none
Software restriction policy not working

    Question

  • I am currently using Windows Server 2012 to create a group policy that restrict the user in the domain cannot open Windows Media Player.

    I have also tried AppLocker but the user is still able to run it. Is there anyone can help me?

    Thursday, November 26, 2015 12:32 AM

Answers

  • Hi JackTiew,

    To restrict users from running specific Windows programs, you can simply use the built-in “Don't run specified Windows Applications” policy setting:

    1. Go to User ConfigurationàPoliciesàAdministrative TemplatesàSystem
    2. Enabled "Don't run specified Windows Applications"
    3. Under "Options" click on the "Show" button
    4. Enter "wmplayer.exe"

    Once group policy has been refreshed or you could force with the "gpupdate /force" command. Windows Media Player will no longer be allowed.

    If you have any questions, please feel free to contact us.


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, November 26, 2015 8:55 AM
    Moderator

All replies

  • Hi JackTiew,

    To restrict users from running specific Windows programs, you can simply use the built-in “Don't run specified Windows Applications” policy setting:

    1. Go to User ConfigurationàPoliciesàAdministrative TemplatesàSystem
    2. Enabled "Don't run specified Windows Applications"
    3. Under "Options" click on the "Show" button
    4. Enter "wmplayer.exe"

    Once group policy has been refreshed or you could force with the "gpupdate /force" command. Windows Media Player will no longer be allowed.

    If you have any questions, please feel free to contact us.


    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Thursday, November 26, 2015 8:55 AM
    Moderator
  • > I am currently using Windows Server 2012 to create a group policy that
    > restrict the user in the domain cannot open Windows Media Player.
     
    Since I asssume you use a computer setting, is your GPO applied to the
    computer? And since you use a hash rule, do the computers have the exact
    same executable wmplayer.exe as the computer where you created the hash
    rule?
     
    Thursday, November 26, 2015 11:36 AM