Remember, if you use an administrator account for daily tasks, AppLocker won't provide any meaningful cybersecurity benefit.
Enable the Application Identity Service.
Open PowerShell as Administrator and execute:
Set-Service -Name AppIDSvc -StartupType Automatic
Start-Service -Name AppIDSvc
Enable the Application Identity Service in GPO
Enable the Application Identity Service.
Open PowerShell as Administrator and execute:
Set-Service -Name AppIDSvc -StartupType Automatic
Start-Service -Name AppIDSvc
Configure AppLocker Rules
Press Win + R, type secpol.msc, and press Enter.
In the left panel, navigate to: Security Settings -> Application Control Policies -> AppLocker
Generate Default Rules
Expand the AppLocker folder in the left pane.
Right-click Executable Rules and select Create Default Rules.
Right-click Script Rules and select Create Default Rules.
Right-click Windows Installer Rules and select Create Default Rules.
(Optional) Right-click Packaged app Rules and select Create Default Rules
Enable rules
Right-click the AppLocker root node (top folder) and select Properties.
Check the Configured box under each rule collection:
Executable rules: Select Audit only
Script rules: Select Audit only
Windows Installer rules: Select Audit only
Monitor Log Events
Open Event Viewer (eventvwr.msc).Navigate to: Applications and Services Logs -> Microsoft -> Windows -> AppLocker.
Check the EXE and DLL or Script and MSI logs:
Event ID 8002: The application was allowed.
Event ID 8003 / 8004: The application was audited (would be blocked) or explicitly blocked.
Update AppLocker rules
Set Enforcement Mode