225k views
5 votes
Why is it necessary to start the application identity service before the applocker rules take effect?

1 Answer

3 votes
because applocker uses the application identity service to verify attributes of a file, you must configure it to start automatically. in one GPO that applies applocker rules, the Application Identity service determines and verifies the identity of an application. stopping this service will prevent Applocker policies from being enforced.
User Michael Hellein
by
7.0k points