{"id":6771,"date":"2016-05-09T16:51:07","date_gmt":"2016-05-09T16:51:07","guid":{"rendered":"http:\/\/www.top-password.com\/blog\/?p=6771"},"modified":"2016-05-09T16:51:07","modified_gmt":"2016-05-09T16:51:07","slug":"prevent-other-users-from-accessing-windows-apps-with-applocker","status":"publish","type":"post","link":"https:\/\/www.top-password.com\/blog\/prevent-other-users-from-accessing-windows-apps-with-applocker\/","title":{"rendered":"Prevent Other Users from Accessing Windows Apps with AppLocker"},"content":{"rendered":"<p>AppLocker is a Window&#8217;s built-in application that gives the administrator a very granular control over which applications are allowed to execute and which are blocked for a Windows account. This feature is really useful if you share a computer and don&#8217;t want other users accessing certain applications. <\/p>\n<p>Today we&#8217;ll walk you through how to create rules in AppLocker to prevent other users from accessing certain applications in Windows 10, 8 and 7.<\/p>\n<p><strong>How to Restrict Access to Programs with Windows AppLocker?<\/strong><\/p>\n<ol>\n<li>Press Windows key + R to open the Run dialog box. Type <strong>gpedit.msc<\/strong> and press Enter.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/gpedit.png\" alt=\"gpedit\" width=\"413\" height=\"212\" class=\"alignnone size-full wp-image-6775\" \/><\/p>\n<\/li>\n<li>Under Local Group Policy Editor, navigate to:<br \/>\n\t<code>Computer Configuration -&gt; Windows Settings -&gt; Security Settings -&gt; Application Control Policies -&gt; AppLocker -&gt; Executable Rules<\/code><\/li>\n<li>Right-click on <strong>Executable Rules<\/strong> in the left pane, and then select <strong>Create New Rule<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/applocker.png\" alt=\"applocker\" width=\"600\" height=\"437\" class=\"alignnone size-full wp-image-6776\" \/><\/p>\n<\/li>\n<li>Click <strong>Next<\/strong> to bypass the <em>Before You Begin<\/em> screen. On the <em>Permissions<\/em> page, select <strong>Deny<\/strong> (Click <strong>Allow<\/strong> if you want to restrict what programs other users can access only).\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/permissions-page.png\" alt=\"permissions-page\" width=\"600\" height=\"431\" class=\"alignnone size-full wp-image-6777\" \/><\/p>\n<p>Click on the <strong>Select<\/strong> button to choose the user or groups you want the rule to apply. When it&#8217;s done, click <strong>Next<\/strong> to reach the <em>Conditions<\/em> page.<\/li>\n<li>AppLocker rules can identify programs using the following conditions: <strong>Publisher<\/strong>, <strong>Path<\/strong> and <strong>File hash<\/strong>. Publisher condition relies on the digital signature of the executable file.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/conditions-page.png\" alt=\"conditions-page\" width=\"600\" height=\"432\" class=\"alignnone size-full wp-image-6778\" \/><\/p>\n<p>Here we&#8217;ll choose <strong>File hash<\/strong> because AppLocker can still identify the program even if it&#8217;s renamed or moved.<\/li>\n<li>On the <em>File Hash<\/em> page, click <strong>Browse Files<\/strong> and find the executable file for the application to which you want this rule to apply, or click <strong>Browse Folders<\/strong> if you want the system to calculate a hash for all of the executable files in a folder. Click <strong>Next<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/file-hash-page.png\" alt=\"file-hash-page\" width=\"600\" height=\"437\" class=\"alignnone size-full wp-image-6779\" \/><\/p>\n<\/li>\n<li>Type a name for the rule that will make it easy for you to remember what it is, and then click on <strong>Create<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/name-and-description.png\" alt=\"name-and-description\" width=\"600\" height=\"366\" class=\"alignnone size-full wp-image-6780\" \/><\/p>\n<\/li>\n<li>When prompted to create the default rules, make sure you click <strong>Yes<\/strong>. This is to ensure that the rules you created don&#8217;t block operating system files from running.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/create-default-rules.png\" alt=\"create-default-rules\" width=\"496\" height=\"214\" class=\"alignnone size-full wp-image-6781\" \/><\/p>\n<\/li>\n<li>Now you will see three default rules and the new one you created.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/applocker-rules.png\" alt=\"applocker-rules\" width=\"600\" height=\"418\" class=\"alignnone size-full wp-image-6791\" \/><\/p>\n<p>Restart your computer for the AppLocker rules to come into effect. When you try to run the blocked application, you&#8217;ll receive an error: &#8220;<em>This app has been blocked by group policy. For more information, please contact your system administrator.<\/em>&#8221;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/app-blocked-by-group-policy.png\" alt=\"app-blocked-by-group-policy\" width=\"572\" height=\"139\" class=\"alignnone size-full wp-image-6782\" \/><\/p>\n<\/li>\n<\/ol>\n<p><strong>AppLocker Doesn&#8217;t Work?<\/strong><\/p>\n<p>AppLocker doesn&#8217;t work under either an admin account or a standard account? AppLocker not blocking application even if you set up the executable rule correctly? AppLocker relies on the built-in <strong>Application Identity<\/strong> service, which is normally set to manual startup type by default. Administrators should configure the service to start automatically.<\/p>\n<p>To bring AppLocker back to work, follow these steps to start the Application Identity service:<\/p>\n<ol>\n<li>Press Windows key + R to open the Run dialog box. Type <strong>services.msc<\/strong> and press Enter.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/services-msc.png\" alt=\"services-msc\" width=\"413\" height=\"212\" class=\"alignnone size-full wp-image-6783\" \/><\/p>\n<\/li>\n<li>Right-click on the <strong>Application Identity<\/strong> service, and select <strong>Properties<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/services.png\" alt=\"services\" width=\"600\" height=\"307\" class=\"alignnone size-full wp-image-6784\" \/><\/p>\n<\/li>\n<li>Set the <strong>Startup type<\/strong> to <strong>Automatic<\/strong> and click on the <strong>Start<\/strong> button to run the service.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2016\/05\/application-identity-service.png\" alt=\"application-identity-service\" width=\"420\" height=\"474\" class=\"alignnone size-full wp-image-6785\" \/><\/p>\n<\/li>\n<li>Click on <strong>Apply<\/strong> and then <strong>OK<\/strong>.<\/li>\n<\/ol>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>AppLocker is a Window&#8217;s built-in application that gives the administrator a very granular control over which applications are allowed to execute and which are blocked for a Windows account. This feature is really useful if you share a computer and don&#8217;t want other users accessing certain applications. Today we&#8217;ll walk you through how to create [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,10,1894,3,39],"tags":[2691,2688,2690,2689,2692],"class_list":["post-6771","post","type-post","status-publish","format-standard","hentry","category-others","category-tips-tricks","category-windows-10","category-windows-7","category-windows-8","tag-applocker-block-application","tag-applocker-not-working","tag-block-programs-with-applocker","tag-configure-applocker-group-policy","tag-prevent-windows-program-from-running"],"_links":{"self":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/6771","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/comments?post=6771"}],"version-history":[{"count":9,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/6771\/revisions"}],"predecessor-version":[{"id":6792,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/6771\/revisions\/6792"}],"wp:attachment":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/media?parent=6771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/categories?post=6771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/tags?post=6771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}