Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Auditing AppLocker while SRP is active

$
0
0

So our domain currently has numerous Software Restriction Policies in place for assorted departments, and we want to migrate to AppLocker.  The current plan is as follows:

  1. Create an AppLocker GPO for each of the affected departments, independent of the SRP GPOs.  Since all our SRP GPOs at the moment are path-based and AppLocker does path-based rules, we figure this is a 1:1 migration.
  2. Set the AppLocker policies to audit only.
  3. Let these run on the domain for X amount of time while monitoring the event logs to see if what people are doing and what we see coincide with one another.
  4. Remove SRP GPOs when satisfied.

Now, I understand that in Windows, AppLocker policies supersede SRPs in terms of enforcement.  Say I create a SRP GPO which requires whitelisting ("allow list mode" as defined in the documentation), and I create an AppLocker policy which does the same, only in audit mode.  If I run an app that isn't whitelisted, does it:

a) trigger the AppLocker audit GPO, which makes a note of it in the event log, and then skips the SRP GPO and runs the app

or

b) trigger the AppLocker audit GPO, which makes a note of it in the event log, and then check the SRP GPO which then denies the application from being run?

Any help on this subject would be greatly appreciated.


Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>