windows-itpro-docs/windows/keep-secure/configure-an-applocker-policy-for-audit-only.md
Jan Backstrom f046a5fec0 tagging update
change W10 to w10 (lower case), add security pagetype to various
2016-05-26 17:07:01 -07:00

2.1 KiB

title, description, ms.assetid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, author
title description ms.assetid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype author
Configure an AppLocker policy for audit only (Windows 10) This topic for IT professionals describes how to set AppLocker policies to Audit only within your IT environment by using AppLocker. 10bc87d5-cc7f-4500-b7b3-9006e50afa50 w10 deploy library security brianlic-msft

Configure an AppLocker policy for audit only

Applies to

  • Windows 10

This topic for IT professionals describes how to set AppLocker policies to Audit only within your IT environment by using AppLocker.

After AppLocker rules are created within the rule collection, you can configure the enforcement setting to Enforce rules or Audit only.

When AppLocker policy enforcement is set to Enforce rules, rules are enforced for the rule collection and all events are audited. When AppLocker policy enforcement is set to Audit only, rules are only evaluated but all events generated from that evaluation are written to the AppLocker log.

Note:  There is no audit mode for the DLL rule collection. DLL rules affect specific apps. Therefore, test the impact of these rules first before deploying them to production. To enable the DLL rule collection, see Enable the DLL rule collection.   You can perform this task by using the Group Policy Management Console for an AppLocker policy in a Group Policy Object (GPO) or by using the Local Security Policy snap-in for an AppLocker policy on a local computer or in a security template. For info how to use these MMC snap-ins to administer AppLocker, see Administer AppLocker.

To audit rule collections

  1. From the AppLocker console, right-click AppLocker, and then click Properties.
  2. On the Enforcement tab, select the Configured check box for the rule collection that you want to enforce, and then verify that Audit only is selected in the list for that rule collection.
  3. Repeat the above step to configure the enforcement setting to Audit only for additional rule collections.
  4. Click OK.