Windows-itpro-docs: AppLocker DLL Audit Mode

Created on 6 Jun 2018  Â·  10Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

The following implies that there is not an audit mode for the DLL rule collection, however, so far as I can tell the audit function for DLL rules works as intended in Windows 10 _Version 10.0.16299.461_

Note: There is no audit mode for the DLL rule collection. DLL rules affect specific apps. Therefore, test the impact of these rules first before deploying them to production. To enable the DLL rule collection, see Enable the DLL rule collection.

The below screenshot shows DLL rule collection set to audit with AppLocker logs showing audit mode functioning as expected for DLLs

screen shot 2018-06-05 at 6 06 08 pm


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

application control security

Most helpful comment

@mypil yes I did, sorry. @vgrsec thanks for the feedback and sorry for delay.

fyi you can check topic history, here for example: https://github.com/MicrosoftDocs/windows-itpro-docs/commit/7ebd39f45254da85432b45ae1d1bdba0861f2817#diff-921fa7bd4471960cd90002c8fa5c0ef6

All 10 comments

@vgrsec thanks for reporting this. We are confirming with the engineering team if there was any change here.

FYI testing on Server 2012 R2, DLL Audit Mode works as expected as well.

I believe audit mode worked on 2008/7 Enterprise as well, however, I don't have ISOs handy to test and report.

screen shot 2018-06-08 at 4 36 18 pm

@officedocsbot assign @mypil

@Justinha - Do you have any updates on this issue?

Thanks.

@mypil yes, sorry for delay. Can you assist with a pull request to remove the note in question. @vgrsec Thanks again for reporting and sorry to let this slip.

@Justinha - Yes, I will be glad to assist you with this. I have already discussed with @Malind19 to create the PR for this issue. Thank you.

@mypil I cannot find such section in the content article. Can you kindly check.

@Justinha - I checked on the article but could not find the "Note section" indicated on this issue.

Is it possible that it was already removed? Can you please advise @Malind19 on which portion to edit in the article so he can create a PR for this?

Thank you.

@mypil yes I did, sorry. @vgrsec thanks for the feedback and sorry for delay.

fyi you can check topic history, here for example: https://github.com/MicrosoftDocs/windows-itpro-docs/commit/7ebd39f45254da85432b45ae1d1bdba0861f2817#diff-921fa7bd4471960cd90002c8fa5c0ef6

Commit https://github.com/MicrosoftDocs/windows-itpro-docs/commit/7ebd39f45254da85432b45ae1d1bdba0861f2817 is sufficient reference for the change.
I presume it can be a lot to remember or look up
if you want to reference or close issues in all commits.
(Thank you for the follow-up, however delayed.)

Was this page helpful?
0 / 5 - 0 ratings

Related issues

arcotek-ltd picture arcotek-ltd  Â·  3Comments

ang216 picture ang216  Â·  3Comments

illfated picture illfated  Â·  3Comments

zjalexander picture zjalexander  Â·  3Comments

ruffy91 picture ruffy91  Â·  3Comments