @krishnakps3436 3 роки тому +1

    how to block installation of all exe, msi applications from running

    • @directorcia
      @directorcia  3 роки тому +1

      You set the policy as shown and none will run.

    • @Endymionem
      @Endymionem Рік тому

      @@directorcia what about blocking specific .exe files only? I mean as per tutorial, which is great, and thank you for your effort...the video describes blocking all .exe files right? and should I choose a specific .exe file it would work the same?

    • @directorcia
      @directorcia  Рік тому

      @@Endymionem yes

  • @khanhphanduy6097
    @khanhphanduy6097 2 роки тому

    Thanks for video. Please tell me more. What is condition need to configuration an Applocker? Ex: AD on-prime, PC joined domain? or Just Intune. Thank you

    • @directorcia
      @directorcia  2 роки тому

      You need to use something to push policy, Intune, Endpoint Manager, Group policy etc.

  • @sanojvettath5623
    @sanojvettath5623 Рік тому

    Hello Robert, The policy worked for me unfortunately its blocking ms teams and wont allow the admin to execute MSI packages

  • @roshanjangid6336
    @roshanjangid6336 3 роки тому

    Can we define a list of allowed software there and block all others?

  • @gokulrdev6428
    @gokulrdev6428 2 роки тому

    Excellent video.. I tried to create one. But in deployment status it is showing remediated.. Do you know why?