DonatShell
Server IP : 180.180.241.3  /  Your IP : 216.73.216.252
Web Server : Microsoft-IIS/7.5
System : Windows NT NETWORK-NHRC 6.1 build 7601 (Windows Server 2008 R2 Standard Edition Service Pack 1) i586
User : IUSR ( 0)
PHP Version : 5.3.28
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Windows/Help/Windows/en-US/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /Windows/Help/Windows/en-US/applocker_help.h1s
MZ@PEL!@0@.rsrc@@.its @@0	HX||4VS_VERSION_INFOStringFileInfo040904b0b!FileVersion1.00.00                         l"FileDescriptionCompiled Microsoft Help 2.0 TitleBFileStamp713771E201CA041F4JCompilerVersion2.5.71210.08579VCompileDate2009-07-14T01:07:22      >TopicCount35000000000000ALegalCopyright 2005 Microsoft Corporation. All rights reserved.CCCCCCCCCCCCCDVarFileInfo$Translation	ti#q7q×0yITOLITLS(X쌡^
V`   x 9CAOLPHHC ITSF #c9q	P--Y쌡^
VY쌡^
VIFCMAOLL9IFCM AOLLD//$FXFtiAttribute//$FXFtiAttribute/BTREE,/$FXFtiAttribute/DATA/$FXFtiAttribute/PROPERTYDN/$FXFtiMain//$FXFtiMain/BTREEy/$FXFtiMain/DATAM/$FXFtiMain/PROPERTY^N/$Index/$ATTRNAMEb4/$Index/$PROPBAG/$Index/$STRINGSJ/$Index/$SYSTEMp
/$Index/$TOC//$Index/$TOC/$applocker_helpn/$Index/$TOPICATTRP/$Index/$TOPICSP@/$Index/$URLSTRPh/$Index/$URLTBL8/$Index/$VTAIDXp/$Index/AssetId//$Index/AssetId/$LEAVES	/$OBJINSTn/applocker_help.h1cc</applocker_help.H1FS/applocker_help.H1TH/applocker_help.H1Vr/applocker_help_AssetId.H1KSk/applocker_help_BestBet.H1K>k/applocker_help_LinkTerm.H1K)l/applocker_help_SubjectTerm.H1Ko/assets/0/assets/02a1be35-7ead-489a-8997-aa4afc0ac686.xmltP0/assets/03c9ea88-d90c-4454-b76d-9874cf658693.xmlD#0/assets/11f74b62-1635-4ef0-9fe6-6067a506c413.xmlg0/assets/29eb37a3-bfb9-4681-a52f-be79908d244d.xml
0/assets/2a7b3de9-06f2-4647-9a61-53148781f313.xml.0/assets/3984e6db-2894-4e39-99ef-d1296a8fdcdc.xml<0/assets/4961ae4d-4aff-4931-a692-709fc7737a18.xmlD0/assets/4d7290d5-a934-417c-a7bd-b457f9988c80.xmlLi0/assets/4e23b4e4-913e-4c58-b208-22a59783d2c2.xml5q0/assets/9c045c1f-f7b2-4bb1-ac1d-714f88dde245.xml&h0/assets/b37ae250-d710-40d8-aa46-a08b71aea61f.xml{0/assets/b6a8dc34-400c-4b3d-a519-1ab5992ed996.xml	J0/assets/c215c7ec-0773-4e07-a08b-7ac422a6ab00.xmlSH0/assets/c25e95d2-7978-4056-89c2-ab71a00e47cf.xml$0/assets/df5d2dfa-a3ae-43ee-8300-c1c0340c01b6.xml?I0/assets/e190cd5e-1813-4b92-9d28-70b4fb58177c.xml0/assets/e56861aa-275b-49f5-8ebe-91a20a1aa585.xmlM::DataSpace/NameList<(::DataSpace/Storage/MSCompressed/Content,,::DataSpace/Storage/MSCompressed/ControlDataT )::DataSpace/Storage/MSCompressed/SpanInfoL/::DataSpace/Storage/MSCompressed/Transform/List<_::DataSpace/Storage/MSCompressed/Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/InstanceData/i::DataSpace/Storage/MSCompressed/Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/InstanceData/ResetTable0H3::Transform/{8CEC5846-07A1-11D9-B15E-000D56BFE6EE}/?Xp9UncompressedMSCompressedFX쌡^
VLZXCHH<maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Audit AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction><maml:para>You can configure all rules contained within a specified rule collection to only audit activity but not enforce rules. This may be useful if you want to test new rules before they are deployed.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To configure audit-only mode</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, right-click <maml:ui>AppLocker</maml:ui>, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>On the <maml:ui>Enforcement</maml:ui> tab, select the <maml:ui>Configured</maml:ui> check box for the appropriate rule collection, and then select <maml:ui>Audit only</maml:ui> in the list for that rule collection.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Repeat step 4 to configure additional rule collections.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>OK</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rule Enforcement</maml:linkText><maml:uri href="mshelp://windows/?id=b37ae250-d710-40d8-aa46-a08b71aea61f"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Configuring AppLocker Rule Exceptions</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>Rule exceptions allow you to specify files or folders to exclude from the rule.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para></maml:introduction></maml:section><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:procedure><maml:title>To configure exceptions for a rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Expand <maml:ui>Application Control Policies</maml:ui>, and then expand <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Expand the rule collection, right-click the rule that you want to configure exceptions for, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the <maml:ui>Exceptions</maml:ui> tab.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Add exception</maml:ui> box, select the rule type that you want to create, and then click <maml:ui>Add</maml:ui>.</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>For a publisher exception, click <maml:ui>Browse</maml:ui>, select the file that contains the publisher to exclude, and then click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>For a path exception, choose the file or folder path to exclude, and then click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>For a file hash exception, choose the file or folder path to exclude, and then click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Windows AppLocker</maml:linkText><maml:uri href="mshelp://windows/?id=b6a8dc34-400c-4b3d-a519-1ab5992ed996"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>AppLocker Rule Properties</maml:title><maml:introduction><maml:para>There are two ways that you can edit a rule or view its properties in AppLocker:</maml:para> 
<maml:list class="unordered">
<maml:listItem><maml:para>In the details pane, select the rule, and then in the <maml:ui>Action</maml:ui> pane, click <maml:ui>Properties</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>In the details pane, right-click the rule, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:listItem>
</maml:list>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title>Viewing and editing rules</maml:title>
<maml:introduction>
<maml:para>The <maml:ui>Properties</maml:ui> dialog box displays a different set of tabs based on the primary condition of the rule. For example, a rule with a publisher primary condition includes the <maml:ui>General</maml:ui>, <maml:ui>Publisher</maml:ui>, and <maml:ui>Exceptions</maml:ui> tab. The <maml:ui>Exceptions</maml:ui> tab is not displayed for rules with a primary condition set to file hash.</maml:para>
</maml:introduction>
<maml:sections>
<maml:section><maml:title>General tab</maml:title><maml:introduction>
<maml:para>On the <maml:ui>General</maml:ui> tab, you can change the name and description of the rule, change the action of the rule (allow or deny), and change the user or group to which the rule applies.</maml:para>

</maml:introduction></maml:section>

<maml:section><maml:title>Publisher tab</maml:title><maml:introduction>
<maml:para>The <maml:ui>Publisher</maml:ui> tab is available only for rules that have publisher conditions. On the <maml:ui>Publisher</maml:ui> tab, you can change the publisher name, product name, file name, and file version that the rule applies to.</maml:para>


</maml:introduction></maml:section>

<maml:section><maml:title>Path tab</maml:title><maml:introduction>
<maml:para>The <maml:ui>Path</maml:ui> tab is available only for rules that have path conditions. On the <maml:ui>Path</maml:ui> tab, you can change the folder or file path that the rule is applied to. </maml:para>
</maml:introduction></maml:section>

<maml:section><maml:title>File Hash tab</maml:title><maml:introduction>
<maml:para>File hash allows you to create a rule that applies to a specific file. The <maml:ui>File Hash</maml:ui> tab is available only for rules that have file hash conditions. On the <maml:ui>File Hash</maml:ui> tab, you can add and remove files that are included in the rule.</maml:para>

</maml:introduction></maml:section>

<maml:section><maml:title>Exceptions tab</maml:title><maml:introduction>
<maml:para>On the <maml:ui>Exceptions</maml:ui> tab, you can add or edit files or folders that are excluded from the rule. The <maml:ui>Exceptions</maml:ui> tab is not available for file hash rules.</maml:para>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Windows AppLocker</maml:linkText><maml:uri href="mshelp://windows/?id=b6a8dc34-400c-4b3d-a519-1ab5992ed996"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section>


</maml:sections></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Create Default AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To create default rules</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Right-click the appropriate rule type for which you want to automatically generate default rules. You can automatically generate rules for executable, Windows Installer, and script rules.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Create Default Rules</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Understanding AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section>
<maml:title>Rule collections</maml:title>
<maml:introduction>
<maml:para>The AppLocker Microsoft Management Console (MMC) snap-in is organized into four areas called rule collections. The four rule collections are executable files, scripts, Windows Installer files, and DLL files. These collections give the administrator an easy way to differentiate the rules for different types of applications. The following table lists the file formats included in each rule collection.</maml:para>
<maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>The DLL rule collection is not enabled by default. To learn how to enable the DLL rule collection, see <maml:navigationLink><maml:linkText>Enforce AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=9c045c1f-f7b2-4bb1-ac1d-714f88dde245"></maml:uri></maml:navigationLink>.</maml:para></maml:alertSet>

<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry><maml:para>Rule collection</maml:para></maml:entry>
<maml:entry><maml:para>Associated file formats</maml:para></maml:entry>
</maml:row></maml:tableHeader>

<maml:row>
<maml:entry><maml:para>Executable</maml:para></maml:entry>
<maml:entry><maml:para>.exe</maml:para><maml:para>.com</maml:para></maml:entry>

</maml:row>

<maml:row>
<maml:entry><maml:para>Scripts</maml:para></maml:entry>
<maml:entry>
<maml:para>.ps1</maml:para>
<maml:para>.bat</maml:para>
<maml:para>.cmd</maml:para>
<maml:para>.vbs</maml:para>
<maml:para>.js</maml:para></maml:entry>
</maml:row>

<maml:row>
<maml:entry><maml:para>Windows Installer</maml:para></maml:entry>
<maml:entry><maml:para>.msi</maml:para>
<maml:para>.msp</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>DLL</maml:para></maml:entry>
<maml:entry><maml:para>.dll</maml:para>
<maml:para>.ocx</maml:para></maml:entry>
</maml:row></maml:table>
<maml:alertSet class="important"><maml:title>Important </maml:title><maml:para>If you use DLL rules, a DLL allow rule has to be created for each DLL that is used by all of the allowed applications.</maml:para></maml:alertSet>
<maml:alertSet class="caution"><maml:title>Caution </maml:title><maml:para>When DLL rules are used, AppLocker must check each DLL that an application loads. Therefore, users may experience a reduction in performance if DLL rules are used.</maml:para></maml:alertSet>

</maml:introduction></maml:section><maml:section><maml:title>Rule conditions</maml:title><maml:introduction>
<maml:para>Rule conditions are criteria that the AppLocker rule is based on. Primary conditions are required to create an AppLocker rule. The three primary rule conditions are publisher, path, and file hash.</maml:para></maml:introduction>
<maml:sections>
<maml:section><maml:title>Publisher</maml:title><maml:introduction>
<maml:para>This condition identifies an application based on its digital signature and extended attributes. The digital signature contains information about the company that created the application (the publisher). The extended attributes, which are obtained from the binary resource, contain the name of the product that the application is part of and the version number of the application. The publisher may be a software development company, such as Microsoft, or the information technology department of your organization.</maml:para>
<maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>Use a publisher condition when possible. Publisher conditions can be created to allow applications to continue to function even if the location of the application changes or if the application is updated.</maml:para></maml:alertSet>
<maml:para>When you select a reference file for a publisher condition, the wizard creates a rule that specifies the publisher, product, file name, and version number. You can make the rule more generic by moving the slider down or by using a wildcard character (*) in the product, file name, or version number fields.</maml:para>
<maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>To enter custom values while creating a rule in the Create Rules Wizard, you must select the <maml:ui>Use custom values</maml:ui> check box. When this check box is selected, you cannot use the slider to make the rule more or less specific.</maml:para></maml:alertSet>

<maml:para>The <maml:phrase>file version</maml:phrase> controls whether a user can run a specific version, earlier versions, or later versions. You can choose a version number and then configure the following options: </maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:phrase>Exactly.</maml:phrase> The rule applies only to this version of the application.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>And above.</maml:phrase> The rule applies to this version and all later versions.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>And below.</maml:phrase> The rule applies to this version and all earlier versions.</maml:para></maml:listItem></maml:list>
<maml:para>The following table describes how a publisher condition is applied.</maml:para>
<maml:table>
<maml:tableHeader><maml:row>
<maml:entry><maml:para>Option</maml:para></maml:entry><maml:entry><maml:para>The publisher condition allows or denies…</maml:para></maml:entry></maml:row></maml:tableHeader>

<maml:row><maml:entry><maml:para><maml:ui>All signed files</maml:ui></maml:para></maml:entry><maml:entry><maml:para>All files that are signed by a publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher only</maml:ui></maml:para></maml:entry><maml:entry><maml:para>All files that are signed by the named publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher and product name</maml:ui></maml:para></maml:entry><maml:entry><maml:para>All files for the specified product that are signed by the named publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher and product name, and file name</maml:ui></maml:para></maml:entry><maml:entry><maml:para>Any version of the named file for the named product that are signed by the publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher, product name, file name, and file version</maml:ui></maml:para></maml:entry><maml:entry><maml:para><maml:ui>Exactly</maml:ui></maml:para></maml:entry><maml:entry><maml:para>The specified version of the named file for the named product that are signed by the publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher, product name, file name, and file version</maml:ui></maml:para></maml:entry><maml:entry><maml:para><maml:ui>And above</maml:ui></maml:para></maml:entry><maml:entry><maml:para>The specified version of the named file and any new releases for the product that are signed by the publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Publisher, product name, file name, and file version</maml:ui></maml:para></maml:entry><maml:entry><maml:para><maml:ui>And below</maml:ui></maml:para></maml:entry><maml:entry><maml:para>The specified version of the named file and any older versions for the product that are signed by the publisher.</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para><maml:ui>Custom</maml:ui></maml:para></maml:entry><maml:entry><maml:para>You can edit the <maml:ui>Publisher</maml:ui>, <maml:ui>Product name</maml:ui>, <maml:ui>File name</maml:ui> and <maml:ui>Version</maml:ui> fields to create a custom rule.</maml:para></maml:entry></maml:row>
</maml:table>
</maml:introduction></maml:section>

<maml:section><maml:title>Path</maml:title><maml:introduction>
<maml:para>This condition identifies an application by its location in the file system of the computer or on the network.</maml:para>
<maml:para>AppLocker uses path variables for directories in Windows.</maml:para><maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>While two of these path variables use the same format as Windows environment variables, they are not environment variables. AppLocker can only interpret AppLocker path variables.</maml:para></maml:alertSet>

<maml:para>The following table details these path variables.</maml:para>

<maml:table>
<maml:tableHeader><maml:row><maml:entry><maml:para>Windows directory or drive</maml:para></maml:entry><maml:entry><maml:para>AppLocker path variable</maml:para></maml:entry><maml:entry><maml:para>Windows environment variable</maml:para></maml:entry></maml:row></maml:tableHeader>
<maml:row><maml:entry><maml:para>Windows</maml:para></maml:entry><maml:entry><maml:para>%WINDIR%</maml:para></maml:entry><maml:entry><maml:para>%SystemRoot%</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>System32</maml:para></maml:entry><maml:entry><maml:para>%SYSTEM32%</maml:para></maml:entry><maml:entry><maml:para>%SystemDirectory%</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Windows installation directory</maml:para></maml:entry><maml:entry><maml:para>%OSDRIVE%</maml:para></maml:entry><maml:entry><maml:para>%SystemDrive%</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Program Files</maml:para></maml:entry><maml:entry><maml:para>%PROGRAMFILES%</maml:para></maml:entry><maml:entry><maml:para>%ProgramFiles% and </maml:para><maml:para>%ProgramFiles(x86)%</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Removable media (for example, CD or DVD)</maml:para></maml:entry><maml:entry><maml:para>%REMOVABLE%</maml:para></maml:entry><maml:entry><maml:para></maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Removable storage device (for example, USB flash drive)</maml:para></maml:entry><maml:entry><maml:para>%HOT%</maml:para></maml:entry><maml:entry><maml:para></maml:para></maml:entry></maml:row>
</maml:table>
<maml:alertSet class="important"><maml:title>Important </maml:title><maml:para>Because a path condition can be configured to include a large number of folders and files, path conditions should be carefully planned. For example, if an allow rule with a path condition includes a folder location that non-administrators are allowed to write data into, a user can then copy unapproved files into that location and run the files. For this reason, it is a best practice to not create path conditions for standard user writable locations, such as a user profile.</maml:para></maml:alertSet>
</maml:introduction></maml:section>

<maml:section><maml:title>File hash</maml:title><maml:introduction>
<maml:para>When the file hash condition is chosen, the system computes a cryptographic hash of the identified file.</maml:para>
</maml:introduction></maml:section>
</maml:sections></maml:section><maml:section><maml:title>AppLocker default rules</maml:title><maml:introduction>
<maml:para>AppLocker allows you to generate default rules for each of the rule types.</maml:para>

<maml:para>Executable default rule types:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Allow members of the local <maml:phrase>Administrators</maml:phrase> group to run all applications.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run applications that are located in the Windows folder.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run applications that are located in the Program Files folder.</maml:para></maml:listItem>
</maml:list>

<maml:para>Windows Installer default rule types:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Allow members of the local <maml:phrase>Administrators</maml:phrase> group to run all Windows Installer files.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run digitally signed Windows Installer files.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run all Windows Installer files located in the Windows\Installer folder.</maml:para></maml:listItem>
</maml:list>

<maml:para>Script default rule types:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Allow members of the local <maml:phrase>Administrators</maml:phrase> group to run all scripts.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run scripts located in the Program Files folder.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run scripts located in the Windows folder.</maml:para></maml:listItem></maml:list>

<maml:para>DLL default rule types:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Allow members of the local <maml:phrase>Administrators</maml:phrase> group to run all DLLs.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run DLLs located in the Program Files folder.</maml:para></maml:listItem>
<maml:listItem><maml:para>Allow members of the <maml:phrase>Everyone</maml:phrase> group to run DLLs located in the Windows folder.</maml:para></maml:listItem></maml:list>


<maml:para>For more information, see <maml:navigationLink><maml:linkText>Create Default AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=29eb37a3-bfb9-4681-a52f-be79908d244d"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction></maml:section><maml:section><maml:title>AppLocker rule behavior</maml:title><maml:introduction>
<maml:para>If no AppLocker rules for a specific rule collection exist, all files with that file format are allowed to run. However, when an AppLocker rule for a specific rule collection is created, only the files explicitly allowed in a rule are permitted to run. For example, if you create an executable rule that allows .exe files in <maml:replaceable>%SystemDrive%\FilePath</maml:replaceable> to run, only executable files located in that path are allowed to run. </maml:para>

<maml:para>A rule can be configured to use either an allow or deny action:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:phrase>Allow.</maml:phrase> You can specify which files are allowed to run in your environment and for which users or groups of users. You can also configure exceptions to identify files that are excluded from the rule.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>Deny.</maml:phrase> You can specify which files are <maml:replaceable>not</maml:replaceable> allowed to run in your environment and for which users or groups of users. You can also configure exceptions to identify files that are excluded from the rule.</maml:para></maml:listItem>
</maml:list>

<maml:alertSet class="important"><maml:title>Important </maml:title><maml:para>You can use a combination of allow actions and deny actions. However, we recommend using allow actions with exceptions because deny actions override allow actions in all cases. Deny actions can also be circumvented.</maml:para></maml:alertSet>


</maml:introduction></maml:section><maml:section><maml:title>Rule exceptions</maml:title><maml:introduction>
<maml:para>You can apply AppLocker rules to individual users or a group of users. If you apply a rule to a group of users, all users in that group are affected by that rule. If you need to allow a subset of a user group to use an application, you can create a special rule for that subset. For example, the rule "Allow Everyone to run Windows except Registry Editor" allows everyone in the organization to run Windows but does not allow anyone to run Registry Editor. The effect of this rule would prevent users such as help desk personnel from running a program that is necessary for their support tasks. To resolve this problem, create a second rule that applies to the Helpdesk user group: "Allow Helpdesk to run Registry Editor." If you create a deny rule that does not allow any users to run Registry Editor, the deny rule will override the second rule that allows the Helpdesk user group to run Registry Editor.</maml:para>
</maml:introduction></maml:section><maml:section><maml:title>AppLocker wizards</maml:title><maml:introduction>
<maml:para>You can create custom rules in two ways:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>The Create Rules Wizard enables you to create one rule at a time. For more information, see <maml:navigationLink><maml:linkText>Create an AppLocker Rule</maml:linkText><maml:uri href="mshelp://windows/?id=4961ae4d-4aff-4931-a692-709fc7737a18"></maml:uri></maml:navigationLink>.</maml:para></maml:listItem>
<maml:listItem><maml:para>The Automatically Generate Rules Wizard allows you to select a folder, select a user or group to apply the rule to, and then create many rules at one time for that folder. This wizard automatically generates allow rules only. For more information, see <maml:navigationLink><maml:linkText>Automatically Generate AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=4e23b4e4-913e-4c58-b208-22a59783d2c2"></maml:uri></maml:navigationLink>.</maml:para></maml:listItem>
</maml:list>
<maml:para><maml:phrase>Additional considerations</maml:phrase></maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>By default, AppLocker rules do not allow users to open or run any files that are not specifically allowed. Administrators should maintain an up-to-date list of allowed applications. </maml:para></maml:listItem>
<maml:listItem><maml:para>There are two types of AppLocker conditions that do not persist following an update: </maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:phrase>File hash condition.</maml:phrase> File hash conditions can be used with any application because a cryptographic hash value of the application is generated at the time the rule is created. However, the hash value is specific to that exact version of the application. If there are several versions of the application in use within the organization, you need to create file hash conditions for each version in use and for any new versions that are released.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>A publisher condition with a specific product version set.</maml:phrase> If you create a publisher condition that uses the <maml:phrase>Exactly</maml:phrase> file condition option, the rule cannot persist if a new version of the application is installed. A new publisher condition must be created, or the rule version must be edited to be made less specific.</maml:para></maml:listItem>

</maml:list></maml:listItem>
<maml:listItem><maml:para>If an application is not digitally signed, you cannot use a publisher condition.</maml:para></maml:listItem>
<maml:listItem><maml:para>AppLocker rules cannot be used to manage computers running a Windows operating system earlier than Windows 7. Software Restriction Policies must be used instead.</maml:para></maml:listItem>
<maml:listItem><maml:para>If AppLocker rules are defined in a Group Policy object (GPO), only those rules are applied. To ensure interoperability between Software Restriction Policies rules and AppLocker rules, define Software Restriction Policies rules and AppLocker rules in different GPOs.</maml:para></maml:listItem>
<maml:listItem><maml:para>When an AppLocker rule is set to <maml:ui>Audit only</maml:ui>, the rule is not enforced. When a user runs an application that is included in the rule, the application is opened and runs normally, and information about that application is added to the AppLocker event log.</maml:para></maml:listItem>
<maml:listItem><maml:para>A custom configured URL can be included in the message that is displayed when an application is blocked.</maml:para></maml:listItem>

<maml:listItem><maml:para>Expect an increase in the number of help desk calls initially because of blocked applications. As users begin to understand that they cannot run applications that are not allowed, the help desk calls may decrease.</maml:para></maml:listItem>
</maml:list>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Edit an AppLocker Rule</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section>
<maml:title></maml:title>
<maml:introduction><maml:para>You can use AppLocker to edit rules that you have created. </maml:para></maml:introduction>
<maml:sections>
<maml:section><maml:title>Editing a publisher rule</maml:title>
<maml:introduction><maml:para>The following procedure describes how to edit a publisher rule.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To edit a publisher rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate rule collection.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Action</maml:ui> pane, right-click the publisher rule, and then click <maml:ui>Properties</maml:ui>.</maml:para>

</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate tab to edit the rule properties.</maml:para><maml:list class="unordered">
<maml:listItem><maml:para>Click the <maml:ui>General</maml:ui> tab to change the rule name, add a rule description, configure whether the rule is used to allow or deny applications, and set the security group for which this rule should apply.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click the <maml:ui>Publisher</maml:ui> tab to configure the certificate's common name, the product name, the file name, or file version of the publisher.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click the <maml:ui>Exceptions</maml:ui> tab to create or edit exceptions.</maml:para></maml:listItem>
<maml:listItem><maml:para>When you finish updating the rule, click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step></maml:procedure></maml:introduction></maml:section>

<maml:section>
<maml:title>Editing a file hash rule</maml:title>
<maml:introduction>
<maml:para>The following procedure describes how to edit a hash rule.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To edit a file hash rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Choose the appropriate rule collection.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Action</maml:ui> pane, right-click the file hash rule, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate tab to edit the rule properties.</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Click the <maml:ui>General</maml:ui> tab to change the rule name, add a rule description, configure whether the rule is used to allow or deny applications, and set the security group in which this rule should apply.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click the <maml:ui>File Hash</maml:ui> tab to configure the files that should be used to enforce the rule. You can use the <maml:ui>Browse Files</maml:ui> button to add a specific file or the <maml:ui>Browse Folders</maml:ui> button to add all files in a specified folder.</maml:para></maml:listItem>
<maml:listItem><maml:para>When you finish updating the rule, click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem></maml:list></maml:section></maml:sections></maml:step></maml:procedure></maml:introduction></maml:section>

<maml:section><maml:title>Editing a path rule</maml:title>
<maml:introduction>
<maml:para>The following procedure describes how to edit a path rule.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To edit a path rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Choose the appropriate rule collection.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Action</maml:ui> pane, right-click the path rule, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate tab to edit the rule properties.</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Click the <maml:ui>General</maml:ui> tab to change the rule name, add a rule description, configure whether the rule is used to allow or deny applications, and set the security group in which this rule should apply.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click the <maml:ui>Path</maml:ui> tab to configure the path on the computer in which the rule should be enforced.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click the <maml:ui>Exceptions</maml:ui> tab to create exceptions for specific files in a folder.</maml:para></maml:listItem>
<maml:listItem><maml:para>When you finish updating the rule, click <maml:ui>OK</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered">
<maml:listItem>
<maml:para><maml:navigationLink><maml:linkText>Understanding AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=2a7b3de9-06f2-4647-9a61-53148781f313"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section>

</maml:sections></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Create an AppLocker Rule</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section>
<maml:title></maml:title>
<maml:introduction><maml:para>You can create new rules by using the Create Rules Wizard.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To create a new rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Right-click the rule collection for which you want to create the rule, and then click <maml:ui>Create New Rule</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>On the <maml:ui>Before You Begin</maml:ui> page, click <maml:ui>Next</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Allow</maml:ui> or <maml:ui>Deny</maml:ui> to allow or deny the files contained within the rule.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Select</maml:ui>. In the <maml:ui>Select User or Group</maml:ui> box, type the appropriate security group or user, and then click <maml:ui>OK</maml:ui>. </maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Next</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate rule condition for this rule. You can choose from <maml:ui>Publisher</maml:ui>, <maml:ui>Path</maml:ui>, or <maml:ui>File hash</maml:ui>, and then click <maml:ui>Next</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Depending on the rule condition you selected, you are asked for different criteria:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:phrase>Publisher rule condition.</maml:phrase> Click <maml:ui>Browse</maml:ui> to select the file for which you want to extract the publisher information. To edit the publisher information, select the <maml:ui>Use custom values</maml:ui> check box, and then edit the values. Click <maml:ui>Next</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>Path rule condition.</maml:phrase> Navigate to the file or folder by clicking <maml:ui>Browse Folders</maml:ui> or <maml:ui>Browse Files</maml:ui>. Optionally, you can type the path into the <maml:ui>Path</maml:ui> box. Click <maml:ui>Next</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para><maml:phrase>File hash rule condition.</maml:phrase> Navigate to the file or folder by clicking <maml:ui>Browse Folders</maml:ui> or <maml:ui>Browse Files</maml:ui>. Click <maml:ui>Next</maml:ui>.</maml:para></maml:listItem></maml:list>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>(Optional) On the <maml:ui>Exceptions</maml:ui> page, specify the publisher or path that you want to exclude from the rule, and then click <maml:ui>Next</maml:ui>.</maml:para>
<maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>You cannot create exceptions for file hash rules.</maml:para></maml:alertSet>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Name</maml:ui> box, type a name that you can use to identify the rule.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Description</maml:ui> box, type a description that explains the purpose of this rule.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Create</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Delete an AppLocker Rule</maml:title><maml:introduction>

<maml:para>We recommend reviewing the active AppLocker rules occasionally and deleting any rules that are no longer needed.</maml:para>

<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
</maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:procedure><maml:title>To delete a rule</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the appropriate rule collection for which you want to delete the rule.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the details pane, right-click the rule to delete, click <maml:ui>Delete</maml:ui>, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Automatically Generate AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>AppLocker allows you to automatically generate rules for all of the files within a folder. It will scan the specified folder and create the condition types that you choose for each file in that folder.</maml:para>



<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To automatically generate rules</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, and then double-click <maml:ui>AppLocker</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Right-click the appropriate rule collection for which you want to automatically generate rules. You can automatically generate rules for executable, Windows Installer, and script rules.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Automatically Generate Rules</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>On the <maml:ui>Folder and Permissions</maml:ui> page, click <maml:ui>Browse</maml:ui> to choose the folder to be analyzed. By default, this is the Program Files folder.</maml:para>
</maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Select</maml:ui> to choose the security group in which the default rules should be applied. By default, this is the <maml:phrase>Everyone</maml:phrase> group.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>The wizard provides a name in the <maml:ui>Name to identify this set of rules</maml:ui> box based on the name of the folder that you have selected. Accept the provided name or type a different name, and then click <maml:ui>Next</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>On the <maml:ui>Rule Preferences</maml:ui> page, choose the conditions that you want the wizard to use while creating rules, and then click <maml:ui>Next</maml:ui>. For more information about rule conditions, see <maml:navigationLink><maml:linkText>Understanding AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=2a7b3de9-06f2-4647-9a61-53148781f313"></maml:uri></maml:navigationLink>.</maml:para>
<maml:alertSet class="note"><maml:title>Notes </maml:title><maml:alert>The <maml:ui>Reduce the number of rules created by grouping similar files</maml:ui> check box is selected by default. This helps you organize AppLocker rules and reduce the number of rules that you create by performing the following operations for the rule condition that you select:</maml:alert></maml:alertSet></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Review the files that were analyzed and the rules that will be automatically created. To make changes, click <maml:ui>Previous</maml:ui> to return to the page where you can change your selections. After reviewing the rules, click <maml:ui>Create</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Enforce AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction><maml:para>After AppLocker rules are created, you can enforce the rules.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To enforce rules</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, right-click <maml:ui>AppLocker</maml:ui>, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>On the <maml:ui>Enforcement</maml:ui> tab, select the <maml:ui>Configured</maml:ui> check box for the rule collection that you want to enforce, and then verify that <maml:ui>Enforce rules</maml:ui> is selected in the list for that rule collection.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Repeat step 4 to configure enforcement for additional rule collections.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>OK</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>
<maml:para>Because the DLL rule collection is not enabled by default, you must perform the following procedure before you can create and enforce DLL rules.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>
<maml:procedure><maml:title>To enable the DLL rule collection</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, type <maml:userInput>secpol.msc</maml:userInput> in the <maml:ui>Search programs and files</maml:ui> box, and then press ENTER. You can also:</maml:para>
<maml:list class="ordered">
<maml:listItem><maml:para>Click <maml:ui>Start</maml:ui>, and then click <maml:ui>Control Panel</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Click <maml:ui>System and Security</maml:ui>, and then click <maml:ui>Administrative Tools</maml:ui>.</maml:para></maml:listItem>
<maml:listItem><maml:para>Double-click <maml:ui>Local Security Policy</maml:ui>.</maml:para></maml:listItem>
</maml:list></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>If the <maml:ui>User Account Control</maml:ui> dialog box appears, confirm that the action it displays is what you want, and then click <maml:ui>Yes</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the console tree, double-click <maml:ui>Application Control Policies</maml:ui>, right-click <maml:ui>AppLocker</maml:ui>, and then click <maml:ui>Properties</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click the <maml:ui>Advanced</maml:ui> tab, select the <maml:ui>Enable the DLL rule collection</maml:ui> check box, and then click <maml:ui>OK</maml:ui>.</maml:para>
<maml:alertSet class="important"><maml:title>Important </maml:title><maml:para>Before you enforce DLL rules, make sure that there are allow rules for each DLL that is used by any of the allowed applications.</maml:para></maml:alertSet>

</maml:section></maml:sections></maml:step></maml:procedure>

<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rule Enforcement</maml:linkText><maml:uri href="mshelp://windows/?id=b37ae250-d710-40d8-aa46-a08b71aea61f"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Configuring AppLocker Rule Enforcement</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>The procedures in this section help you configure enforcement for AppLocker rules in your organization.</maml:para>
<maml:para>This section contains the following topics:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Understanding AppLocker Rule Enforcement</maml:linkText><maml:uri href="mshelp://windows/?id=c25e95d2-7978-4056-89c2-ab71a00e47cf"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Enforce AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=9c045c1f-f7b2-4bb1-ac1d-714f88dde245"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Audit AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=02a1be35-7ead-489a-8997-aa4afc0ac686"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
</maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Windows AppLocker</maml:title><maml:introduction>
<maml:para>AppLocker is a new feature in Windows 7 and Windows Server 2008 R2 that allows you to specify which users or groups can run particular applications in your organization based on unique identities of files. If you use AppLocker, you can create rules to allow or deny applications from running.</maml:para>
<maml:para>Today's organizations face a number of challenges in controlling application execution, including the following:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para>Which applications should a user have access to run?</maml:para></maml:listItem>
<maml:listItem><maml:para>Which users should be allowed to install new software?</maml:para></maml:listItem>
<maml:listItem><maml:para>Which versions of applications should be allowed?</maml:para></maml:listItem>
<maml:listItem><maml:para>How are licensed applications controlled?</maml:para></maml:listItem></maml:list>
<maml:para>To meet these challenges, AppLocker provides administrators with the ability to specify which users can run specific applications. AppLocker allows administrators to control the following types of applications: executable files (.exe and .com), scripts (.js, .ps1, .vbs, .cmd, and .bat), Windows Installer files (.msi and .msp), and DLL files (.dll and .ocx). This helps reduce the organization's cost of managing computing resources by decreasing the number of help desk calls from users running inappropriate applications.</maml:para>
<maml:para>The following topics provide more information about AppLocker:</maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Overview of Windows AppLocker</maml:linkText><maml:uri href="mshelp://windows/?id=c215c7ec-0773-4e07-a08b-7ac422a6ab00"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rule Enforcement</maml:linkText><maml:uri href="mshelp://windows/?id=b37ae250-d710-40d8-aa46-a08b71aea61f"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rule Exceptions</maml:linkText><maml:uri href="mshelp://windows/?id=03c9ea88-d90c-4454-b76d-9874cf658693"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>AppLocker Rule Properties</maml:linkText><maml:uri href="mshelp://windows/?id=11f74b62-1635-4ef0-9fe6-6067a506c413"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Windows Versions That Support AppLocker</maml:linkText><maml:uri href="mshelp://windows/?id=e56861aa-275b-49f5-8ebe-91a20a1aa585"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction><maml:content><maml:sections></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Overview of Windows AppLocker</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>AppLocker is a new feature in Windows 7 and Windows Server 2008 R2 that replaces the Software Restriction Policies feature. AppLocker contains new capabilities and extensions that reduce administrative overhead and help administrators control how users can access and use files, such as executable files, scripts, Windows Installer files, and DLLs. Using AppLocker, you can:</maml:para>

<maml:list class="unordered">
<maml:listItem><maml:para>Define rules based on file attributes derived from the digital signature, including the publisher, product name, file name, and file version. For example, you can create rules based on the publisher attribute that is persistent through updates, or you can create rules for a specific version of a file.</maml:para></maml:listItem>

<maml:listItem><maml:para>Assign a rule to a security group or an individual user. </maml:para>

</maml:listItem>
<maml:listItem><maml:para>Create exceptions to rules. For example, you can create a rule that allows all Windows processes to run except Registry Editor (Regedit.exe).</maml:para></maml:listItem>
<maml:listItem><maml:para>Use audit-only mode to deploy the policy and understand its impact before enforcing it.</maml:para></maml:listItem>
<maml:listItem><maml:para>Import and export rules. The import and export affects the entire policy. For example, if you export a policy, all of the rules from all of the rule collections are exported, including the enforcement settings for the rule collections. If you import a policy, the existing policy is overwritten.</maml:para></maml:listItem>
<maml:listItem><maml:para>Simplify creating and managing AppLocker rules by using AppLocker PowerShell cmdlets. </maml:para></maml:listItem>
</maml:list>

<maml:para>For more information about AppLocker rules, see <maml:navigationLink><maml:linkText>Understanding AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=2a7b3de9-06f2-4647-9a61-53148781f313"></maml:uri></maml:navigationLink>.</maml:para>
</maml:introduction></maml:section><maml:section><maml:title>What has changed?</maml:title>
<maml:introduction>
<maml:para>The following table compares AppLocker to Software Restriction Policies.</maml:para>
<maml:table>
<maml:tableHeader>
<maml:row>
<maml:entry><maml:para>Feature</maml:para></maml:entry>
<maml:entry><maml:para>Software Restriction Policies</maml:para></maml:entry>
<maml:entry><maml:para>AppLocker</maml:para></maml:entry></maml:row></maml:tableHeader>
<maml:row><maml:entry><maml:para>Rule scope</maml:para></maml:entry><maml:entry><maml:para>All users</maml:para></maml:entry><maml:entry><maml:para>Specific user or group</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>Rule conditions provided</maml:para></maml:entry>
<maml:entry><maml:para>File hash, path, certificate, registry path, and Internet zone rules</maml:para></maml:entry>
<maml:entry><maml:para>File hash, path, and publisher rules</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Rule types provided</maml:para></maml:entry><maml:entry><maml:para>Allow and deny</maml:para></maml:entry><maml:entry><maml:para>Allow and deny</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para>Default rule action</maml:para></maml:entry><maml:entry><maml:para>Allow or deny</maml:para></maml:entry><maml:entry><maml:para>Deny</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>Audit-only mode</maml:para></maml:entry>
<maml:entry><maml:para>No</maml:para></maml:entry>
<maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>Wizard to create multiple rules at one time</maml:para></maml:entry>
<maml:entry><maml:para>No</maml:para></maml:entry>
<maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>Policy import or export</maml:para></maml:entry>
<maml:entry><maml:para>No</maml:para></maml:entry>
<maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>
<maml:row>
<maml:entry><maml:para>Rule collection</maml:para></maml:entry>
<maml:entry><maml:para>No</maml:para></maml:entry>
<maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para>PowerShell support</maml:para></maml:entry><maml:entry><maml:para>No</maml:para></maml:entry><maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>

<maml:row><maml:entry><maml:para>Custom error messages</maml:para></maml:entry><maml:entry><maml:para>No</maml:para></maml:entry><maml:entry><maml:para>Yes</maml:para></maml:entry></maml:row>
</maml:table></maml:introduction></maml:section><maml:section>
<maml:title>AppLocker requirements</maml:title>
<maml:introduction>
<maml:para>AppLocker is available in all editions of Windows Server 2008 R2 and in Windows 7 Ultimate and Windows 7 Enterprise. To use AppLocker, you need:</maml:para>

<maml:list class="unordered">
<maml:listItem><maml:para>A computer running Windows Server 2008 R2, Windows 7 Ultimate, Windows 7 Enterprise, or Windows 7 Professional to create the AppLocker rules. Windows 7 Professional can be used to create the rules, but the rules cannot be enforced on computers running Windows 7 Professional. The computer can be a domain controller.</maml:para></maml:listItem>
<maml:listItem><maml:para>For Group Policy deployment, at least one computer with the Group Policy Management Console (GPMC) or Remote Server Administration Tools (RSAT) installed to host the AppLocker rules.</maml:para></maml:listItem>
<maml:listItem><maml:para>Computers running Windows Server 2008 R2, Windows 7 Ultimate, or Windows 7 Enterprise to enforce the AppLocker rules that you create.</maml:para></maml:listItem>
</maml:list>

</maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Understanding AppLocker Rule Enforcement</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>


<maml:para>The three AppLocker enforcement modes are described in the following table.</maml:para>

<maml:table>
<maml:tableHeader><maml:row><maml:entry><maml:para>Enforcement mode</maml:para></maml:entry><maml:entry><maml:para>Description</maml:para></maml:entry></maml:row></maml:tableHeader>
<maml:row><maml:entry><maml:para><maml:ui>Not configured</maml:ui></maml:para></maml:entry><maml:entry><maml:para>This is the default setting. If linked Group Policy objects (GPOs) contain a different setting, that setting is used. If enforcement is not configured but rules are present in the corresponding rule collection, those rules are enforced.</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para><maml:ui>Enforce rules</maml:ui></maml:para></maml:entry><maml:entry><maml:para>Rules are enforced.</maml:para></maml:entry></maml:row>
<maml:row><maml:entry><maml:para><maml:ui>Audit only</maml:ui></maml:para></maml:entry><maml:entry><maml:para>Rules are audited but not enforced. The audit-only enforcement mode helps you determine which applications are affected by the policy before enforcing the policy. When the AppLocker policy for a rule collection is set to <maml:ui>Audit only</maml:ui>, rules for that rule collection are not enforced. When a user runs an application that is affected by an AppLocker rule, information about that application is added to the AppLocker event log.</maml:para></maml:entry></maml:row>
</maml:table>

<maml:para>When AppLocker policies from various GPOs are merged, both the rules and the enforcement modes are merged. The most similar Group Policy setting is used for the enforcement mode, and all rules from linked GPOs are applied. </maml:para>

<maml:para>For information about GPOs and Group Policy inheritance, see the Group Policy Planning and Deployment Guide (<maml:navigationLink><maml:linkText>http://go.microsoft.com/fwlink/?LinkId=143138</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=143138"></maml:uri></maml:navigationLink>).</maml:para>

<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rule Enforcement</maml:linkText><maml:uri href="mshelp://windows/?id=b37ae250-d710-40d8-aa46-a08b71aea61f"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
</maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Configuring AppLocker Rules</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>The procedures in this section are designed to help you configure AppLocker rules in your organization.</maml:para>
<maml:para>This section contains the following topics:</maml:para>
<maml:list class="unordered">
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Understanding AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=2a7b3de9-06f2-4647-9a61-53148781f313"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Start the Application Identity Service</maml:linkText><maml:uri href="mshelp://windows/?id=e190cd5e-1813-4b92-9d28-70b4fb58177c"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Create Default AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=29eb37a3-bfb9-4681-a52f-be79908d244d"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Automatically Generate AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=4e23b4e4-913e-4c58-b208-22a59783d2c2"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Create an AppLocker Rule</maml:linkText><maml:uri href="mshelp://windows/?id=4961ae4d-4aff-4931-a692-709fc7737a18"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Edit an AppLocker Rule</maml:linkText><maml:uri href="mshelp://windows/?id=3984e6db-2894-4e39-99ef-d1296a8fdcdc"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
<maml:listItem><maml:para><maml:navigationLink><maml:linkText>Delete an AppLocker Rule</maml:linkText><maml:uri href="mshelp://windows/?id=4d7290d5-a934-417c-a7bd-b457f9988c80"></maml:uri></maml:navigationLink></maml:para></maml:listItem>
</maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Start the Application Identity Service</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title><maml:introduction>
<maml:para>Before you can enforce AppLocker policies, you must start the Application Identity service by using the Services snap-in console.</maml:para>
<maml:para>Membership in the local <maml:phrase>Administrators</maml:phrase> group, or equivalent, is the minimum required to complete this procedure.</maml:para>

<maml:procedure><maml:title>To start the Application Identity service</maml:title><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>Click <maml:ui>Start</maml:ui>, click <maml:ui>Administrative Tools</maml:ui>, and then click <maml:ui>Services</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the Services snap-in console, double-click <maml:ui>Application Identity</maml:ui>.</maml:para></maml:section></maml:sections></maml:step><maml:step><maml:sections><maml:section><maml:title></maml:title><maml:para>In the <maml:ui>Application Identity Properties</maml:ui> dialog box, click <maml:ui>Automatic</maml:ui> in the <maml:ui>Startup type</maml:ui> list, click <maml:ui>Start</maml:ui>, and then click <maml:ui>OK</maml:ui>.</maml:para></maml:section></maml:sections></maml:step></maml:procedure>

<maml:alertSet class="note"><maml:title>Note </maml:title><maml:para>You can also use a Group Policy object (GPO) setting that configures the Application Identity service <maml:ui>Startup type</maml:ui> to <maml:ui>Automatic</maml:ui>. For information about using Group Policy, see Planning and Deploying Group Policy (<maml:navigationLink><maml:linkText>http://go.microsoft.com/fwlink/?LinkId=143689</maml:linkText><maml:uri href="http://go.microsoft.com/fwlink/?LinkId=143689"></maml:uri></maml:navigationLink>).</maml:para></maml:alertSet>

<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Configuring AppLocker Rules</maml:linkText><maml:uri href="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><maml:conceptual contentType="conceptual" xmlns:maml="http://schemas.microsoft.com/maml/2004/10" xmlns:dev="http://schemas.microsoft.com/maml/dev/2004/10"><maml:title>Windows Versions That Support AppLocker</maml:title><maml:introduction></maml:introduction><maml:content><maml:sections><maml:section><maml:title></maml:title>
<maml:introduction>
<maml:para>AppLocker is available in all editions of Windows Server 2008 R2 and in Windows 7 Ultimate and Windows 7 Enterprise.  Windows 7 Professional can be used to create AppLocker rules. However, AppLocker rules cannot be enforced on computers running Windows 7 Professional. Organizations should use AppLocker for all computers that support it. </maml:para>
<maml:alertSet class="caution"><maml:title>Caution </maml:title><maml:para>If you upgrade a computer that uses Software Restriction Policies to Windows 7 or Windows Server 2008 R2 and then implement AppLocker rules, only the AppLocker rules are enforced. For this reason, it is recommended that you create a new Group Policy object (GPO) for AppLocker in environments where both Software Restriction Policies and AppLocker are used.</maml:para></maml:alertSet>
<maml:para><maml:phrase>Additional references</maml:phrase></maml:para>
<maml:list class="unordered"><maml:listItem><maml:para><maml:navigationLink><maml:linkText>Windows AppLocker</maml:linkText><maml:uri href="mshelp://windows/?id=b6a8dc34-400c-4b3d-a519-1ab5992ed996"></maml:uri></maml:navigationLink></maml:para></maml:listItem></maml:list></maml:introduction></maml:section></maml:sections></maml:content></maml:conceptual><?xml version="1.0" encoding="utf-8"?>
<HelpCollection Id="applocker_help" DTDVersion="1.0" FileVersion="" LangId="1033" Copyright="© 2005 Microsoft Corporation. All rights reserved." Title="Windows AppLocker" xmlns="http://schemas.microsoft.com/help/collection/2004/11">
	<CompilerOptions CompileResult="H1S" CreateFullTextIndex="Yes" BreakerId="Microsoft.NLG.en.WordBreaker">
		<IncludeFile File="applocker_help.H1F" />
	</CompilerOptions>
	<TOCDef File="applocker_help.H1T" Id="applocker_help_TOC" />
	<VTopicDef File="applocker_help.H1V" />
	<KeywordIndexDef File="applocker_help_AssetId.H1K" />
	<KeywordIndexDef File="applocker_help_BestBet.H1K" />
	<KeywordIndexDef File="applocker_help_LinkTerm.H1K" />
	<KeywordIndexDef File="applocker_help_SubjectTerm.H1K" />
	<ItemMoniker Name="!DefaultTOC" ProgId="HxDs.HxHierarchy" InitData="AnyString" />
	<ItemMoniker Name="!DefaultFullTextSearch" ProgId="HxDs.HxFullTextSearch" InitData="AnyString" />
	<ItemMoniker Name="!DefaultAssetIdIndex" ProgId="HxDs.HxIndex" InitData="AssetId" />
	<ItemMoniker Name="!DefaultBestBetIndex" ProgId="HxDs.HxIndex" InitData="BestBet" />
	<ItemMoniker Name="!DefaultAssociativeIndex" ProgId="HxDs.HxIndex" InitData="LinkTerm" />
	<ItemMoniker Name="!DefaultKeywordIndex" ProgId="HxDs.HxIndex" InitData="SubjectTerm" />
</HelpCollection><?xml version="1.0" encoding="utf-8"?>
<HelpFileList xmlns="http://schemas.microsoft.com/help/filelist/2004/11">
	<File Url="assets\02a1be35-7ead-489a-8997-aa4afc0ac686.xml" />
	<File Url="assets\03c9ea88-d90c-4454-b76d-9874cf658693.xml" />
	<File Url="assets\11f74b62-1635-4ef0-9fe6-6067a506c413.xml" />
	<File Url="assets\29eb37a3-bfb9-4681-a52f-be79908d244d.xml" />
	<File Url="assets\2a7b3de9-06f2-4647-9a61-53148781f313.xml" />
	<File Url="assets\3984e6db-2894-4e39-99ef-d1296a8fdcdc.xml" />
	<File Url="assets\4961ae4d-4aff-4931-a692-709fc7737a18.xml" />
	<File Url="assets\4d7290d5-a934-417c-a7bd-b457f9988c80.xml" />
	<File Url="assets\4e23b4e4-913e-4c58-b208-22a59783d2c2.xml" />
	<File Url="assets\9c045c1f-f7b2-4bb1-ac1d-714f88dde245.xml" />
	<File Url="assets\b37ae250-d710-40d8-aa46-a08b71aea61f.xml" />
	<File Url="assets\b6a8dc34-400c-4b3d-a519-1ab5992ed996.xml" />
	<File Url="assets\c215c7ec-0773-4e07-a08b-7ac422a6ab00.xml" />
	<File Url="assets\c25e95d2-7978-4056-89c2-ab71a00e47cf.xml" />
	<File Url="assets\df5d2dfa-a3ae-43ee-8300-c1c0340c01b6.xml" />
	<File Url="assets\e190cd5e-1813-4b92-9d28-70b4fb58177c.xml" />
	<File Url="assets\e56861aa-275b-49f5-8ebe-91a20a1aa585.xml" />
</HelpFileList><?xml version="1.0" encoding="utf-8"?>
<VTopicSet DTDVersion="1.0" xmlns="http://schemas.microsoft.com/help/vtopic/2004/11">
	<Vtopic Url="assets\02a1be35-7ead-489a-8997-aa4afc0ac686.xml" RLTitle="Audit AppLocker Rules">
		<Attr Name="assetid" Value="02a1be35-7ead-489a-8997-aa4afc0ac686" />
		<Keyword Index="AssetId" Term="02a1be35-7ead-489a-8997-aa4afc0ac686" />
		<Keyword Index="AssetId" Term="02a1be35-7ead-489a-8997-aa4afc0ac6861033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="02a1be35-7ead-489a-8997-aa4afc0ac686" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\03c9ea88-d90c-4454-b76d-9874cf658693.xml" RLTitle="Configuring AppLocker Rule Exceptions">
		<Attr Name="assetid" Value="03c9ea88-d90c-4454-b76d-9874cf658693" />
		<Keyword Index="AssetId" Term="03c9ea88-d90c-4454-b76d-9874cf658693" />
		<Keyword Index="AssetId" Term="03c9ea88-d90c-4454-b76d-9874cf6586931033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="03c9ea88-d90c-4454-b76d-9874cf658693" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\11f74b62-1635-4ef0-9fe6-6067a506c413.xml" RLTitle="AppLocker Rule Properties">
		<Attr Name="assetid" Value="11f74b62-1635-4ef0-9fe6-6067a506c413" />
		<Keyword Index="AssetId" Term="11f74b62-1635-4ef0-9fe6-6067a506c413" />
		<Keyword Index="AssetId" Term="11f74b62-1635-4ef0-9fe6-6067a506c4131033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="11f74b62-1635-4ef0-9fe6-6067a506c413" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\29eb37a3-bfb9-4681-a52f-be79908d244d.xml" RLTitle="Create Default AppLocker Rules">
		<Attr Name="assetid" Value="29eb37a3-bfb9-4681-a52f-be79908d244d" />
		<Keyword Index="AssetId" Term="29eb37a3-bfb9-4681-a52f-be79908d244d" />
		<Keyword Index="AssetId" Term="29eb37a3-bfb9-4681-a52f-be79908d244d1033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="29eb37a3-bfb9-4681-a52f-be79908d244d" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\2a7b3de9-06f2-4647-9a61-53148781f313.xml" RLTitle="Understanding AppLocker Rules">
		<Attr Name="assetid" Value="2a7b3de9-06f2-4647-9a61-53148781f313" />
		<Keyword Index="AssetId" Term="2a7b3de9-06f2-4647-9a61-53148781f313" />
		<Keyword Index="AssetId" Term="2a7b3de9-06f2-4647-9a61-53148781f3131033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="2a7b3de9-06f2-4647-9a61-53148781f313" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\3984e6db-2894-4e39-99ef-d1296a8fdcdc.xml" RLTitle="Edit an AppLocker Rule">
		<Attr Name="assetid" Value="3984e6db-2894-4e39-99ef-d1296a8fdcdc" />
		<Keyword Index="AssetId" Term="3984e6db-2894-4e39-99ef-d1296a8fdcdc" />
		<Keyword Index="AssetId" Term="3984e6db-2894-4e39-99ef-d1296a8fdcdc1033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="3984e6db-2894-4e39-99ef-d1296a8fdcdc" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\4961ae4d-4aff-4931-a692-709fc7737a18.xml" RLTitle="Create an AppLocker Rule">
		<Attr Name="assetid" Value="4961ae4d-4aff-4931-a692-709fc7737a18" />
		<Keyword Index="AssetId" Term="4961ae4d-4aff-4931-a692-709fc7737a18" />
		<Keyword Index="AssetId" Term="4961ae4d-4aff-4931-a692-709fc7737a181033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="4961ae4d-4aff-4931-a692-709fc7737a18" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\4d7290d5-a934-417c-a7bd-b457f9988c80.xml" RLTitle="Delete an AppLocker Rule">
		<Attr Name="assetid" Value="4d7290d5-a934-417c-a7bd-b457f9988c80" />
		<Keyword Index="AssetId" Term="4d7290d5-a934-417c-a7bd-b457f9988c80" />
		<Keyword Index="AssetId" Term="4d7290d5-a934-417c-a7bd-b457f9988c801033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="4d7290d5-a934-417c-a7bd-b457f9988c80" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\4e23b4e4-913e-4c58-b208-22a59783d2c2.xml" RLTitle="Automatically Generate AppLocker Rules">
		<Attr Name="assetid" Value="4e23b4e4-913e-4c58-b208-22a59783d2c2" />
		<Keyword Index="AssetId" Term="4e23b4e4-913e-4c58-b208-22a59783d2c2" />
		<Keyword Index="AssetId" Term="4e23b4e4-913e-4c58-b208-22a59783d2c21033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="4e23b4e4-913e-4c58-b208-22a59783d2c2" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\9c045c1f-f7b2-4bb1-ac1d-714f88dde245.xml" RLTitle="Enforce AppLocker Rules">
		<Attr Name="assetid" Value="9c045c1f-f7b2-4bb1-ac1d-714f88dde245" />
		<Keyword Index="AssetId" Term="9c045c1f-f7b2-4bb1-ac1d-714f88dde245" />
		<Keyword Index="AssetId" Term="9c045c1f-f7b2-4bb1-ac1d-714f88dde2451033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="9c045c1f-f7b2-4bb1-ac1d-714f88dde245" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\b37ae250-d710-40d8-aa46-a08b71aea61f.xml" RLTitle="Configuring AppLocker Rule Enforcement">
		<Attr Name="assetid" Value="b37ae250-d710-40d8-aa46-a08b71aea61f" />
		<Keyword Index="AssetId" Term="b37ae250-d710-40d8-aa46-a08b71aea61f" />
		<Keyword Index="AssetId" Term="b37ae250-d710-40d8-aa46-a08b71aea61f1033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="b37ae250-d710-40d8-aa46-a08b71aea61f" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\b6a8dc34-400c-4b3d-a519-1ab5992ed996.xml" RLTitle="Windows AppLocker">
		<Attr Name="assetid" Value="b6a8dc34-400c-4b3d-a519-1ab5992ed996" />
		<Keyword Index="AssetId" Term="b6a8dc34-400c-4b3d-a519-1ab5992ed996" />
		<Keyword Index="AssetId" Term="b6a8dc34-400c-4b3d-a519-1ab5992ed9961033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="b6a8dc34-400c-4b3d-a519-1ab5992ed996" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\c215c7ec-0773-4e07-a08b-7ac422a6ab00.xml" RLTitle="Overview of Windows AppLocker">
		<Attr Name="assetid" Value="c215c7ec-0773-4e07-a08b-7ac422a6ab00" />
		<Keyword Index="AssetId" Term="c215c7ec-0773-4e07-a08b-7ac422a6ab00" />
		<Keyword Index="AssetId" Term="c215c7ec-0773-4e07-a08b-7ac422a6ab001033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="c215c7ec-0773-4e07-a08b-7ac422a6ab00" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\c25e95d2-7978-4056-89c2-ab71a00e47cf.xml" RLTitle="Understanding AppLocker Rule Enforcement">
		<Attr Name="assetid" Value="c25e95d2-7978-4056-89c2-ab71a00e47cf" />
		<Keyword Index="AssetId" Term="c25e95d2-7978-4056-89c2-ab71a00e47cf" />
		<Keyword Index="AssetId" Term="c25e95d2-7978-4056-89c2-ab71a00e47cf1033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="c25e95d2-7978-4056-89c2-ab71a00e47cf" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\df5d2dfa-a3ae-43ee-8300-c1c0340c01b6.xml" RLTitle="Configuring AppLocker Rules">
		<Attr Name="assetid" Value="df5d2dfa-a3ae-43ee-8300-c1c0340c01b6" />
		<Keyword Index="AssetId" Term="df5d2dfa-a3ae-43ee-8300-c1c0340c01b6" />
		<Keyword Index="AssetId" Term="df5d2dfa-a3ae-43ee-8300-c1c0340c01b61033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="df5d2dfa-a3ae-43ee-8300-c1c0340c01b6" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\e190cd5e-1813-4b92-9d28-70b4fb58177c.xml" RLTitle="Start the Application Identity Service">
		<Attr Name="assetid" Value="e190cd5e-1813-4b92-9d28-70b4fb58177c" />
		<Keyword Index="AssetId" Term="e190cd5e-1813-4b92-9d28-70b4fb58177c" />
		<Keyword Index="AssetId" Term="e190cd5e-1813-4b92-9d28-70b4fb58177c1033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="e190cd5e-1813-4b92-9d28-70b4fb58177c" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
	<Vtopic Url="assets\e56861aa-275b-49f5-8ebe-91a20a1aa585.xml" RLTitle="Windows Versions That Support AppLocker">
		<Attr Name="assetid" Value="e56861aa-275b-49f5-8ebe-91a20a1aa585" />
		<Keyword Index="AssetId" Term="e56861aa-275b-49f5-8ebe-91a20a1aa585" />
		<Keyword Index="AssetId" Term="e56861aa-275b-49f5-8ebe-91a20a1aa5851033" />
		<Attr Name="appliesToProduct" Value="Windows Server 2008 R2" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2DATACENTERSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISEIA64SERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2ENTERPRISESERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2STANDARDSERVER" />
		<Attr Name="APPLIESTOPRODUCTSPECIFIC" Value="WS08R2WEBSERVER" />
		<Attr Name="CommunityContent" Value="1" />
		<Attr Name="WillHaveMamlFeed" Value="True" />
		<Attr Name="zzpub_MtpsProductFamily" Value="WS" />
		<Attr Name="zzpub_MTPSVersion" Value="11" />
		<Attr Name="Locale" Value="kbEnglish" />
		<Attr Name="AssetID" Value="e56861aa-275b-49f5-8ebe-91a20a1aa585" />
		<Attr Name="TopicType" Value="kbArticle" />
	</Vtopic>
</VTopicSet><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpTOC>
<HelpTOC xmlns="http://schemas.microsoft.com/help/toc/2004/11" DTDVersion="1.0" Id="applocker_help_TOC" FileVersion="" LangId="1033" ParentNodeIcon="Book" PluginStyle="Hierarchical">
	<HelpTOCNode Url="mshelp://windows/?tocid=0b7edbf1-9e72-4703-a425-d14c2eff2bc5" Title="">
		<HelpTOCNode Url="mshelp://windows/?id=b6a8dc34-400c-4b3d-a519-1ab5992ed996" Title="Windows AppLocker">
			<HelpTOCNode Url="mshelp://windows/?id=c215c7ec-0773-4e07-a08b-7ac422a6ab00" Title="Overview of Windows AppLocker" />
			<HelpTOCNode Url="mshelp://windows/?id=df5d2dfa-a3ae-43ee-8300-c1c0340c01b6" Title="Configuring AppLocker Rules">
				<HelpTOCNode Url="mshelp://windows/?id=2a7b3de9-06f2-4647-9a61-53148781f313" Title="Understanding AppLocker Rules" />
				<HelpTOCNode Url="mshelp://windows/?id=e190cd5e-1813-4b92-9d28-70b4fb58177c" Title="Start the Application Identity Service" />
				<HelpTOCNode Url="mshelp://windows/?id=29eb37a3-bfb9-4681-a52f-be79908d244d" Title="Create Default AppLocker Rules" />
				<HelpTOCNode Url="mshelp://windows/?id=4e23b4e4-913e-4c58-b208-22a59783d2c2" Title="Automatically Generate AppLocker Rules" />
				<HelpTOCNode Url="mshelp://windows/?id=4961ae4d-4aff-4931-a692-709fc7737a18" Title="Create an AppLocker Rule" />
				<HelpTOCNode Url="mshelp://windows/?id=3984e6db-2894-4e39-99ef-d1296a8fdcdc" Title="Edit an AppLocker Rule" />
				<HelpTOCNode Url="mshelp://windows/?id=4d7290d5-a934-417c-a7bd-b457f9988c80" Title="Delete an AppLocker Rule" />
			</HelpTOCNode>
			<HelpTOCNode Url="mshelp://windows/?id=b37ae250-d710-40d8-aa46-a08b71aea61f" Title="Configuring AppLocker Rule Enforcement">
				<HelpTOCNode Url="mshelp://windows/?id=c25e95d2-7978-4056-89c2-ab71a00e47cf" Title="Understanding AppLocker Rule Enforcement" />
				<HelpTOCNode Url="mshelp://windows/?id=9c045c1f-f7b2-4bb1-ac1d-714f88dde245" Title="Enforce AppLocker Rules" />
				<HelpTOCNode Url="mshelp://windows/?id=02a1be35-7ead-489a-8997-aa4afc0ac686" Title="Audit AppLocker Rules" />
			</HelpTOCNode>
			<HelpTOCNode Url="mshelp://windows/?id=03c9ea88-d90c-4454-b76d-9874cf658693" Title="Configuring AppLocker Rule Exceptions" />
			<HelpTOCNode Url="mshelp://windows/?id=11f74b62-1635-4ef0-9fe6-6067a506c413" Title="AppLocker Rule Properties" />
			<HelpTOCNode Url="mshelp://windows/?id=e56861aa-275b-49f5-8ebe-91a20a1aa585" Title="Windows Versions That Support AppLocker" />
		</HelpTOCNode>
	</HelpTOCNode>
</HelpTOC><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="AssetId" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="BestBet" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="LinkTerm" /><?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE HelpIndex>
<HelpIndex DTDVersion="1.0" Name="SubjectTerm" /> naTPVU?}TWZp	
RD*KڔͩTZ$ҨhPT㤶mؽݕo>3}y=bRC4bIB]((ֲT`DD]hEEX h
~fX@ hDM)Mwer}oGzD^M"ZK.CI.8T-KvzqļwoxȾaȾGm>čm~MߵӇ]M}#~A͗ޱx<~]{ռ|"g׺~]ٯݝ7ywyC3y6O:oy+w@[c[Xs~Oyܿ^ÿ\<>bv^.o:5_ßp~xAW}.8?B@?\s^NlW_p{ĸ~3i@ſo.87!moG6ɷ+j8ԑ~z4^oqtg'䣼rozV*^Wo[73=w=ww7nr[˹ywv.Ȏ]_M鷞ůO$
̷s6}Q{H>ߓSS2$@oW?AЧ}ct:W攁>Ds
2/t|Sg޾k~:_sv~v|Mgxyׂ?תuo@ӧ$]K9Wݝwo7:>O6؏?=_9}'kk;9۾vlH#}_{m>x;^][>3wkfΦkӮkw<#gu~{W힚pm|kßz$M}ku׎_ՖcЍ}v米y:~Ϟ$]!л>wO;?~e}l.|>>v}lc7Odžvy?؏mlO}cU>ޏ:>{ol;~ڹzכﳝwvn};ܹ}sn
;w8}܃	ó'`.|w;~<yn
܉;snVU/~sjnƪasƽrUR&إȏsmK-o#뵗lɚeپgO7_ٗZmKsKsKs6KvtKtK-mtKt6KlΗ/ٞ՟//٠ЗlMKKf|;.;>R_}9}GN6&};;F[>RRÝRR;;ڥwK}l܎>x}Ir)8q߰Ǿ>w-ݘ}N9|ݻ}<=W󹽃>~sz{};|<#< ã@<#<`ǣtm$D$b2&}r=y'=W9gEw^w;<_Mn<Gqs]wQF\ʃ)NS:guJ<N)s:tW:gS:t[ҙ)s=:SJg{tg{Jt_O΁,OLN)ҹ
)ҝ)9S:>:/S3;t|JtvǧJ<vOΐҙ#)Y:SS>S:s>:[Sc>S:s>:kSs>S:g|JtϧJg|tg}JtѧJg|vOΣLOlOΧN)9ҝU)yY):SJgvN)sv;tg}Jt~o:S3>S:;tsΙҝg)ҙםS:g}JtۧJg}twN)s>:SJgwOκ鼼ON)s>S:g}Jt):SJgxO)&<t΅S:gxJO)<tf:?SJgyLs%<)L饳<tq[x/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/ŋx/^x^/R#ͣA>
;|44|>
E#ѐ<x4GChX4~4
'CGah4T|?Kӏ!h4d|>
]aࣣѐt~4
GC!hJ?SՏ!XhZW?!h|4Z?hv>
gGC!Ѱhh~o>
8؏!hc?ÜGѐ,~4
ͳG4L|>
wGCp4d~
<ۏh4|>
GC!h>
GÐ4~
BG!Ѱ}4>>
H!0h4\2}>
NçG!Z'~a`00``00``00``00``00``00``00``0?`>/DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDGD^N0j ?8y1]8?uקMU7Z侩|ロ7wN}v7ܖ<ǜלۜ=OrE;ϲyl#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1b#Fb1F#Ĉ1bBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB^BSYC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐ2dC!d2!CȐo-ϩ+~9~?2.\m'.…p\.¸p.\…p\..p7\.¸p.\…p\.¸p.\ps\.9.\…p\.Ae.¸p.\…p=eu]v…p\.¸p.\…p\.4qp׸kvׇ>;#w1aw۵q;ޑ{tgG|}ÿv~x!axx$⡌7j<^yFB"f;WŅ.\*xiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii:jګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjv׳iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiin{mV[[mVmV[[mVmV[[mVZnjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjjګjݶǵⳚiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii۞Co߾ͷ;q.ŅY\eĵ[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mVmV[[mV1g
44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM4=MH4MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MMӶ4MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM4iiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiimqM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MM44MDd܄ vnu>iwl`FR
$n:<)]Du+U/{{9^{4C4CUWp=ww~}y|9^=ET
Jtӽ!e]1kqo.I EeSjKTd[y
1*h6^MRn+._,Lh|g;}=ȕ$ʕJK圔`3tID?:ˆcx<o|}|}|}|}|}|}}}}}}5Bv!vIĀU6dbG?f>>./ms.p_nJ
."Ʋn3'?[^
|'>I> 
w2v1}rl3	*="u($'a]Cvavf8W_zv{ߟW;x3
܉xz5p402^X))$ba@{0*CGLْ<i58-˓i+TM#DZ4TG!أ-[~MIɽ_l>`Jjn
9S.dF2W!*3ɎkuUv1;&`'m:^6Vx5MJ͂jģRbp]B;ߕʐ5'zws԰+|wd
BqPM/`>գuVCIʏ\nIU0>K鞮ݕ\+1+4˵DfDplmK-jiT`叮tq4
&!SOa. "ѥ4:^Wq,Tu"|B'?s4ЋoܿL#,ĢcRNLkU7j/T5f2kOzɞݞ[M;h2/,\rfֶX+5F7;|2IK%訟,0v2Vи9(JO:Ǘ(VRȸC6JvOy1F8Bl5/$[T
*ZR[KL|3M4
)g%8ryʎN[1vcžmbr:&)8yX*	v/driDASAvϴlfezoOWӑgY{HuP
Ȥ[Ji']bPV/qegnu
Zt8#]-`,tWH5h)rل8\<%?c
Ew1
^AHAv6ؘ0x0-;2ߠ>ANJ bSE`J8EdM&vV&kvt=6Artl>/`QU@TR/jL^&4'Eo?cW;`f:̾e
QDVMZ
CzrX\f*8Y21"FEevzD/Dm	Wrjr<C08齭Gh,EOZqoz4uإbXzZ񏳵-Ν|h#Tč9ͅT0>
/dڶru-(Sbq/2HtC#r܂ERUXhSP8Eq]ٮ%3
Q8_SBt$Fn2NU8_1ekAͪ!Tu].̜sQ@J(JSZ$K[{lZ8fl*Znk&
lNdQ	\ƨK|,n|b
RS\Z5yrh5_uۜ(԰Ѕ俣Ђn-h/wlFKKAT)M0$+o>D_Xug+A1+ y㭊nZ яy(U#3t)p!G$n4GyWձ
]dl]gTp6Wͧߢ JS*
5x;ܒ\qs]-dڴ>/V۵PYQu}
{D- 6k11.uAb@a4ԍ2XH\:>.s)B/y6NnrGC'4i[y.,U9ED+(u,ǣ1#cG<+n"j˫(C"˨Pz8	fpC51gfvﬤUpap`[,9\
Ð$0D]f+:*HL'`rh+AoN|ǨscO[*g-<WGF2ުb!(O(?楗$*;`YO8Y,v5)Ҥ/]yٞLr*]1oFԣ2eUw0I/K
gŖ]0[ǢR&1+j^<ۛMFo<c(	Gbt/23[*oM:$#1S!>ƛ^uml
6>j/!XJ9ΑcvtLH#Dr40$y$O3L$9%Y^BY'e\m	%o+hG<#!#<壌
KFX&wPzvFzμvll]Vjv11zA3JK_xE>ɛ:!O:zju-V*[1TZ(}?FՖl"Ū&&7
$/SV#*gߧJ)^,KY?UP,-f﬋d6(MJ3MzUt^62xbM(gBǢJJx(`$Ȓ_i7a 9}lf\h@O)KjL3"܆D΁R9dzٸg3i+ƕz7d}7[BRZRyPgQb{*Uƶe%"|<!x,\wr};Msc~֋4Y_Xmnnv=O؉%y^1n:A1R̷Iбbn4(Gu>y.D-`?O<:Ⳏ9?:k	'-mڮuۭ	T.>ɋmզ);n]#)Rhl?KQo|!ҥY%U
E
Ntwͯ{V1Ly$W,\K1ǚoIg%/ƀL
BK
yuZRQsd݈FaB1epw{>Y)S\
JP|ezy_^@m{Gݤ?DM)	̩btaFTj|V[6zb-q+G@DGX	\#܏u{{	tC</wdB
.U]EسdT^sЍCeXr
esd8EtW W03,Ƶ1Sׂdq3q"/<ʵe;zP2V	6]5Km
c䔷-zQ7sNgZQ7V,N/FRg&~
[+sj/ȔtAD2)[MkmGJ}cXnyHt}ap@QwV6j
҆<d$@8dQE G܇ڤ!W(W(ȻiDAD@'	ܘBL~7C"0a$UyPy|s)J{&sܟV鴄4Prd 
)|U_UE[4CTjSf0%EVWruvlF
(XyJB!~"_fܘqKSO:bv+D/~=sU
MGi2SG^A4
\Syf[?uNl_O7Qc?h/)$lh1g[s&l攻o(4G5;qJ:}^w1_R79VXur\aeY\Sv5`m]NߧrAfCƮhYٖHslԨ+N<GmXd&#`#My2f-?*1W@M	Ͷ圛j-=β	2BVeNV%[V!PUbc0XMiz2@ChBL"p,DUL0G[܉}ޏg(H*=7֓U.|u>6/<tqkv*l:,_R%ցDGmL:1YXm1-:,&X1㭑y-3]n^2h!RWVN<\Dwm7x'oԸN~r!=QuhpjvD<[_TIc@mpEc{3ZyɷOl_~^+{*2i 6kxuZ\éY檁Q06!*m_Y;ir,'EWzyH9`)A]:)'Roڭd'ϋ]ly[&5Ӣ
MIE,9Tf^q=ڪ	˻
Usp!)eP{m:ac#=/In{㝻dȭ cxLpzϰn )Pʑ:ZeĴlǚ2ne7y/3O>\f]:F'=J%[p9Led$K7ӌ@n{
Ir](QVݜԑAiG\<t*R[}kpT\)]RQ8CQ;z{q#|i!j$94_%Rp%[!9l5ˌ"#>ʯ[}qGL^sPy10|[}$=VW1'?yYYJKw]B 7n-t`4Z't{ÃYpwaQCcE	_&ϱ5G8ݷ<ջ0_'<IĬJʥdR+Q])/11D	Ӆ1,\]-|-;,lY+MVTΩ%b)j)<I[B҉kT,!"rǤ1lbBs"fqd5%p9,ئH_A u7COpˏˇ_/}d0``00``0: PDOp=Gvm%Y`ɕ(	*H:<5̤lŝk^)bshܡ:YE,?	M8C,gc0A1r7"U|J2#J?\uA"ao?P5#N: _oau9qf9~
5J2A(5w*ioSr	3Vb/d0i['с$,sǰ)ps6(?ŔeM${˷vlW:q=7Vl\dm&/M倉MV+h*g1ڠl6Xl,РJ+$-Jpϑr71'#SyYQf\i`KsȀ	>?("EyN7g44NvAGzִծ9w^cX\SćkdT+c\a:,X\+Ć&ixSy85>K\@[^-o'D4ة@4xA[ҖV3Lc44ڣQ/Z0=3z,rM+x3ky̜j\jB)ŷ$4IlzwN3DH9ݢvp8IOKbN!4+STȈWpWW>l_QLe[Ѭ}NBe+04ntU^"~@9ur\NƉ?pȩtBW]ޟRA
E/L"sgZbД>jZwTzH_IЈwT9CKFa$D
^9Ylt-US9ݏSg*ySc9I?Y\$]_OYaoK&jsJ&jۜ+,+z
pB:	>R	;kt@GSp5w9ɷ!^-D>ZM^g+פd3k4s!'X}iWQV9ezN0JW\U#2ȘVYSPWnNjg:%-	g wղԬTU
v]+ ;ەV8N
3=k ֯*k)Xq+IǪZ#F;KR)jlṠbpcQeyEMϽ~>/JlĮ!
:MBG-[9
%W2re@֠UsSU= DTmhdjv*IFH.
lĸ1>2%,j皸̧#d+{KHJ}>)ZfyW~%9a9tc=
~gD#=&LQ>646"YD۪Vtw_̷sB	powAy|fK<IPtcc]F_˳ncSW8ńc{TqWT|G,M0b^.fk=l)ZW.lal8T~q%nۼY>x3]+[6Vhz߱>s?

n<F&>S/RE&#屧*UHPK#іd!dн>,N'k!LpoҏƬE/[uȡI~fPB9φ68m~'[I6"j
/x--}\<4||0.i0aJ<Ew]Y#mvYʮ=5Gh1%@^b/d9\Y#8?>+X29xY>T~4`RhHܞ6n,(B(0Ԧ&W)NpTJcc}Y,OS7_-]5	/`}ƁLZi6!ڌߙ;l|xZYr!Fl<ڬܿ6ݽ$vWVH@IKR2RTL9RU_[N%r"8ZC_a^bŔ;=|ypw[}yQ<錀(b0֑0TsKwڊc*+
%_i
Venci֢}TxT"SdwdђJyB8RMf)(VqG%#:!ԞrXQX|t{=Bbń.OIDnbui}djrnd0H\a1ιE˔+i8uߺN׉F˹U5<D.`22b@!2Xw]4|ϰǺ&E%Ehd9&T֡>2޽bVN&gY&;R20#\*imluCmiu"GRV5ƨHǻR&Q(ݯ#O`_R35D$Gg#rͻM
ØHzB!9n	c	,,rk+dHid;dX˸$tXnNNQ$
Z,]+1ρs+xaY.dQf8"Wa$XkI</n<r:A3U
"փC\]G7wv.Ncc$rt)rS$ik<z*K
TPZ6.q>Cke~VLOuȁaNl8qٚ5[{yR0A5Rɋ uxoETLOݒZ@I뷑"Sek] !ySWx}ݚk#D,\I5b`vmavڢ}xa	lMC&'*9R5hˆ?H]
xĭGɯػdw5D;5tJv6e\e:82@
mU,5ݶsbt
OkT&q=[}ȥ ,ܖ_	|B	CAέoE6Ĵ{p1}+"Ekן.CܓbBVK
ea?UEumұ.-7f:dcH10vu^p4n9raPm
1j`LLHvM=\.,0B`-pnZk˜ɪCaQ["Ƴj׬	›m/nKZjR[+>q1q=BorCRXUqhTW3"B
UfSH~%QeiFmg8EѸh}q,Qeyw8Uڿ\
.XwqhCF]Nfӣy=:ť@Mjw}kFyaWC+c+EݝӰ3<@݋X(͟&ڭ.xC	es6˧&)[R^_Ѹ4QuɺNx,0a@zx
KtEi|GG=% =d9cf50DZ|$6L6_	8uvdPep. #pdav)4msvX@+L<	ԽgQ&wuB*Ί,nkbо{{]ط5*Ř)@~2|sN	*&I`11M͂%$Blȶ)A)sFz}ƼGq24J7+}^w_m	{
֔,vf>ybc)(
[<#{k֑ӌdwc]fmɏ#!=-9VVZ'+է*{wJZ	JtJPlcO 	yа. IC44"{,?Q@N%b5'0f~sVr9r
&9€](Dg&:no' slCMFvYVi9JSXH-]\SRdnzxȨUqf
VPu%
iD),rƦJ*ndUdT]]Aa>ѷH`hMf6Ik/$F7&'I*m2uN`tudƣ:Fq(r^ZSlEpVבXZZY
k6<jG]&D2NBZoLil9
R04R緰)3F`cqʤrR5f2'iq%]ͧ&$&In)¢$GԒ-ʸp/Oaښ8#O.=oq:+{}ܲ==yCφ~0(/Bi?&<_x9VVPGÔqx!wE_!UOo֎k5wBuH2&i-HV.SJ,<TNeZb4J\5.R)Q(DLLe*!asrh"QY0]#J|4YK"%20aPst|>8[iJqŅ#8&`0x&y"?c̃0T4b`zAbX%=l\QZu("UmOQs90NjE0@6YW{/QsU|hOVCc,+2<4
V_͵ZBkcdDBFeJg6*eL!e.ju=(.`3ʪhvD=4,]2b?8 =kcwv3EfZ1H(D6
'Ń+!kQVVocQLZ;;S/{Iv߲G'n7FtGVjE-
1w.!UB'Zխ[#Ym,d2fSWBd=(SVޟxPi "
֭mI#U=`}|^3bwTJqݠ$
lK-D٬qN׉1Jq^5Ogx97go={]rN565A_+we	n`CYTl7C,߈xjE#ҘU5yQHV*>M\p:=ݴN+a##Ύ'		j-=^8p=}9vR|Ӟa"bٔD"tpW\D''sT`i]3uIˠ-mшz\_w^:ܾqys1p}.D4Ms)tyqL&Gd8άWդ_I+dUצM")26WرC*gtf)qrMIzgOP46HAJ|zEʋ@_WC1_͟|	0Md,wND4\&Mj7%j`-Z$p_a1Yr%Qm\:RDifib5_|nud
/r1	P_=fڗ>o?B՞K7堎Q&GRѩ1wTa[5<JN42iT34Oum1G)6z2ncE&ak~gzn#/yDbo>+¶,`!T=
QYga9V\.穄g-
JnFJ&#ǚ|AsB$i3xo"
Ve	=Rfd#H#b$ĿKA*Xme &K{&#P>I<!˥VcK\m`,R/<<A/>LbZSTڰv;?Ry{,U/9Zl.k'-UH;r{D1<9QM9o$?Xd-i;#2ܔ'L.4?̸QrӠOe8G@ۋmr5&Ь[k&kKg'f'q3b,޴`[{NҖޤ
w+n'ɕ4ݜH}Z%PEط(wKPFVr>,٫C#/p0\C<)W~NIpA?,	e/,F$xƔO)i?e׸"2^P\~ue#gLTx9Y#|d^zNoHVIc{ƴLnr93_odʬ:raZDԭ[PVh*cӆ.D	hM߂	G,Rg,ݴOc#+aWd5x"\[-|,fdM Jn~@Q馺ќ@E?[GcbFcp/vF<|/*G>R{o#_#IdŷOP)&}U
:qpB0A:crϯ^7.XtWh	nѹCQ1QAٛzrEk\?/VΑ/ڶW53"o9&gfLSYe/T#~ψ{zعH[ױnŃE7dUXv_?HL=z4JYJg}t׸^9u\fPu5eGe%M`iu?nx矗;mšjPpps|BRAFr"]P*F[3=TpQIڒF	2
\5t@ְʓQ5U
()ٷ"D	?uCN=͈ƘPt~yLoLJctS^dVՄ <2bc
;RKMh
TJ61%k|xݠ֦Rx[}
psh1u'G"Ei
_^a
exm+
/]KɴcE\kdaQ`L4o\F(iB)54*˧Rٱ1:eךi~UB-npNxFװXWQ'00`RrV$ACIh`B0zHcrT.$t%; *x??qD4!t0@v(o mX0uBePu[h-Q3ZbI??hq1wڗ=Y!#BEYex
K:(_5j0l]>%_N F(_Tmx	df,(xu4fEfr帔nt1uդ[mkߘdMu1aR9,U!JƢjm
Sɨ\U9	ES+C@ceZǻ5e]RqZ19LB-Fg#VƱthiSuKTyp#*5jL\4
 +U&7QRdDJX*)$!1cI`bJrWiC!EN@~_o
<$>P5ќG/A&%m4my5k>}_F@@=-+Qk	G)iԕs~uTAQ:N\{D.Y|h
`;|f`3E=nb`v>3=~e>N:7fк_\Zm.]> aG=9|=Hl>Gq3Aȏt(cSᠱ?)aP1AգtG=N>>@Qz?*)gT{=%QTFGAcY3GsP~8ѰwoWV03SH
?GQUcScf@K@6n@IGy&M>Tx?c跰M]Ü[>Msj=lBlX(@06;[:{%O(kP#Pf?-H[8	ͱkΕY=֨RRܓ,Loa'٭(),=ODV=%[sm?<B ِ3N[Ԗ]G'{FY6ߞ!bֵjw%9Wi
/V2ڻjhM%c
:w)"4r)֛tԔ[
{xVP
m#e׎RcG 
zIhHZ){d/Ě5=!_Ϥ+D7y:xB@jC,4c Hm6Z7?<zXJ6<
rՆ=q|{{{
jC&ױcX֞f}]{!M6'+cƧ$0Zq몜{^"` :)sxz~G'z\n:DgQg\ʱ/qwM/8i#3R'a"B+ZoqDlD	ޜK8-D_7X;W~}0D8[*A[c]p`00`/o!#?UY}5xx4Na"9#?I}~p38P=a#@%\;&fB_bVӜiKx~XW[_mGOr"d}]! ^=2_^H<'f'23w&B v>I;Cq\}5˅#Wy8
+s;|z1~zKO/8xئD

<u-"~>^vamS/oƇ7S5OØ=k>J~BH70[Q0@V1o0^ɜ@T^^`Xo/T;{i>L;j><5{+΃>쳟a oEypQ|s}v>>;y``g/>^aQG<#|8ܓv}>
$*``{3΃}^‡w=g>/CϢD`0\dl8.Y^mct&^t,grƵJL'7,ggFOe͡RpiTgO.ALli.i:|k:~/Mu(.eg.}4 }ZlfP77}=LہvB~x^[[fA9~x^z<=V-=d%띲:~nҔ繝/{ai}B~KbނVY=?mnC}lF[M({n]|7"P}PYsӃn֩y$tUݷ|ݮ'~}CgYDm	N`W>а*a<i&/vFїx#,R5lL :g$̋mIxhkꓛ`I~L_W4^s6R](֙As93idb+OX 1Xҋ9ċM-:3]!SIKʠ̸
*UŶd(XF&ys3' uGȟK`f>((zLܜV&|g>̮$9ClGΨ}9C,BPΐ3irf܇yifهrrܜ|g>^`O#gxx~FY9iǩMK[y4)0XE.`]
(
Q0#yy E]0JEgp.`O o<]~_9]ࣹ1ӨעNu(ȫ&c
9?!V =tء^lFs%ypρ{>qq꨸l)௩o?\
zxoMRޗ;]	RF]`D]<b:<ik.blA}0;VRfs;P.%= ]Ţ~ry3.(rɝT۹EOiby.Эo>Pڄ!tMjYe3o[BWIA0OEB\<yyB5ݺ;3iz=̗e"vB_xAfYP sM7	jm!PBƣ<,;HF+$rB+b7d=j!IxE6mY˸`%qUѷc{r=hX\3q_1n83=6d~5+'HݕX)%`~}Y(i!$FFs	.7
|'%e4$!m$ES!v?6t1cտ<VJI!D%o	2,/;$S.|9Zhk\<*o&:3\W򫦟q=v!r='o+|W׼wRL`~Վt?6TO7y	1Aښ~7A8QbNF|鳰ރkz0P?~%.KtD|Gҹ7Hwbx
$J4Bye4_ W`@3{B^Ҫz;J
>5ݏ5,Ձ2/
[@,9[@4N7DKZ	y (#`G>ǀ-wS=hg;v? }!I-o[N_:7DR-:ď7P&:0``0(Zr(P

Anon7 - 2022
AnonSec Team