Тёмный

Basics of deploying Windows AppLocker using Intune 

Robert Crane
Подписаться 9 тыс.
Просмотров 15 тыс.
50% 1

Опубликовано:

 

30 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 31   
@__whitehawk__
@__whitehawk__ 2 года назад
Awesome tutorial man. Worked like a charm for my AD!
@idatoo
@idatoo 3 года назад
great video! can I whitelist a path? what i mean to say is, I would like a particular path that is exempt from applocker policies.
@directorcia
@directorcia 3 года назад
You can whatever you wish with the appropriate policy.
@Schnitzer325ci
@Schnitzer325ci 2 года назад
Thanks as always Rob 👍
@cybercole777
@cybercole777 2 года назад
Great video thanks!
@krishnakps3436
@krishnakps3436 3 года назад
how to block installation of all exe, msi applications from running
@directorcia
@directorcia 3 года назад
You set the policy as shown and none will run.
@Endymionem
@Endymionem Год назад
@@directorcia what about blocking specific .exe files only? I mean as per tutorial, which is great, and thank you for your effort...the video describes blocking all .exe files right? and should I choose a specific .exe file it would work the same?
@directorcia
@directorcia Год назад
@@Endymionem yes
@piersonmoran7324
@piersonmoran7324 2 года назад
Hey Robert, how do you deploy the Managed Installer Applocker policy via intune. Is there a Custom URI for this? Like "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/Native/ManagedInstaller/Policy"? As you separate each policy . How do you deploy through Intune, the ? The Documents on MS website only mention how deploy through GPO or running a Script. cheers mate.
@directorcia
@directorcia 2 года назад
I have no idea I'm sorry. Call MS.
@sanojvettath5623
@sanojvettath5623 Год назад
Hello Robert, The policy worked for me unfortunately its blocking ms teams and wont allow the admin to execute MSI packages
@directorcia
@directorcia Год назад
U can adjust the policy to accommodate Teams
@sanojvettath5623
@sanojvettath5623 Год назад
@@directorcia Thanks
@kanjoracer4296
@kanjoracer4296 2 года назад
Great video, exactly what i was looking for. What is the value I have to insert for msi?
@directorcia
@directorcia 2 года назад
Sorry? value for MSI?
@nvidiashield495
@nvidiashield495 2 года назад
I think he’s asking about the text you copied from your .xml file into the string window . You showed how to block .exe & .appx only. The .appx is 9 lines of text. To block .Msi do you just use that 1 line of text ?
@jamesmax7721
@jamesmax7721 2 года назад
@@nvidiashield495 😎
@AN-ic7wp
@AN-ic7wp 3 года назад
Hey Mate. Fantastic video and some great clear explanations. Can I ask what resource you used to locate the correct OMA-URA?
@directorcia
@directorcia 3 года назад
docs.microsoft.com/en-us/windows/client-management/mdm/applocker-csp
@roshanjangid6336
@roshanjangid6336 2 года назад
Can we define a list of allowed software there and block all others?
@directorcia
@directorcia 2 года назад
Yes
@gokulrdev6428
@gokulrdev6428 2 года назад
Excellent video.. I tried to create one. But in deployment status it is showing remediated.. Do you know why?
@directorcia
@directorcia 2 года назад
Sorry, no idea
@inlinesix6694
@inlinesix6694 3 года назад
Thanks but how would you automate the reconfiguration of the Windows Service (with Intune) so you can actually deploy this out?
@directorcia
@directorcia 3 года назад
Use PowerShell and the Microsoft Graph
@inlinesix6694
@inlinesix6694 3 года назад
@@directorcia thanks. I created a small power shell script in Intune that turns on the service and sets it to automatic start. It’s working good so far.
@directorcia
@directorcia 3 года назад
@@inlinesix6694 If u apply AppLocker via the Intune process I highlighted using the OMI URL, everything, including starting the service, is done for you. If you use Intune for AppLocker via the method I show there should be no need for additional scripting as Intune handles the lot. I would also suggest that you really should be using WDAC rather than AppLocker as that is newer technology amd WDAC is what MS recommends you use.
@inlinesix6694
@inlinesix6694 3 года назад
@@directorcia you are right. I tried without the power shell script and all is working. I was considered MDAC but just have not spent the time researching how much is involved to just block google chrome from installing. The applocker was quick and easy though for my need.
@khanhphanduy6097
@khanhphanduy6097 2 года назад
Thanks for video. Please tell me more. What is condition need to configuration an Applocker? Ex: AD on-prime, PC joined domain? or Just Intune. Thank you
@directorcia
@directorcia 2 года назад
You need to use something to push policy, Intune, Endpoint Manager, Group policy etc.
Далее
Configure AppLocker in Intune
22:19
Просмотров 11 тыс.
Stay protected with Windows Security Applocker
17:47
Просмотров 13 тыс.
КВН 2024 Встреча выпускников
2:00:41
БЕЛКА ЗВОНИТ ДРУГУ#cat
00:20
Просмотров 788 тыс.
Windows AppLocker basics
11:27
Просмотров 46 тыс.
Crazy easy Intune App Deployment with Pckgr
19:26
Просмотров 35 тыс.
Disable These 3 Windows Settings Now! (For Security)
12:26
Windows Defender Application Control (WDAC) Basics
9:07
КВН 2024 Встреча выпускников
2:00:41