Remove spesific Applocker rule by name with powershell

Furkan Aykut 1 Reputation point
2021-05-10T13:14:08.167+00:00

Hello,
I trying to remove Default Applocker rules from Local with powershell.
When support teams create a Applocker rule on lacal they select yes for adding Default Rules.
Is there anyway to delete this policy rules with powershell? I only want to delete these rules. not clear all applocker rule.

In applocker xml file it shown like below.

</FilePublisherCondition>
</Conditions></FilePublisherRule><FilePathRule Id="921cc481-6e17-4653-8f75-050b80acca20" Name="(Default Rule) All files located in the Program Files folder"
Description="Allows members of the Everyone group to run applications that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">

<Conditions><FilePathCondition Path="%PROGRAMFILES%*" /></Conditions></FilePathRule><FilePathRule Id="a61c8b2c-a319-4cd0-9690-d2177cad7b51" Name="(Default Rule) All files located in the Windows folder" Description="Allows members of the Everyone group to run applications that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">

<Conditions><FilePathCondition Path="%WINDIR%*" /></Conditions></FilePathRule><FilePathRule Id=
"fd686d83-a829-4351-8ff4-27c7de5755d2" Name="(Default Rule) All files" Description="Allows members of the local Administrators group to run all applications." UserOrGroupSid="S-1-5-32-544" Action="Allow">

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | PowerShell
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Reza-Ameri 45,586 Reputation points Volunteer Moderator
    2021-05-10T14:46:40.55+00:00

    Take a look at:
    https://free.blessedness.top/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule
    You may configure the XML to remove policy (or set as Not Configured) for the one you are looking for.

    0 comments No comments

  2. Furkan Aykut 1 Reputation point
    2021-05-10T15:31:36.293+00:00

    Thank you for quick answer Reza. I already read documents. But i have more than 10000+ clients in my domain and some of them have local applocker rules. these applocker rules must stay. I just want to delete which is coming from default rules while making new applocker rule.

    I couldn't filter these default applocker rules. If i dont have choice i will try to do compare xml files which are on my clients computer and which has these default rules. But i dont think it is best practice.

    For better to understand me i share an example of local default policies.

    95180-capture.png


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.