How to limit software operation through application control policies?

  
                                    

1. Open the Control Panel and select the Administrative Tools. As shown below:

2. Select the local security policy. As shown below:

3. After opening the local security policy, open “application control policy>--click “Applocker”. As shown below:

4, open Applocker as shown below:

5, before setting the rule to confirm whether the Application Identity service is set to start automatically, only the service is started, Applocker is set Only take effect, open the same method as step 1, open the search and enter “Services.msc”, open the service settings interface. As shown below:

6. Select Auto and click Start. As shown below:

7, you can set up specific projects, first select the configuration mandatory rules. As shown below:

8, you can see the mandatory tab, you can set whether each rule set enforces the applocker rule, the option has mandatory rules and only audited, set to mandatory rules, set The rule will be enforced. After it is set to audit only, the set rule will be recorded in the log after it takes effect, but it will not take effect. As shown below:

9. Take the executable rules as an example, and select executable rules on the Applocker interface. As shown below:

10, right click to select a new rule. As shown below:

11. Click “Next”. As shown below:

12. Set whether the rule allows or deny the rule, and you can select the user or user group for the rule. As shown below:

13, set the conditions, the conditions are divided into three, the publisher, the path and the file hash, according to the needs. As shown below:

14, using the file hash as an example, disable the notes mailbox program. First select “file hash” as shown below:

15. Select the application that uses the rule setting, for example, “notes.exe”, select and click Next. As shown below:

16. Enter the name of the rule and the corresponding description, click Create. As shown below:

17. The program rules have been established and will take effect after restart.

Copyright © Windows knowledge All Rights Reserved