Help with disabling App Control for Business policy and Code Integrity #974
Unanswered
brunoshure
asked this question in
Q&A
Replies: 1 comment 6 replies
-
|
Hi,
Depending on your hardware config and setup, there can be different ways to disable it. This doc goes over the UEFI lock scenario: https://github.com/HotCakeX/Harden-Windows-Security/wiki/Device-Guard |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment

Uh oh!
There was an error while loading. Please reload this page.
-
Hello!
I need help and I can't figure out what I'm doing wrong. I've read the wiki already and some things didn't work as intended.
Regarding App Control for Business and Code Integrity, here's the way they are set up:
How would you change from
EnforcedtoAudit, at least in Kernel-mode, since User-mode is already onAudit?I have read a bunch of documentation from Microsoft and according to them if the policy is
Enforcedyou can't just disable it, you need to:First - Change the policy to an
Auditpolicy (it apparently needs to have the same ID);Second - Then you can disable it (after rebooting).
I basically need to change an existing policy or create a new one that has
AUDITmode and deploy it.This is where my problems start!
I've tried using App Control Wizard to create an
AllowAll.xmlpolicy and deploy it using Group Policy, to no avail. Then I found this app - AppControl Manager - which makes this job much easier. I can create, edit and deploy policies in a simple manner. But even then I can't properly configure these policies or edit existing ones to my liking. I'm probably doing something wrong. The app also doesn't allow me to edit some of the deployed policies. I don't know if this is an app problem or a problem with my policies.Policies.mp4
As you can see, some of the policies show some type of error and the "Remove" button is greyed out.
I appreciate if someone could shed some light on this issue for me. It would really help, because I'm messing with some things on this test install and I need to disable these "features" like VBS and Code Integrity. Thanks in advance!
Beta Was this translation helpful? Give feedback.
All reactions