Alekhya Jupudi 941f089142 TASK 5358645 : Batch 03, Windows 11 Inclusion updates
Third batch of Windows 11 Inclusion updates under Windows-defender-application-control folder. (I've also made some changes to few words as per Acrolinx suggestions to meet the PR criteria).
2021-08-24 14:31:46 +05:30

3.8 KiB

title, description, ms.assetid, ms.reviewer, ms.author, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, ms.localizationpriority, author, manager, audience, ms.collection, ms.topic, ms.date, ms.technology
title description ms.assetid ms.reviewer ms.author ms.prod ms.mktglfcycl ms.sitesec ms.pagetype ms.localizationpriority author manager audience ms.collection ms.topic ms.date ms.technology
Deploy the AppLocker policy into production (Windows) This topic for the IT professional describes the tasks that should be completed before you deploy AppLocker application control settings. ebbb1907-92dc-499e-8cee-8e637483c9ae dansimp m365-security deploy library security medium dansimp dansimp ITPro M365-security-compliance conceptual 09/21/2017 mde

Deploy the AppLocker policy into production

Applies to

  • Windows 10
  • Windows 11
  • Windows Server 2016 and above

Note

Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the Defender App Guard feature availability.

This topic for the IT professional describes the tasks that should be completed before you deploy AppLocker application control settings.

After successfully testing and modifying the AppLocker policy for each Group Policy Object (GPO), you are ready to deploy the enforcement settings into production. For most organizations, this means switching the AppLocker enforcement setting from Audit only to Enforce rules. However, it is important to follow the deployment plan that you created earlier. For more info, see the AppLocker Design Guide. Depending on the needs of different business groups in your organization, you might deploy different enforcement settings for linked GPOs.

Understand your design decisions

Before you deploy an AppLocker policy, you should determine:

For info about how AppLocker deployment is dependent on design decisions, see Understand AppLocker policy design decisions.

AppLocker deployment methods

If you have configured a reference device, you can create and update your AppLocker policies on this device, test the policies, and then export the policies to the appropriate GPO for distribution. Another method is to create the policies and set the enforcement setting on Audit only, then observe the events that are generated.

See also