question

Dan13-3438 avatar image
0 Votes"
Dan13-3438 asked Dan13-3438 commented

AppLocker controlling services running as a service account

Hello,

I'm trying to use AppLocker on a Windows 2016 to audit/controller what a service running as a service account can access. When I run a command like whoami.exe from a service AppLocker does not show any audit trail in the log files. When I login as that service account and run whoami.exe, the AppLocker Logs fills with entries. I know this was a problem with 2012 R2, but I thought I heard it was fixed in 2016. Does anyone know if it was fixed in 2016? Maybe 2019? Is there a special switch I have to do to allow AppLocker to work with services?

Thanks for any help on this.

Dan

windows-server
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

CarlFan-MSFT avatar image
0 Votes"
CarlFan-MSFT answered Dan13-3438 commented

Hi Dan,
Thank you for your post.
What's your system version? You could type "winver" in Search Bar to check. The latest version is April 13, 2021—KB5001347 (OS Build 14393.4350).
Is Application Identity Services enabled?
Application Identity service
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/configure-the-application-identity-service
http://halflifeofknowledge.blogspot.com/2014/09/applocker-service-accounts-and-group.html
Hope this helps and please help to accept as Answer if the response is useful.
Best Regards,
Carl

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you for the reply. The service Application Identity services is enabled and running. AppLocker works correctly if I login as the service account that I'm trying to limit, but it does not work when the service account is running service blah that I wrote.

The build is 14393.4350 version 1607

0 Votes 0 ·