Allow members of the local Administrators group to run all applicationsID: oval:org.secpod.oval:def:28644 | Date: (C)2015-10-08 (M)2022-10-10 |
Class: COMPLIANCE | Family: windows |
This setting allows members of the local Administrators group to run all applications on computers, regardless of their location.
If you enable this setting, members of the Administrators group will be able to run applications, regardless of their location.
If you disable this setting, members of the Administrators group will be unable to run applications, regardless of their location.
This setting is largely used to control running of apps on sensitive computers (such as domain controllers).
Fix:
(1) GPO: Computer Configuration\Windows Settings\Security Settings\Application Control Policies\AppLocker\Executable Rules!Allow members of the local Administrators group to run all applications
(2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SrpV2\Exe\fd686d83-a829-4351-8ff4-27c7de5755d2!Value
Platform: |
Microsoft Windows Server 2012 R2 |