having a hard time with getting app security rules...
# citrix-wem
s
having a hard time with getting app security rules to apply. I know its kind bad to do powershell blocking but im trying it anyways. Problem is I can see in the applocker event log that there was a policy applied, but its not being effective on the user I assigned the app security rule too. I have it set to enforce and merge, blocking the hash for powershell. Where eelse can i look for why this isnt working? Or is there something else I need to enable?
d
I've never used Applocker, for blocking Powershell since you need to specify both "normal Powershell and ISE, and its located different places and with Terminal its even worse. I've tried hiding it via Citrix App Access Control in User Profile management. It's possible to hide/block for specific AD Groups. It also blocks inside Terminal. FSLogix App Masking is also working. Don't know if it blocks in Terminal aswell.
s
thanks, how are you doing it with app access control? that was something i never followed through on with server 2025, the terminal app would block cmd but not powershell for me
d
I'd use the Rule Generator and paste it into WEM/Profile Management. These are the objects I hide: Folder %SystemRoot%\system32\WindowsPowerShell\v1.0 Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerShell Registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PowerShell