Allow members of the Everyone group to run applications that are located in the Windows folderID: oval:org.secpod.oval:def:28643 | Date: (C)2015-10-08 (M)2022-10-10 |
Class: COMPLIANCE | Family: windows |
This setting allows members of the Everyone group to run applications that are located in (or beneath) the Windows folder.
If you enable this setting, members of the Everyone group will be able to run applications that are located in (or beneath) the Windows folder.
If you disable this setting, members of the Everyone group will not be able to run applications that are located in (or beneath) the Windows folder.
This setting is largely used to control running of apps on sensitive computers (such as domain controllers).
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Application Control Policies\AppLocker\Executable Rules!Allow members of the Everyone group to run applications that are located in the Windows folder
(2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SrpV2\Exe\a61c8b2c-a319-4cd0-9690-d2177cad7b51!Value
Platform: |
Microsoft Windows Server 2012 R2 |