AppLocker Policies Design Guide
Published: August 19, 2009
Updated: June 21, 2012
Applies To: Windows 7, Windows 8, Windows Server 2008 R2, Windows Server 2012
This topic for the IT professional introduces the design and planning steps required to deploy application control policies by using AppLocker which was introduced in Windows Server® 2008 R2 and Windows® 7.
This guide provides important designing and planning information for deploying application control policies by using AppLocker. It is intended for security architects, security administrators, and system administrators. Through a sequential and iterative process, you can create an AppLocker policy deployment plan for your organization that will address your specific application control requirements by department, organizational unit, or business group.
This guide does not cover the deployment of application control policies by using Software Restriction Policies (SRP). However, SRP is discussed as a deployment option in conjunction with AppLocker policies. For information about these options, see Determining Your Application Control Objectives.
To understand if AppLocker is the correct application control solution for your organization, see Understanding AppLocker Policy Design Decisions.
For an HTML or PDF downloadable version of this topic, select the Lightweight view, click the drop-down caret on the printer icon, then click Print Multiple Copies. Follow the instructions to download one or a collection of topics.
This guide contains the following topics:
Understanding the AppLocker Policy Deployment Process
Understanding AppLocker Policy Design Decisions
Determining Your Application Control Objectives
Creating the List of Applications Deployed to Each Business Group
Selecting the Types of Rules to Create
Determining Group Policy Structure and Rule Enforcement
Planning for AppLocker Policy Management
Creating Your AppLocker Planning Document
After careful design and detailed planning, the next step is to deploy AppLocker policies. AppLocker Policies Deployment Guide (http://go.microsoft.com/fwlink/?LinkId=160260) covers the creation and testing of policies, deploying the enforcement setting, and managing and maintaining the policies.