Project

General

Profile

Actions

Bug #11084

open

product-uem 7.0.0 GA - Task #12355: windows App locker policy related issues

Windows App Locker policy is not working

Added by Navod Zoysa 10 months ago. Updated about 10 hours ago.

Status:
QA
Priority:
High
Assignee:
Start date:
18/02/2025
Due date:
18/02/2025 (Due in 0 days)
% Done:

100%

Estimated time:
Device Type:
Windows
Component:
Type:
Windows

Description

Windows App Locker policy to allow / disallow certain apps.
Related Ticket: https://roadmap.entgra.net/issues/9309

https://docs.entgra.io/uem/6.2.0/policies/#app-locker-policy
https://learn.microsoft.com/en-us/windows/client-management/mdm/applocker-csp

Additional information:
[1]

How to get details of an app in windows: https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/find-a-pfn-for-per-app-vpn

EX:
Get-AppxPackage *<app_name>
consider this app: https://apps.microsoft.com/detail/9wzdncrfhvqv?hl=en-us&gl=LK
you can find the details by: Get-AppxPackage *Notes-

Payload of the policy: [2]

EX: Sample payload:
"featureCode": "APP_LOCKER",
"deviceType": "windows",
"content":[{
"id": "b1ad59a9-ae0b-4642-b385-c312d060ff45",
"name": "FIREFOX.EXE, version 68.0.0.0 and above, in FIREFOX, from O=MOZILLA CORPORATION, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US",
"type": "Exe",
"description": "",
"userOrGroupSid": "S-1-1-0",
"publisherName": "O=MOZILLA CORPORATION, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US",
"productName": "FIREFOX",
"binaryName": "FIREFOX.EXE",
"highSection": "*",
"lowSection": "68.0.0.0",
"enforcementMode": "x",
"action": "Deny"
}, {
"id": "351d769f-6aef-4049-b3d2-0302ef10b530",
"name": "CHROME.EXE, version 76.0.0.0 and above, in GOOGLE CHROME, from O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US",
"type": "Exe",
"description": "",
"userOrGroupSid": "S-1-1-0",
"publisherName": "O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US",
"productName": "GOOGLE CHROME",
"binaryName": "CHROME.EXE",
"highSection": "*",
"lowSection": "76.0.0.0",
"enforcementMode": "x",
"action": "Deny"
}
]

[2] {"policyName":"Windows App Locker Policy","description":"Windows App Locker Policy","active":true,"compliance":"enforce","ownershipType":null,"policyType":"GENERAL","profile":{"profileName":"Windows App Locker Policy","deviceType":"windows","profileFeaturesList":[{"featureCode":"APP_LOCKER","deviceType":"windows","content":{"appLockerContent":[{"publisherName":"CN=D23A8018-0943-4207-B03D-2E5979D9A260","name":"22944SamJarawan.-MyNotes-","id":"9WZDNCRFHVQV","type":"*","productName":"*","binaryName":"*","highSection":"*","lowSection":"0.0.0.0"}]},"correctiveActions":[]}]},"deviceGroups":[{"id":14,"name":"Test Group"}],"roles":["ANY"],"users":[]}


Files

image (1).png (222 KB) image (1).png [1] Arshana Atapattu, 26/06/2024 02:20 PM
Actions #1

Updated by Viranga Gunarathna 9 months ago

  • Status changed from New to QA
Actions #2

Updated by Arshana Atapattu 8 months ago

  • Due date set to 26/06/2024
Actions #3

Updated by Arshana Atapattu 8 months ago

  • Description updated (diff)
Actions #4

Updated by Arshana Atapattu 8 months ago

  • Description updated (diff)
Actions #5

Updated by Arshana Atapattu 8 months ago

Actions #6

Updated by Arshana Atapattu 8 months ago

  • Due date changed from 26/06/2024 to 07/07/2024
Actions #7

Updated by Arshana Atapattu 7 months ago

  • Project changed from product-uem 6.2.0 GA to product-uem 6.3.0 GA
Actions #8

Updated by Arshana Atapattu 4 months ago

  • Project changed from product-uem 6.3.0 GA to product-uem 7.0.0 GA
  • Subject changed from QA - Windows App Locker policy to Windows App Locker policy is not working
  • Description updated (diff)
  • Status changed from QA to New
  • Private changed from No to Yes
Actions #9

Updated by Arshana Atapattu 4 months ago

  • Description updated (diff)
  • Assignee deleted (Arshana Atapattu)
Actions #10

Updated by Arshana Atapattu 4 months ago

  • Private changed from Yes to No
Actions #11

Updated by Navod Zoysa 3 months ago

  • Tracker changed from Task to Bug
  • Assignee set to Pramila Niroshan
Actions #12

Updated by Navod Zoysa 3 months ago

  • Assignee changed from Pramila Niroshan to Sathira Perera
Actions #13

Updated by Navod Zoysa 3 months ago

  • Subtask #11840 added
Actions #14

Updated by Sathira Perera 2 months ago

  • Status changed from New to Implementation
Actions #15

Updated by Arshana Atapattu 2 months ago

  • Subtask deleted (#11840)
Actions #16

Updated by Arshana Atapattu 2 months ago

  • Parent task set to #12355
Actions #17

Updated by Lasantha Dharmakeerthi 28 days ago

  • Project changed from product-uem 7.0.0 GA to product-uem 7.1.0 GA
Actions #18

Updated by Navod Zoysa about 13 hours ago

  • Assignee changed from Sathira Perera to Navod Zoysa
  • Priority changed from Medium to High
Actions #19

Updated by Navod Zoysa about 11 hours ago

  • Due date set to 18/02/2025
  • Status changed from Implementation to QA
  • Start date changed from 28/08/2024 to 18/02/2025
  • % Done changed from 0 to 100
  • Device Type set to Windows

Fixes with https://github.com/entgra-proprietary/emm-proprietary-plugins/pull/108

Refer [1] to generate the applocker rule collection.

Chrome browser was used to test as the blocking application:

Application ID Application Name Description User or Group Sid Publisher Name Product Name Binary Name High Section Low Section Action
1ad2e4ad-87e3-4e3d-8367-bd08a8e61656 Chrome This will block chrome S-1-1-0 O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US GOOGLE CHROME CHROME.EXE * * DENY

[1] - https://cloudinfra.net/how-to-implement-applocker-using-intune/

Actions #20

Updated by Navod Zoysa about 10 hours ago

  • Project changed from product-uem 7.0.0 GA to product-uem 6.4.0 GA
Actions

Also available in: Atom PDF