Applocker
Sometimes Applocker gets itself into a knot and gets stuck in Enforcing Mode. Here are the full steps to reset Applocker and set it up properly.
To fix this, follow the steps attached from https://en.it-pirate.eu/windows-10-applocker-policies-still-affect-disabling-service/
Then, follow these steps:
Log in as Administrator.
Windows + R > services.msc > double-click Application Identity > change Startup type to "Manual".
Reset applocker (from https://en.it-pirate.eu/windows-10-applocker-policies-still-affect-disabling-service/)
Insert the Default Windows Rules to make sure you don't cut yourself off:
Windows + R > secpol.msc > Application Control Policies > AppLocker
Executable Rules > Create Default Rules
Windows Installer Rules > Create Default Rules
Script Rules > Create Default Rules
Packaged App Rules > Create Default Rules
Unblock AppLocker for Local Administrator user only (if required):
Executable Rules > right-click "(Default) Allow All" > change user to "Administrator"
Windows Installer Rules > right-click "(Default) Allow All" > change user to "Administrator"
Script Rules > right-click "(Default) Allow All" > change user to "Administrator"
Turn on and test in Audit Mode:
Windows + R > secpol.msc > Application Control Policies > AppLocker > Configure Rule enforcement > change all to "Audit rules".
Windows > "Command" > right-click "Command" > Run as Administrator > type "gpupdate /force" and press enter.
Reboot computer. <-- Make sure you do this step!!
Log in as Administrator.
Windows + R > services.msc > right-click Application Identity > Start
Copy c:\windows\write.exe to desktop.
On the desktop, double-click write.exe. Write will open.
Log in as User.
Copy c:\windows\write.exe to desktop.
On the desktop, double-click write.exe. Write will open.
Windows + R > eventvwr.msc > Applications and Services Logs > Microsoft > Windows > AppLocker
Check the log to see if write.exe was blocked. If so, then Applocker is working correctly.
Check the log to make sure that Administrator executables are not being blocked. If so then start from Step 1.
Log out of User.
Log in as Administrator.
Turn on Enforcing Mode:
Windows + R > secpol.msc > Application Control Policies > AppLocker > Configure Rule enforcement > change all to "Enforce rules".
Windows > "Command" > right-click "Command" > Run as Administrator > type "gpupdate /force" and press enter.
Reboot computer. <-- Make sure you do this step!!
Log in as Administrator.
Windows + R > services.msc > right-click Application Identity > Start
On the desktop, double-click write.exe. Write will open.
Log in as a User.
On the desktop, double-click write.exe. Write will NOT open and an AppLocker block dialog box will appear. If so, then AppLocker is working properly.
Log out of User.
Add any additional path rules for applications that are not in Program Files:
Log in as Administrator.
Windows + R > secpol.msc > Application Control Policies > AppLocker > Executable Rules
Add any extra executables here.
Windows > "Command" > right-click "Command" > Run as Administrator > type "gpupdate /force" and press enter.
Reboot computer. <-- Make sure you do this step!!
Log in as Administrator.
Windows + R > services.msc > right-click Application Identity > Start
Ensure that no applications are blocked.
Log in as User.
Check that the required applications work.
Add ACSC block rules (see https://www.cyber.gov.au/resources-business-and-government/maintaining-devices-and-systems/system-hardening-and-administration/system-hardening/implementing-application-control):
After you are sure things are working, you can turn on Applocker automatically on boot. WARNING this has the potential to block you from ever accessing the computer. Ensure you have a full backup before performing this step.
Windows + R > services.msc > double-click Application Identity > change Startup type to "Automatic".
Windows > "Command" > right-click "Command" > Run as Administrator > type "gpupdate /force" and press enter.
Reboot computer. <-- Make sure you do this step!!
Log in as Administrator.
Ensure that no applications are blocked.
Log in as a general user.
Check that the required applications work.