|
Hello, We have some apps that are located in user's AppData folder and i'm not sure if I'm doing it correctly. After I created and deployed it, it worked. I check the xml file and I saw that there's my username in the policy and it didn't change from %userprofile% or any wildcard. Is this a normal behaviour? will it work if I deploy it to other machines with different user? Thanks in advance |
Replies: 1 comment 14 replies
|
Hi,
When you use Publisher scan level, if a file or log is unsigned, hash rules are automatically created instead (I can provide more customization options for this area if needed). FilePublisher, Publisher or Hash levels don't rely on file paths, so yes, your policy will work on other machines, but just to be sure, can you please tell me where you exactly see the username in the XML policy? Is it in the |
Hi,
Yes, it is a normal behavior.
%userprofile%is not a valid macro, only the following macros are supported by the App Control engine in the OS:%OSDRIVE%,%WINDIR%,%SYSTEM32%. The reason is that an App Control policies applies to the entire system, not user accounts, so if there are more than 1 user accounts,%userprofile%wouldn't be solvable. All of them are only used by File path scan levels/rules.When you use Publisher scan level, if a file or log is unsigned, hash rules are automatically created instead (I can provide more customization options for this area if needed). FilePublisher, Publisher or Hash levels don't rely on file paths, so yes, your policy will work on other machi…