AppLocker maintains a cache to store the file attributes of the applications that are installed on a computer. AppLocker uses this cache to look up the file attributes quickly every time that you start an application, instead of computing those attributes again. Introduction to Applocker What is applocker Policy? Windows Applocker is a function that was introduced in home windows 7 and windows server 2008 r2 as a method to restrict the usage of unwanted Programs. Windows AppLocker lets administrators control which executable files are denied or allowed to be run.
Applocker is another Level of security and the purpose is to restrict or allow the access to software in specific group of users.
Today lot of application aren't need administrator access to run. As IT Pro this is a threat for your environment.
While install and configure Applocker can increase the cybersecurity and protect your data from any unathorise access.
If you are thinking why to use Applocker the answer is here.
You can use it to protected against unwanted software , Software standardization , Software management.
If you want to more details you can read the AppLocker policy use scenarios in Microsoft Docs.
Today i will install and Deploy through GPO Applocker in specific Servers.
Applocker can be deploy in the following Windows Versions
- Windows 10 Enterprise
- Windows Server 2012,2016,2019
So let's start !!
- Before start to implement Applocker you must be know exactly which Applications must be allow to run.
- This is the most important step because if you try to apply Applocker without note down what Applications must be allow then you will create lot of problems in your users and the daily operation of your company.
- In case that you are not sure 100% which is the Applications that must be allow you can use Applocker in Audit Mode to identify all the applications.
How to enable Applocker
Windows Application Locker
- Login in the Domain Controller and open the Group Policy Management.
- Right click in the Organization Until that you want to create the Applocker Policy and select Create a GPO in this Domain and link it here.