
While AppLocker has been around since Windows 7 and Windows Server 2008 R2, I have rarely found the solution in enterprises. The main reason was always that the implementation is very time and resource consuming and that you must constantly maintain a whitelist. This is a bummer, because the security gain is enormous when a solution like AppLocker is used. If you deal with the AppLocker rules intensively and have developed a good concept at the beginning, you will realize that you do not have to adjust the rule regularly and that the operation is not as complex as you thought.
This blog article shows the important things to consider when implementing AppLocker, how to create a usable basic ruleset that requires minimal maintenance, and how to manage with Microsoft Intune.
- Application whitelisting technology overview
- AppLocker basic recommendations
- AppLocker deployment considerations
- AppLocker OS Requirements
- AppLocker AppIDSvc Service Requirements
- Configure AppLocker and start with Audit Only Mode
- Configure Basic Ruleset
- Exceptions
- AaronLocker
- AppLocker deployment with Microsoft Intune
- Event monitoring
- Configure Enforce Mode