Take a look at:
https://free.blessedness.top/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/delete-an-applocker-rule
You may configure the XML to remove policy (or set as Not Configured) for the one you are looking for.
Remove spesific Applocker rule by name with powershell
Hello,
I trying to remove Default Applocker rules from Local with powershell.
When support teams create a Applocker rule on lacal they select yes for adding Default Rules.
Is there anyway to delete this policy rules with powershell? I only want to delete these rules. not clear all applocker rule.
In applocker xml file it shown like below.
</FilePublisherCondition>
</Conditions></FilePublisherRule><FilePathRule Id="921cc481-6e17-4653-8f75-050b80acca20" Name="(Default Rule) All files located in the Program Files folder"
Description="Allows members of the Everyone group to run applications that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">
<Conditions><FilePathCondition Path="%PROGRAMFILES%*" /></Conditions></FilePathRule><FilePathRule Id="a61c8b2c-a319-4cd0-9690-d2177cad7b51" Name="(Default Rule) All files located in the Windows folder" Description="Allows members of the Everyone group to run applications that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">
<Conditions><FilePathCondition Path="%WINDIR%*" /></Conditions></FilePathRule><FilePathRule Id=
"fd686d83-a829-4351-8ff4-27c7de5755d2" Name="(Default Rule) All files" Description="Allows members of the local Administrators group to run all applications." UserOrGroupSid="S-1-5-32-544" Action="Allow">
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Server | User experience | PowerShell
2 answers
Sort by: Most helpful
-
Reza-Ameri 45,586 Reputation points Volunteer Moderator
2021-05-10T14:46:40.55+00:00 -
Furkan Aykut 1 Reputation point
2021-05-10T15:31:36.293+00:00 Thank you for quick answer Reza. I already read documents. But i have more than 10000+ clients in my domain and some of them have local applocker rules. these applocker rules must stay. I just want to delete which is coming from default rules while making new applocker rule.
I couldn't filter these default applocker rules. If i dont have choice i will try to do compare xml files which are on my clients computer and which has these default rules. But i dont think it is best practice.
For better to understand me i share an example of local default policies.