├── README.md ├── DeviceConfiguration_Add_Windows_Custom - Storage Sense.ps1 ├── Disabled-ReservedStorage.ps1 ├── Enabled-ReservedStorage.ps1 ├── EnableADAL on Onedrive.ps1 ├── EnableAutoConfig on Onedrive.ps1 ├── Remove Internet Explorer.ps1 ├── IE EnterpriseMode RestrictIE.ps1 ├── OneDrive per machine.ps1 ├── OneDrive for Business Configure.ps1 ├── ActingAdmin1.0.ps1 └── AaronLocker - Intune Config.ps1 /README.md: -------------------------------------------------------------------------------- 1 | # Script_DeployedWithIntune 2 | Scripts that are used with Intune Managment Extentions 3 | -------------------------------------------------------------------------------- /DeviceConfiguration_Add_Windows_Custom - Storage Sense.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/pelarsen/Script_DeployedWithIntune/HEAD/DeviceConfiguration_Add_Windows_Custom - Storage Sense.ps1 -------------------------------------------------------------------------------- /Disabled-ReservedStorage.ps1: -------------------------------------------------------------------------------- 1 | $Storage = Invoke-Command {DISM /Online /Get-ReservedStorageState} 2 | $Output = $Storage | Select-String "Reserved storage is enabled." 3 | Write-Host $Output 4 | If ($Output -like "Reserved storage is enabled."){ 5 | Invoke-Command {DISM /Online /Set-ReservedStorageState /State:Disabled} 6 | } -------------------------------------------------------------------------------- /Enabled-ReservedStorage.ps1: -------------------------------------------------------------------------------- 1 | $Storage = Invoke-Command {DISM /Online /Get-ReservedStorageState} 2 | $Output = $Storage | Select-String "Reserved storage is disabled." 3 | Write-Host $Output 4 | If ($Output -like "Reserved storage is disabled."){ 5 | Invoke-Command {DISM /Online /Set-ReservedStorageState /State:Enabled} 6 | } -------------------------------------------------------------------------------- /EnableADAL on Onedrive.ps1: -------------------------------------------------------------------------------- 1 | $registryPath = "HKCU:\SOFTWARE\Microsoft\OneDrive" 2 | $Name = "EnableADAL" 3 | $value = "1" 4 | IF(!(Test-Path $registryPath)) 5 | { 6 | New-Item -Path $registryPath -Force | Out-Null 7 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 8 | -PropertyType DWORD -Force | Out-Null} 9 | ELSE { 10 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 11 | -PropertyType DWORD -Force | Out-Null} -------------------------------------------------------------------------------- /EnableAutoConfig on Onedrive.ps1: -------------------------------------------------------------------------------- 1 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 2 | $Name = "SilentAccountConfig" 3 | $value = "1" 4 | IF(!(Test-Path $registryPath)) 5 | { 6 | New-Item -Path $registryPath -Force | Out-Null 7 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 8 | -PropertyType DWORD -Force | Out-Null} 9 | ELSE { 10 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 11 | -PropertyType DWORD -Force | Out-Null} 12 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 13 | $Name = "FilesOnDemandEnabled" 14 | $value = "1" 15 | IF(!(Test-Path $registryPath)) 16 | { 17 | New-Item -Path $registryPath -Force | Out-Null 18 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 19 | -PropertyType DWORD -Force | Out-Null} 20 | ELSE { 21 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 22 | -PropertyType DWORD -Force | Out-Null} -------------------------------------------------------------------------------- /Remove Internet Explorer.ps1: -------------------------------------------------------------------------------- 1 | ################################################################################################## 2 | <# 3 | .SYNOPSIS 4 | A script to remove Internet Explorer 5 | 6 | 7 | .NOTES 8 | FileName: Remove Internet Explorer.ps1 9 | Author: Per Larsen 10 | Created: 14-02-2019 11 | Product: Internet Explorer 12 | Version: 1.0 13 | 14 | #> 15 | ################################################################################################### 16 | 17 | #Powershell Script To remove Interner Explorer 18 | #Check If remove Interner Explorer Are Already Installed 19 | $check = Get-WindowsOptionalFeature -Online | Where-Object {$_.FeatureName -eq "Internet-Explorer-Optional-amd64"} 20 | If ($check.State -ne "Disabled") 21 | { 22 | #Remove Internet Explorer 23 | Disable-WindowsOptionalFeature -FeatureName Internet-Explorer-Optional-amd64 -Online -NoRestart | Out-Null 24 | } 25 | 26 | 27 | -------------------------------------------------------------------------------- /IE EnterpriseMode RestrictIE.ps1: -------------------------------------------------------------------------------- 1 | ################################################################################################## 2 | <# 3 | .SYNOPSIS 4 | Script that set a regkey to restrict the use of Internet Explorer 5 | 6 | 7 | .NOTES 8 | FileName: IE EnterpriseMode RestrictIE.ps1 9 | Author: Per Larsen 10 | Created: 14-02-2019 11 | Product: Internet Explorer 12 | Version: 1.0 13 | 14 | #> 15 | ################################################################################################### 16 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\Internet Explorer\Main\EnterpriseMode" 17 | 18 | #Send all sites not included in the Enterprise Mode Site List to Microsoft Edge. 19 | $Name = "RestrictIE" 20 | $value = "1" 21 | IF((Test-Path -LiteralPath $registryPath) -ne $true) 22 | { New-Item $registryPath -force -ea SilentlyContinue }; 23 | New-ItemProperty -LiteralPath $registryPath -Name $Name -Value $value -PropertyType DWord -Force -ea SilentlyContinue; 24 | 25 | 26 | 27 | -------------------------------------------------------------------------------- /OneDrive per machine.ps1: -------------------------------------------------------------------------------- 1 | ################################################################################################## 2 | <# 3 | .SYNOPSIS 4 | Migrate OneDrive for Business from per user to per machine for Intune to run with the Microsoft Intune Management Extention 5 | 6 | 7 | 8 | .NOTES 9 | FileName: OneDrive per machine.ps1 10 | Author: Per Larsen 11 | Created: 24-03-2019 12 | Product: OneDrive for Bussines 13 | Version: 1.0 14 | Blog: https://osddeployment.dk 15 | 16 | #> 17 | ################################################################################################### 18 | 19 | $url = "https://go.microsoft.com/fwlink/?linkid=2083517" 20 | $output = "$ENV:temp" + '\OneDriveSetup.exe' 21 | $O4BPath = "$ENV:localappdata" + 'Microsoft/OneDrive/OneDriveSetup.exe' 22 | 23 | #write $O4BPath 24 | #write $output 25 | 26 | IF(Test-Path $output) 27 | { 28 | 29 | } 30 | ELSE { 31 | Invoke-WebRequest -Uri $url -OutFile $output 32 | } 33 | 34 | IF(!(Test-Path $O4BPath)) 35 | { 36 | & "$output" + '/allusers' 37 | } 38 | ELSE { 39 | 40 | } 41 | 42 | -------------------------------------------------------------------------------- /OneDrive for Business Configure.ps1: -------------------------------------------------------------------------------- 1 | ################################################################################################## 2 | <# 3 | .SYNOPSIS 4 | Policy Definition template file for Intune to run with the Microsoft Intune Management Extention 5 | This policy setup OneDrive For Business with AutoConfigure and KFM 6 | 7 | 8 | .NOTES 9 | FileName: OneDrive for Business Configure.ps1 10 | Author: Per Larsen 11 | Created: 11-07-2018 12 | Product: OneDrive for Business 13 | Version: 1.0 14 | 15 | #> 16 | ################################################################################################### 17 | 18 | $TenantID = "TenantID" 19 | 20 | 21 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 22 | $Name = "SilentAccountConfig" 23 | $value = "1" 24 | IF(!(Test-Path $registryPath)) 25 | { 26 | New-Item -Path $registryPath -Force | Out-Null 27 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 28 | -PropertyType DWORD -Force | Out-Null} 29 | ELSE { 30 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 31 | -PropertyType DWORD -Force | Out-Null} 32 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 33 | $Name = "FilesOnDemandEnabled" 34 | $value = "1" 35 | IF(!(Test-Path $registryPath)) 36 | { 37 | New-Item -Path $registryPath -Force | Out-Null 38 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 39 | -PropertyType DWORD -Force | Out-Null} 40 | ELSE { 41 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 42 | -PropertyType DWORD -Force | Out-Null} 43 | 44 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 45 | $Name = "KFMBlockOptIn" 46 | $value = "1" 47 | IF(!(Test-Path $registryPath)) 48 | { 49 | New-Item -Path $registryPath -Force | Out-Null 50 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 51 | -PropertyType DWORD -Force | Out-Null} 52 | ELSE { 53 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 54 | -PropertyType DWORD -Force | Out-Null} 55 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 56 | $Name = "KFMSilentOptIn" 57 | IF(!(Test-Path $registryPath)) 58 | { 59 | New-Item -Path $registryPath -Force | Out-Null 60 | New-ItemProperty -Path $registryPath -Name $name -Value $TenantID ` 61 | -PropertyType String -Force | Out-Null} 62 | ELSE { 63 | New-ItemProperty -Path $registryPath -Name $name -Value $TenantID ` 64 | -PropertyType String -Force | Out-Null} 65 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 66 | $Name = "KFMSilentOptInWithNotification" 67 | $value = "0" 68 | IF(!(Test-Path $registryPath)) 69 | { 70 | New-Item -Path $registryPath -Force | Out-Null 71 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 72 | -PropertyType DWORD -Force | Out-Null} 73 | ELSE { 74 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 75 | -PropertyType DWORD -Force | Out-Null} 76 | $registryPath = "HKLM:\SOFTWARE\Policies\Microsoft\OneDrive" 77 | $Name = "KFMBlockOptOut" 78 | $value = "1" 79 | IF(!(Test-Path $registryPath)) 80 | { 81 | New-Item -Path $registryPath -Force | Out-Null 82 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 83 | -PropertyType DWORD -Force | Out-Null} 84 | ELSE { 85 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 86 | -PropertyType DWORD -Force | Out-Null} -------------------------------------------------------------------------------- /ActingAdmin1.0.ps1: -------------------------------------------------------------------------------- 1 | # Policy Definition template file for Intune 2 | # Product: Acting Admin 3 | # Version: 1.0.0 4 | # Revision: 1.0.0 5 | 6 | New-Item -Path "HKLM:\Software\Policies\Atea Global Services" -Name "Acting Admin" –Force 7 | $registryPath = "HKLM:\Software\Policies\Atea Global Services\Acting Admin" 8 | 9 | # "SecondsAsAdministratorPrompt" minValue="1" maxValue="3600" 10 | # Determines how many seconds the user should be administrator. 11 | $Name = "SecondsAsAdministrator" 12 | $value = "120" 13 | IF(!(Test-Path $registryPath)) 14 | { 15 | New-Item -Path $registryPath -Force | Out-Null 16 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 17 | -PropertyType DWORD -Force | Out-Null} 18 | ELSE { 19 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 20 | -PropertyType DWORD -Force | Out-Null} 21 | 22 | # "IsExitMenuItemVisible" Enable="1" disable="0" 23 | # Is the menu item “exit” available for the tray icon? 24 | $Name = "IsExitMenuItemVisible" 25 | $value = "1" 26 | IF(!(Test-Path $registryPath)) 27 | { 28 | New-Item -Path $registryPath -Force | Out-Null 29 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 30 | -PropertyType DWORD -Force | Out-Null} 31 | ELSE { 32 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 33 | -PropertyType DWORD -Force | Out-Null} 34 | 35 | # "IsTimeExtendable" Enable="1" disable="0" 36 | # Determines whether the user can extend the time for administrative rights or not. 37 | $Name = "IsTimeExtendable" 38 | $value = "1" 39 | IF(!(Test-Path $registryPath)) 40 | { 41 | New-Item -Path $registryPath -Force | Out-Null 42 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 43 | -PropertyType DWORD -Force | Out-Null} 44 | ELSE { 45 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 46 | -PropertyType DWORD -Force | Out-Null} 47 | 48 | # "IsApplicationEnabled" Enable="1" disable="0" 49 | # If set to false, the application cannot be used to elevate. 50 | $Name = "IsApplicationEnabled" 51 | $value = "1" 52 | IF(!(Test-Path $registryPath)) 53 | { 54 | New-Item -Path $registryPath -Force | Out-Null 55 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 56 | -PropertyType DWORD -Force | Out-Null} 57 | ELSE { 58 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 59 | -PropertyType DWORD -Force | Out-Null} 60 | 61 | # "IsApplicationInsightsDisabled" Enable="1" disable="0" 62 | # If set to true, the application will not send usage and crash information to manufacturer. 63 | $Name = "IsApplicationInsightsDisabled" 64 | $value = "1" 65 | IF(!(Test-Path $registryPath)) 66 | { 67 | New-Item -Path $registryPath -Force | Out-Null 68 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 69 | -PropertyType DWORD -Force | Out-Null} 70 | ELSE { 71 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 72 | -PropertyType DWORD -Force | Out-Null} 73 | 74 | # "VerbosityLevel" Normal="Normal" Debug="Debug" 75 | # If set to Debug, more verbose logging will be written in the Event Log. 76 | $Name = "VerbosityLevel" 77 | $value = "Normal" 78 | IF(!(Test-Path $registryPath)) 79 | { 80 | New-Item -Path $registryPath -Force | Out-Null 81 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 82 | -PropertyType String -Force | Out-Null} 83 | ELSE { 84 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 85 | -PropertyType String -Force | Out-Null} 86 | 87 | # "GroupnameOrSid" 88 | # Name or SID for the group used for elevation. Default value is the wellknown SID for BUILTIN\Administrators 89 | # S-1-5-32-547 is the wellknown SID for BUILTIN\PowerUsers 90 | $Name = "GroupnameOrSid" 91 | $value = "S-1-5-32-544" 92 | IF(!(Test-Path $registryPath)) 93 | { 94 | New-Item -Path $registryPath -Force | Out-Null 95 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 96 | -PropertyType String -Force | Out-Null} 97 | ELSE { 98 | New-ItemProperty -Path $registryPath -Name $name -Value $value ` 99 | -PropertyType String -Force | Out-Null} 100 | 101 | -------------------------------------------------------------------------------- /AaronLocker - Intune Config.ps1: -------------------------------------------------------------------------------- 1 | ################################################################################################## 2 | <# 3 | .SYNOPSIS 4 | This is a script that creates the a AaronLocker baseline 5 | get AaronLocker from https://github.com/Microsoft/AaronLocker 6 | 7 | .NOTES 8 | FileName: AaronLocker - Intune Config.ps1 9 | Author: Per Larsen 10 | Created: 08-12-2019 11 | Product: Aaronlocker with Mobile Device Management 12 | Version: 1.0 13 | 14 | #> 15 | ################################################################################################### 16 | <# 17 | 18 | .COPYRIGHT 19 | Copyright (c) Microsoft Corporation. All rights reserved. Licensed under the MIT license. 20 | See LICENSE in the project root for license information. 21 | 22 | #> 23 | 24 | #################################################### 25 | 26 | function Get-AuthToken { 27 | 28 | <# 29 | .SYNOPSIS 30 | This function is used to authenticate with the Graph API REST interface 31 | .DESCRIPTION 32 | The function authenticate with the Graph API Interface with the tenant name 33 | .EXAMPLE 34 | Get-AuthToken 35 | Authenticates you with the Graph API interface 36 | .NOTES 37 | NAME: Get-AuthToken 38 | #> 39 | 40 | [cmdletbinding()] 41 | 42 | param 43 | ( 44 | [Parameter(Mandatory=$true)] 45 | $User 46 | ) 47 | 48 | $userUpn = New-Object "System.Net.Mail.MailAddress" -ArgumentList $User 49 | 50 | $tenant = $userUpn.Host 51 | 52 | Write-Host "Checking for AzureAD module..." 53 | 54 | $AadModule = Get-Module -Name "AzureAD" -ListAvailable 55 | 56 | if ($AadModule -eq $null) { 57 | 58 | Write-Host "AzureAD PowerShell module not found, looking for AzureADPreview" 59 | $AadModule = Get-Module -Name "AzureADPreview" -ListAvailable 60 | 61 | } 62 | 63 | if ($AadModule -eq $null) { 64 | write-host 65 | write-host "AzureAD Powershell module not installed..." -f Red 66 | write-host "Install by running 'Install-Module AzureAD' or 'Install-Module AzureADPreview' from an elevated PowerShell prompt" -f Yellow 67 | write-host "Script can't continue..." -f Red 68 | write-host 69 | exit 70 | } 71 | 72 | # Getting path to ActiveDirectory Assemblies 73 | # If the module count is greater than 1 find the latest version 74 | 75 | if($AadModule.count -gt 1){ 76 | 77 | $Latest_Version = ($AadModule | select version | Sort-Object)[-1] 78 | 79 | $aadModule = $AadModule | ? { $_.version -eq $Latest_Version.version } 80 | 81 | # Checking if there are multiple versions of the same module found 82 | 83 | if($AadModule.count -gt 1){ 84 | 85 | $aadModule = $AadModule | select -Unique 86 | 87 | } 88 | 89 | $adal = Join-Path $AadModule.ModuleBase "Microsoft.IdentityModel.Clients.ActiveDirectory.dll" 90 | $adalforms = Join-Path $AadModule.ModuleBase "Microsoft.IdentityModel.Clients.ActiveDirectory.Platform.dll" 91 | 92 | } 93 | 94 | else { 95 | 96 | $adal = Join-Path $AadModule.ModuleBase "Microsoft.IdentityModel.Clients.ActiveDirectory.dll" 97 | $adalforms = Join-Path $AadModule.ModuleBase "Microsoft.IdentityModel.Clients.ActiveDirectory.Platform.dll" 98 | 99 | } 100 | 101 | [System.Reflection.Assembly]::LoadFrom($adal) | Out-Null 102 | 103 | [System.Reflection.Assembly]::LoadFrom($adalforms) | Out-Null 104 | 105 | $clientId = "d1ddf0e4-d672-4dae-b554-9d5bdfd93547" 106 | 107 | $redirectUri = "urn:ietf:wg:oauth:2.0:oob" 108 | 109 | $resourceAppIdURI = "https://graph.microsoft.com" 110 | 111 | $authority = "https://login.microsoftonline.com/$Tenant" 112 | 113 | try { 114 | 115 | $authContext = New-Object "Microsoft.IdentityModel.Clients.ActiveDirectory.AuthenticationContext" -ArgumentList $authority 116 | 117 | # https://msdn.microsoft.com/en-us/library/azure/microsoft.identitymodel.clients.activedirectory.promptbehavior.aspx 118 | # Change the prompt behaviour to force credentials each time: Auto, Always, Never, RefreshSession 119 | 120 | $platformParameters = New-Object "Microsoft.IdentityModel.Clients.ActiveDirectory.PlatformParameters" -ArgumentList "Auto" 121 | 122 | $userId = New-Object "Microsoft.IdentityModel.Clients.ActiveDirectory.UserIdentifier" -ArgumentList ($User, "OptionalDisplayableId") 123 | 124 | $authResult = $authContext.AcquireTokenAsync($resourceAppIdURI,$clientId,$redirectUri,$platformParameters,$userId).Result 125 | 126 | # If the accesstoken is valid then create the authentication header 127 | 128 | if($authResult.AccessToken){ 129 | 130 | # Creating header for Authorization token 131 | 132 | $authHeader = @{ 133 | 'Content-Type'='application/json' 134 | 'Authorization'="Bearer " + $authResult.AccessToken 135 | 'ExpiresOn'=$authResult.ExpiresOn 136 | } 137 | 138 | return $authHeader 139 | 140 | } 141 | 142 | else { 143 | 144 | Write-Host 145 | Write-Host "Authorization Access Token is null, please re-run authentication..." -ForegroundColor Red 146 | Write-Host 147 | break 148 | 149 | } 150 | 151 | } 152 | 153 | catch { 154 | 155 | write-host $_.Exception.Message -f Red 156 | write-host $_.Exception.ItemName -f Red 157 | write-host 158 | break 159 | 160 | } 161 | 162 | } 163 | 164 | #################################################### 165 | 166 | Function Add-DeviceConfigurationPolicy(){ 167 | 168 | <# 169 | .SYNOPSIS 170 | This function is used to add an device configuration policy using the Graph API REST interface 171 | .DESCRIPTION 172 | The function connects to the Graph API Interface and adds a device configuration policy 173 | .EXAMPLE 174 | Add-DeviceConfigurationPolicy -JSON $JSON 175 | Adds a device configuration policy in Intune 176 | .NOTES 177 | NAME: Add-DeviceConfigurationPolicy 178 | #> 179 | 180 | [cmdletbinding()] 181 | 182 | param 183 | ( 184 | $JSON 185 | ) 186 | 187 | $graphApiVersion = "Beta" 188 | $DCP_resource = "deviceManagement/deviceConfigurations" 189 | Write-Verbose "Resource: $DCP_resource" 190 | 191 | try { 192 | 193 | if($JSON -eq "" -or $JSON -eq $null){ 194 | 195 | write-host "No JSON specified, please specify valid JSON for the Android Policy..." -f Red 196 | 197 | } 198 | 199 | else { 200 | 201 | Test-JSON -JSON $JSON 202 | 203 | $uri = "https://graph.microsoft.com/$graphApiVersion/$($DCP_resource)" 204 | Invoke-RestMethod -Uri $uri -Headers $authToken -Method Post -Body $JSON -ContentType "application/json" 205 | 206 | } 207 | 208 | } 209 | 210 | catch { 211 | 212 | $ex = $_.Exception 213 | $errorResponse = $ex.Response.GetResponseStream() 214 | $reader = New-Object System.IO.StreamReader($errorResponse) 215 | $reader.BaseStream.Position = 0 216 | $reader.DiscardBufferedData() 217 | $responseBody = $reader.ReadToEnd(); 218 | Write-Host "Response content:`n$responseBody" -f Red 219 | Write-Error "Request to $Uri failed with HTTP Status $($ex.Response.StatusCode) $($ex.Response.StatusDescription)" 220 | write-host 221 | break 222 | 223 | } 224 | 225 | } 226 | 227 | #################################################### 228 | 229 | Function Test-JSON(){ 230 | 231 | <# 232 | .SYNOPSIS 233 | This function is used to test if the JSON passed to a REST Post request is valid 234 | .DESCRIPTION 235 | The function tests if the JSON passed to the REST Post is valid 236 | .EXAMPLE 237 | Test-JSON -JSON $JSON 238 | Test if the JSON is valid before calling the Graph REST interface 239 | .NOTES 240 | NAME: Test-AuthHeader 241 | #> 242 | 243 | param ( 244 | 245 | $JSON 246 | 247 | ) 248 | 249 | try { 250 | 251 | $TestJSON = ConvertFrom-Json $JSON -ErrorAction Stop 252 | $validJson = $true 253 | 254 | } 255 | 256 | catch { 257 | 258 | $validJson = $false 259 | $_.Exception 260 | 261 | } 262 | 263 | if (!$validJson){ 264 | 265 | Write-Host "Provided JSON isn't in valid JSON format" -f Red 266 | break 267 | 268 | } 269 | 270 | } 271 | 272 | #################################################### 273 | 274 | #region Authentication 275 | 276 | write-host 277 | 278 | # Checking if authToken exists before running authentication 279 | if($global:authToken){ 280 | 281 | # Setting DateTime to Universal time to work in all timezones 282 | $DateTime = (Get-Date).ToUniversalTime() 283 | 284 | # If the authToken exists checking when it expires 285 | $TokenExpires = ($authToken.ExpiresOn.datetime - $DateTime).Minutes 286 | 287 | if($TokenExpires -le 0){ 288 | 289 | write-host "Authentication Token expired" $TokenExpires "minutes ago" -ForegroundColor Yellow 290 | write-host 291 | 292 | # Defining User Principal Name if not present 293 | 294 | if($User -eq $null -or $User -eq ""){ 295 | 296 | $User = Read-Host -Prompt "Please specify your user principal name for Azure Authentication" 297 | Write-Host 298 | 299 | } 300 | 301 | $global:authToken = Get-AuthToken -User $User 302 | 303 | } 304 | } 305 | 306 | # Authentication doesn't exist, calling Get-AuthToken function 307 | 308 | else { 309 | 310 | if($User -eq $null -or $User -eq ""){ 311 | 312 | $User = Read-Host -Prompt "Please specify your user principal name for Azure Authentication" 313 | Write-Host 314 | 315 | } 316 | 317 | # Getting the authorization token 318 | $global:authToken = Get-AuthToken -User $User 319 | 320 | } 321 | 322 | #endregion 323 | 324 | 325 | #################################################### 326 | 327 | $Aaronlocker = @" 328 | 329 | { 330 | "@odata.type": "#microsoft.graph.windows10CustomConfiguration", 331 | "id": "3885eed4-a552-46d4-876b-eadbbcf1ef83", 332 | "description": "AaronLocker Enforce configuration for AppLocker Configuration.", 333 | "displayName": "AaronLocker - AppLocker Configuration", 334 | "version": 9, 335 | "omaSettings": [ 336 | { 337 | "@odata.type": "#microsoft.graph.omaSettingStringXml", 338 | "displayName": "AaronLocker Store Apps", 339 | "description": "AppLocker configuration for Microsoft store applications", 340 | "omaUri": "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/StoreAppsGroup/StoreApps/Policy", 341 | "fileName": "AppLockerRules-20191123-2058-Enforce - APPX.xml", 342 | "value": "PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCjxSdWxlQ29sbGVjdGlvbiBUeXBlPSJBcHB4IiBFbmZvcmNlbWVudE1vZGU9IkVuYWJsZWQiPg0KICAgIDxGaWxlUHVibGlzaGVyUnVsZSBJZD0iYTllMThjMjEtZmY4Zi00M2NmLWI5ZmMtZGI0MGVlZDY5M2JhIiBOYW1lPSIoRGVmYXVsdCBSdWxlKSBBbGwgc2lnbmVkIHBhY2thZ2VkIGFwcHMiIERlc2NyaXB0aW9uPSJBbGxvd3MgbWVtYmVycyBvZiB0aGUgRXZlcnlvbmUgZ3JvdXAgdG8gcnVuIHBhY2thZ2VkIGFwcHMgdGhhdCBhcmUgc2lnbmVkLiIgVXNlck9yR3JvdXBTaWQ9IlMtMS0xLTAiIEFjdGlvbj0iQWxsb3ciPg0KICAgICAgPENvbmRpdGlvbnM+DQogICAgICAgIDxGaWxlUHVibGlzaGVyQ29uZGl0aW9uIFB1Ymxpc2hlck5hbWU9IioiIFByb2R1Y3ROYW1lPSIqIiBCaW5hcnlOYW1lPSIqIj4NCiAgICAgICAgICA8QmluYXJ5VmVyc2lvblJhbmdlIExvd1NlY3Rpb249IjAuMC4wLjAiIEhpZ2hTZWN0aW9uPSIqIiAvPg0KICAgICAgICA8L0ZpbGVQdWJsaXNoZXJDb25kaXRpb24+DQogICAgICA8L0NvbmRpdGlvbnM+DQogICAgPC9GaWxlUHVibGlzaGVyUnVsZT4NCiAgPC9SdWxlQ29sbGVjdGlvbj4=" 343 | }, 344 | { 345 | "@odata.type": "#microsoft.graph.omaSettingStringXml", 346 | "displayName": "AaronLocker EXE", 347 | "description": "AppLocker configuration for executables", 348 | "omaUri": "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/EXEGroup/EXE/Policy", 349 | "fileName": "AppLockerRules-20191123-2058-Enforce - EXE.xml", 350 | "value": "<?xml version="1.0" encoding="utf-8"?>
<RuleCollection Type="Exe" EnforcementMode="Enabled">
    <FilePathRule Id="fd686d83-a829-4351-8ff4-27c7de5755d2" Name="(Default Rule) All files" Description="Allows members of the local Administrators group to run all applications." UserOrGroupSid="S-1-5-32-544" Action="Allow">
      <Conditions>
        <FilePathCondition Path="*" />
      </Conditions>
    </FilePathRule>
    <FilePathRule Id="cdfd5d1c-828f-4bd6-9542-1395c6088f82" Name="All files located in the Program Files folder" Description="Allows members of the Everyone group to run applications that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%PROGRAMFILES%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%PROGRAMFILES%\google\chrome\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft onedrive\update\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge beta\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge dev\application\setupmetrics\*" />
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="38080c1b-54bc-4f7e-804d-fafb70bf781b" Name="All files located in the Windows folder" Description="Allows members of the Everyone group to run applications that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%WINDIR%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1\*" />
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1:*" />
        <FilePathCondition Path="%WINDIR%\registration\crmlog\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data:*" />
        <FilePathCondition Path="%SYSTEM32%\com\dmp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\packages\wdagrdpclientappcontainer\ac\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates:*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata\*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata:*" />
        <FilePathCondition Path="%SYSTEM32%\fxstmp\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\drivers\color\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\printers\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\servers\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks_migrated\*" />
        <FilePathCondition Path="%WINDIR%\tasks\*" />
        <FilePathCondition Path="%WINDIR%\temp\*" />
        <FilePathCondition Path="%WINDIR%\tracing\*" />
        <FilePathCondition Path="%WINDIR%\tracing:*" />
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® .NET FRAMEWORK" BinaryName="MSBUILD.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="RUNAS.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® .NET FRAMEWORK" BinaryName="REGSVCS.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="WMIC.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="PRESENTATIONHOST.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="INTERNET EXPLORER" BinaryName="MSHTA.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="CIPHER.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® .NET FRAMEWORK" BinaryName="INSTALLUTIL.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® .NET FRAMEWORK" BinaryName="MICROSOFT.WORKFLOW.COMPILER.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® .NET FRAMEWORK" BinaryName="REGASM.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="f740c3ce-dcd1-439c-b729-489e4b076a75" Name="Additional allowed path: %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" Description="Allows Everyone to execute from %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" />
      </Conditions>
    </FilePathRule>
    <FileHashRule Id="456bd77c-5528-4a93-8ab8-51c6b950c541" Name="Rule set created 2019-11-23 20:58" Description="Never-applicable rule to document that this AppLocker rule set was created via AaronLocker at 2019-11-23 20:58" UserOrGroupSid="S-1-3-0" Action="Deny">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x0000000000000000000000000000000000000000000000000020191123205844" SourceFileName="DateTimeInfo" SourceFileLength="1" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FilePublisherRule Id="dbfec5c5-0376-49bd-87e6-51dc5ca2921a" Name="Microsoft Teams: Signer/product rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT TEAMS" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT TEAMS" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="f493e22c-63a9-4811-ab94-c5d8a8a968f5" Name="BgInfo: Disallow old versions of Sysinternals Bginfo.exe" Description="Disallow Sysinternals Bginfo.exe versions 4.25 and earlier that aren't AppLocker-aware" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="BGINFO" BinaryName="BGINFO.EXE">
          <BinaryVersionRange LowSection="*" HighSection="4.25.0.0" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="f02c38df-c1a7-4e23-af01-1fb6468555f2" Name="OneDrive (Win10 v1607 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in : %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="5695973b-1322-4758-987e-648c072b8987" Name="OneDrive (Win10 v1607 initial state): ONEDRIVESETUP.EXE" Description="Product: WINDOWS LIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\ONEDRIVESETUP.EXE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="WINDOWS LIVE" BinaryName="ONEDRIVESETUP.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FileHashRule Id="9618840d-cd6c-4a76-a6f4-0e7aa24306fc" Name="OneDrive (Win10 v1607 initial state): OneDriveStandaloneUpdater.exe - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\ONEDRIVESTANDALONEUPDATER.EXE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x276CDAADE8E65726684DE00F3AD85D5504BB82512495FA126EB78FA853A5FDA0" SourceFileName="OneDriveStandaloneUpdater.exe" SourceFileLength="493256" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FilePublisherRule Id="3de8ec77-379e-415a-8aa0-731729f75a06" Name="OneDrive (Win10 v1803 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="cc281084-bd23-40ce-b9ca-28ae5a9a4bb0" Name="OneDrive (Win10 v1803 initial state): ONEDRIVESETUP.EXE" Description="Product: WINDOWS LIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313\ONEDRIVESETUP.EXE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="WINDOWS LIVE" BinaryName="ONEDRIVESETUP.EXE">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="8f7ccf65-1a4b-4369-af3d-05f3a1cf9268" Name="OneDrive (Win10 v1809 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
  </RuleCollection>" 351 | }, 352 | { 353 | "@odata.type": "#microsoft.graph.omaSettingStringXml", 354 | "displayName": "AaronLocker MSI", 355 | "description": "AppLocker configuration for MSIs", 356 | "omaUri": "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/MSIGroup/MSI/Policy", 357 | "fileName": "AppLockerRules-20191123-2058-Enforce - MSI.xml", 358 | "value": "PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4NCjxSdWxlQ29sbGVjdGlvbiBUeXBlPSJNc2kiIEVuZm9yY2VtZW50TW9kZT0iRW5hYmxlZCI+DQogICAgPEZpbGVQYXRoUnVsZSBJZD0iYzY0ZTUyZmUtYmQwNS00M2VkLWFlOTEtZjM2MTIxODI4MjllIiBOYW1lPSJBbGwgV2luZG93cyBJbnN0YWxsZXIgZmlsZXMgdW5kZXIgJXdpbmRpciVcY2NtY2FjaGUiIERlc2NyaXB0aW9uPSJBbGxvd3MgZXZlcnlvbmUgdG8gcnVuIGluc3RhbGxlciBmaWxlcyBpbiB0aGUgU0NDTSBjYWNoZS4iIFVzZXJPckdyb3VwU2lkPSJTLTEtMS0wIiBBY3Rpb249IkFsbG93Ij4NCiAgICAgIDxDb25kaXRpb25zPg0KICAgICAgICA8RmlsZVBhdGhDb25kaXRpb24gUGF0aD0iJVdJTkRJUiVcY2NtY2FjaGVcKiIgLz4NCiAgICAgIDwvQ29uZGl0aW9ucz4NCiAgICA8L0ZpbGVQYXRoUnVsZT4NCiAgICA8RmlsZVBhdGhSdWxlIElkPSI1YjI5MDE4NC0zNDVhLTQ0NTMtYjE4NC00NTMwNWY2ZDlhNTQiIE5hbWU9IihEZWZhdWx0IFJ1bGUpIEFsbCBXaW5kb3dzIEluc3RhbGxlciBmaWxlcyBpbiAlc3lzdGVtZHJpdmUlXFdpbmRvd3NcSW5zdGFsbGVyIiBEZXNjcmlwdGlvbj0iQWxsb3dzIG1lbWJlcnMgb2YgdGhlIEV2ZXJ5b25lIGdyb3VwIHRvIHJ1biBhbGwgV2luZG93cyBJbnN0YWxsZXIgZmlsZXMgbG9jYXRlZCBpbiAlc3lzdGVtZHJpdmUlXFdpbmRvd3NcSW5zdGFsbGVyLiIgVXNlck9yR3JvdXBTaWQ9IlMtMS0xLTAiIEFjdGlvbj0iQWxsb3ciPg0KICAgICAgPENvbmRpdGlvbnM+DQogICAgICAgIDxGaWxlUGF0aENvbmRpdGlvbiBQYXRoPSIlV0lORElSJVxJbnN0YWxsZXJcKiIgLz4NCiAgICAgIDwvQ29uZGl0aW9ucz4NCiAgICA8L0ZpbGVQYXRoUnVsZT4NCiAgICA8RmlsZVBhdGhSdWxlIElkPSI2NGFkNDZmZi0wZDcxLTRmYTAtYTMwYi0zZjNkMzBjNTQzM2QiIE5hbWU9IihEZWZhdWx0IFJ1bGUpIEFsbCBXaW5kb3dzIEluc3RhbGxlciBmaWxlcyIgRGVzY3JpcHRpb249IkFsbG93cyBtZW1iZXJzIG9mIHRoZSBsb2NhbCBBZG1pbmlzdHJhdG9ycyBncm91cCB0byBydW4gYWxsIFdpbmRvd3MgSW5zdGFsbGVyIGZpbGVzLiIgVXNlck9yR3JvdXBTaWQ9IlMtMS01LTMyLTU0NCIgQWN0aW9uPSJBbGxvdyI+DQogICAgICA8Q29uZGl0aW9ucz4NCiAgICAgICAgPEZpbGVQYXRoQ29uZGl0aW9uIFBhdGg9IiouKiIgLz4NCiAgICAgIDwvQ29uZGl0aW9ucz4NCiAgICA8L0ZpbGVQYXRoUnVsZT4NCiAgICA8RmlsZVB1Ymxpc2hlclJ1bGUgSWQ9IjFlZjUzZDIxLWIzMjgtNDc3ZS04YmUzLTJlZmRjMDMxZmJlOCIgTmFtZT0iTWljcm9zb2Z0IFRlYW1zOiBTaWduZXIvcHJvZHVjdCBydWxlIGZvciBPPU1JQ1JPU09GVCBDT1JQT1JBVElPTiwgTD1SRURNT05ELCBTPVdBU0hJTkdUT04sIEM9VVMvTUlDUk9TT0ZUIFRFQU1TIiBEZXNjcmlwdGlvbj0iSW5mb3JtYXRpb24gYWNxdWlyZWQgZnJvbSBUcnVzdGVkU2lnbmVycy5wczEiIFVzZXJPckdyb3VwU2lkPSJTLTEtMS0wIiBBY3Rpb249IkFsbG93Ij4NCiAgICAgIDxDb25kaXRpb25zPg0KICAgICAgICA8RmlsZVB1Ymxpc2hlckNvbmRpdGlvbiBQdWJsaXNoZXJOYW1lPSJPPU1JQ1JPU09GVCBDT1JQT1JBVElPTiwgTD1SRURNT05ELCBTPVdBU0hJTkdUT04sIEM9VVMiIFByb2R1Y3ROYW1lPSJNSUNST1NPRlQgVEVBTVMiIEJpbmFyeU5hbWU9IioiPg0KICAgICAgICAgIDxCaW5hcnlWZXJzaW9uUmFuZ2UgTG93U2VjdGlvbj0iKiIgSGlnaFNlY3Rpb249IioiIC8+DQogICAgICAgIDwvRmlsZVB1Ymxpc2hlckNvbmRpdGlvbj4NCiAgICAgIDwvQ29uZGl0aW9ucz4NCiAgICA8L0ZpbGVQdWJsaXNoZXJSdWxlPg0KICAgIDxGaWxlUHVibGlzaGVyUnVsZSBJZD0iOTgxMzkyZTQtYmMyMy00MGM2LWJiOGUtZjljZmVhZWI1Y2M1IiBOYW1lPSJNaWNyb3NvZnQtc2lnbmVkIE1TSSBmaWxlczogU2lnbmVyIHJ1bGUgZm9yIE89TUlDUk9TT0ZUIENPUlBPUkFUSU9OLCBMPVJFRE1PTkQsIFM9V0FTSElOR1RPTiwgQz1VUyIgRGVzY3JpcHRpb249IkluZm9ybWF0aW9uIGFjcXVpcmVkIGZyb20gVHJ1c3RlZFNpZ25lcnMucHMxIiBVc2VyT3JHcm91cFNpZD0iUy0xLTEtMCIgQWN0aW9uPSJBbGxvdyI+DQogICAgICA8Q29uZGl0aW9ucz4NCiAgICAgICAgPEZpbGVQdWJsaXNoZXJDb25kaXRpb24gUHVibGlzaGVyTmFtZT0iTz1NSUNST1NPRlQgQ09SUE9SQVRJT04sIEw9UkVETU9ORCwgUz1XQVNISU5HVE9OLCBDPVVTIiBQcm9kdWN0TmFtZT0iKiIgQmluYXJ5TmFtZT0iKiI+DQogICAgICAgICAgPEJpbmFyeVZlcnNpb25SYW5nZSBMb3dTZWN0aW9uPSIqIiBIaWdoU2VjdGlvbj0iKiIgLz4NCiAgICAgICAgPC9GaWxlUHVibGlzaGVyQ29uZGl0aW9uPg0KICAgICAgPC9Db25kaXRpb25zPg0KICAgIDwvRmlsZVB1Ymxpc2hlclJ1bGU+DQogIDwvUnVsZUNvbGxlY3Rpb24+" 359 | }, 360 | { 361 | "@odata.type": "#microsoft.graph.omaSettingStringXml", 362 | "displayName": "AaronLocker Script", 363 | "description": "AppLocker Configuration for scripts", 364 | "omaUri": "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/ScriptGroup/Script/Policy", 365 | "fileName": "AppLockerRules-20191123-2058-Enforce - SCRIPT.xml", 366 | "value": "<?xml version="1.0" encoding="utf-8"?>
<RuleCollection Type="Script" EnforcementMode="Enabled">
    <FilePathRule Id="ed97d0cb-15ff-430f-b82c-8d7832957725" Name="(Default Rule) All scripts" Description="Allows members of the local Administrators group to run all scripts." UserOrGroupSid="S-1-5-32-544" Action="Allow">
      <Conditions>
        <FilePathCondition Path="*" />
      </Conditions>
    </FilePathRule>
    <FilePathRule Id="742c089a-d5bc-4f1e-98dc-2535b7b164b5" Name="All scripts located in the Program Files folder" Description="Allows members of the Everyone group to run scripts that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%PROGRAMFILES%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%PROGRAMFILES%\google\chrome\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft onedrive\update\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge beta\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge dev\application\setupmetrics\*" />
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="2d2e2715-50d1-4f32-9885-7c935e189f44" Name="All scripts located in the Windows folder" Description="Allows members of the Everyone group to run scripts that are located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%WINDIR%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1\*" />
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1:*" />
        <FilePathCondition Path="%WINDIR%\registration\crmlog\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data:*" />
        <FilePathCondition Path="%SYSTEM32%\com\dmp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\packages\wdagrdpclientappcontainer\ac\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates:*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata\*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata:*" />
        <FilePathCondition Path="%SYSTEM32%\fxstmp\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\drivers\color\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\printers\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\servers\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks_migrated\*" />
        <FilePathCondition Path="%WINDIR%\tasks\*" />
        <FilePathCondition Path="%WINDIR%\temp\*" />
        <FilePathCondition Path="%WINDIR%\tracing\*" />
        <FilePathCondition Path="%WINDIR%\tracing:*" />
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="ba96c4cd-fcdb-408e-9d4f-ba63f4ef60eb" Name="Additional allowed path: %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" Description="Allows Everyone to execute from %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" />
      </Conditions>
    </FilePathRule>
    <FilePublisherRule Id="99890aed-4d8e-46f4-a304-1abb7bc2d39b" Name="Microsoft Teams: Signer/product rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT TEAMS" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT TEAMS" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="e597b29f-9f3d-457f-9ee7-20eaa46d9803" Name="Microsoft-signed script files: Signer rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="*" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FileHashRule Id="f2f1e717-bb1b-4d6a-81c2-37e295edbf4f" Name="OneDrive (Win10 v1607 initial state): CollectOneDriveLogs.bat - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\COLLECTONEDRIVELOGS.BAT" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0xCDFC28618E8831CFA2F2487587CC55F40D6868A4F912763738A5975EC5F490AB" SourceFileName="CollectOneDriveLogs.bat" SourceFileLength="5850" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="ac60014e-2a29-45da-abc6-e3bed54652fd" Name="OneDrive (Win10 v1803 initial state): OneDrivePersonal.cmd - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\ONEDRIVEPERSONAL.CMD" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x69A17A4899E1AD3E5FF42F7A24DD47C5130DBAD2CDEE7E3C8FBFDB238F5A20EE" SourceFileName="OneDrivePersonal.cmd" SourceFileLength="77" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="28e55e5d-f553-4be1-b1a6-d5c98701b817" Name="OneDrive (Win10 v1809 initial state): CollectSyncLogs.bat - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002\COLLECTSYNCLOGS.BAT" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x3702A8CFC028A01B06A1E43354F02C99836EEF07F8876D4626DEF966446062AF" SourceFileName="CollectSyncLogs.bat" SourceFileLength="6420" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
  </RuleCollection>" 367 | }, 368 | { 369 | "@odata.type": "#microsoft.graph.omaSettingStringXml", 370 | "displayName": "AaronLocker DLL", 371 | "description": "AppLocker configuration for DLLs", 372 | "omaUri": "./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/DLLGroup/DLL/Policy", 373 | "fileName": "AppLockerRules-20191123-2058-Enforce - DLL.xml", 374 | "value": "<?xml version="1.0" encoding="utf-8"?>
<RuleCollection Type="Dll" EnforcementMode="Enabled">
    <FilePublisherRule Id="0645a114-e55a-4d95-9511-5905489867c6" Name="Disallow PowerShell v2" Description="Explicitly deny signed DLLs needed for PowerShell v2 (implicitly allow 10.* and above)" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT (R) WINDOWS (R) OPERATING SYSTEM" BinaryName="SYSTEM.MANAGEMENT.AUTOMATION.DLL">
          <BinaryVersionRange LowSection="*" HighSection="9.9.9.9" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePathRule Id="fe64f59f-6fca-45e5-a731-0f6715327c38" Name="(Default Rule) All DLLs" Description="Allows members of the local Administrators group to load all DLLs." UserOrGroupSid="S-1-5-32-544" Action="Allow">
      <Conditions>
        <FilePathCondition Path="*" />
      </Conditions>
    </FilePathRule>
    <FilePathRule Id="860f0fa5-afd9-4929-880b-cf0c6f052c67" Name="Microsoft Windows DLLs" Description="Allows members of the Everyone group to load DLLs located in the Windows folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%WINDIR%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1\*" />
        <FilePathCondition Path="%WINDIR%\imecache\11a18dbc-ab21-496d-90d4-98b37ffdd7d4_1:*" />
        <FilePathCondition Path="%WINDIR%\registration\crmlog\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\detectionverificationdrv\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\esif_umdf2\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\helloface\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\hidovergatt\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorscx0102\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\sensorshidclassdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacebase2fwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedialdetection\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedockfwupdate\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacedtxdriver\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacekeyboardbacklight\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacepenpairing\data:*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data\*" />
        <FilePathCondition Path="%WINDIR%\servicestate\surfacesarmanager\data:*" />
        <FilePathCondition Path="%SYSTEM32%\com\dmp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\credentials:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\crypto\pcpksp:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\cloudapcache:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\microsoft\windows\notifications:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\packages\wdagrdpclientappcontainer\ac\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\local\policymanager:*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates\*" />
        <FilePathCondition Path="%SYSTEM32%\config\systemprofile\appdata\roaming\microsoft\systemcertificates\my\certificates:*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata\*" />
        <FilePathCondition Path="%SYSTEM32%\drivers\driverdata:*" />
        <FilePathCondition Path="%SYSTEM32%\fxstmp\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\drivers\color\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\printers\*" />
        <FilePathCondition Path="%SYSTEM32%\spool\servers\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks\*" />
        <FilePathCondition Path="%SYSTEM32%\tasks_migrated\*" />
        <FilePathCondition Path="%WINDIR%\tasks\*" />
        <FilePathCondition Path="%WINDIR%\temp\*" />
        <FilePathCondition Path="%WINDIR%\tracing\*" />
        <FilePathCondition Path="%WINDIR%\tracing:*" />
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="e431d080-a8e3-48d6-904b-19bda95b3fb7" Name="All DLLs located in the Program Files folder" Description="Allows members of the Everyone group to load DLLs that are located in the Program Files folder." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%PROGRAMFILES%\*" />
      </Conditions>
      <Exceptions>
        <FilePathCondition Path="%PROGRAMFILES%\google\chrome\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft onedrive\update\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge beta\application\setupmetrics\*" />
        <FilePathCondition Path="%PROGRAMFILES%\microsoft\edge dev\application\setupmetrics\*" />
      </Exceptions>
    </FilePathRule>
    <FilePathRule Id="4f39bf10-f9ea-49d5-ba26-55535ba5fb35" Name="Disallow PowerShell v2" Description="Explicitly deny unsigned JIT native images needed for PowerShell v2" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions>
        <FilePathCondition Path="%WINDIR%\assembly\NativeImages_v2.0.50727_32\System.Management.A#\*" />
      </Conditions>
    </FilePathRule>
    <FilePathRule Id="31d0a17e-420f-4b79-953f-d681fd69289f" Name="Disallow PowerShell v2" Description="Explicitly deny unsigned JIT native images needed for PowerShell v2" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions>
        <FilePathCondition Path="%WINDIR%\assembly\NativeImages_v2.0.50727_64\System.Management.A#\*" />
      </Conditions>
    </FilePathRule>
    <FilePathRule Id="6e919915-1c20-4ba7-b206-e921b74ea128" Name="Additional allowed path: %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" Description="Allows Everyone to execute from %OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePathCondition Path="%OSDRIVE%\PROGRAMDATA\MICROSOFT\WINDOWS DEFENDER\PLATFORM\*" />
      </Conditions>
    </FilePathRule>
    <FilePublisherRule Id="d6fe43f6-9b75-4c9e-8575-dd19bfd7180f" Name="Microsoft Teams: Signer/product rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT TEAMS" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT TEAMS" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="1b167c59-1cd9-4662-a626-502fac71d386" Name="Allow selected files from %OSDRIVE%\.~BT\SOURCES during Windows upgrade: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® WINDOWS® OPERATING SYSTEM/GENERALTEL.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="GENERALTEL.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="d438920d-c267-4c5e-8b29-064b32e94f24" Name="Allow selected files from %OSDRIVE%\.~BT\SOURCES during Windows upgrade: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® WINDOWS® OPERATING SYSTEM/WDSCORE.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="WDSCORE.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="a5f00981-733b-416a-9ad3-3746f765263b" Name="Allow selected files from %OSDRIVE%\.~BT\SOURCES during Windows upgrade: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® WINDOWS® OPERATING SYSTEM/AEINV.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="AEINV.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="38155903-1ea4-41fa-a353-4cea45f0c817" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2005/MSVCP80.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2005" BinaryName="MSVCP80.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="569a3bcf-4b7f-4cd1-a0a6-d13119f7e3e7" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2005/MSVCR80.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2005" BinaryName="MSVCR80.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="50ca90ad-0d29-49fe-a24b-2ce84ef84545" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2008/MFC90U.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2008" BinaryName="MFC90U.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="0d23eb78-1437-465e-96cf-34af4ff97f84" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2008/MSVCP90.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2008" BinaryName="MSVCP90.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="5ac07c2d-fefe-40da-a978-1a915287dda9" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2008/MSVCR90.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2008" BinaryName="MSVCR90.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="daf3348e-5b20-4033-9f86-a16daf869812" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2010/MSVCP100.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2010" BinaryName="MSVCP100.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="623eebba-02ea-440b-a443-1e1416883afd" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2010/MSVCR100_CLR0400.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2010" BinaryName="MSVCR100_CLR0400.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="9b44523b-63ad-4a76-9bdb-9d0fbaa82ef8" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2012/MFC110.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2012" BinaryName="MFC110.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="54c5268d-6d38-4d9a-a334-4f785af77ec9" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2012/MSVCP110.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2012" BinaryName="MSVCP110.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="7cf15398-c461-4f19-8569-1e5f347c6af0" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2012/MSVCR110.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2012" BinaryName="MSVCR110.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="53590be5-5c23-4684-b44d-71a64c35b93d" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2013/MFC120.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2013" BinaryName="MFC120.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="7caa5a46-0d5e-41f9-8331-51cf67a712c7" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2013/MFC120U.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2013" BinaryName="MFC120U.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="9a100441-cfb3-411c-8b80-7eb6004c9c60" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2013/MSVCP120.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2013" BinaryName="MSVCP120.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="8ec6cd2f-353d-49d6-9956-05086258d025" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2013/MSVCR120.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2013" BinaryName="MSVCR120.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="bf838966-9db1-4414-a570-1efd149953bf" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2015/MSVCP140.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2015" BinaryName="MSVCP140.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="3e268617-18ae-4d20-a1bb-c766e2c5d2d2" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2015/VCRUNTIME140.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2015" BinaryName="VCRUNTIME140.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="fe7bd1d0-753b-4f30-90a4-e41d08f704ce" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2015/MFC140U.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2015" BinaryName="MFC140U.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="6122f6fe-b8de-4480-9485-9c4abcd0ce80" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2017/MSVCP140.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2017" BinaryName="MSVCP140.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="78670fba-2d4f-44f4-98ba-99f7aac39872" Name="MSVC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2017/VCRUNTIME140.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2017" BinaryName="VCRUNTIME140.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="48b91b8f-efd4-4a3a-b85b-55a424efb2dd" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 2017/MFC140.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 2017" BinaryName="MFC140.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="a1bdd0e3-228f-4c60-8acc-bb571041faa1" Name="MFC runtime DLL: Signer/product/file rule for O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US/MICROSOFT® VISUAL STUDIO® 10/MFC100U.DLL" Description="Information acquired from TrustedSigners.ps1" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® VISUAL STUDIO® 10" BinaryName="MFC100U.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="d7c7a2b8-4086-465d-9a39-f1802c0099cc" Name="Google Chrome's Flash Player v26.0.0.137 and above" Description="Custom hand-edited because of a bug in AppLocker's PowerShell cmdlets. Signed by O=ADOBE SYSTEMS INCORPORATED, L=SAN JOSE, S=CALIFORNIA, C=US.&#xD;&#xA;Original path: C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\PepperFlash\26.0.0.137\pepflashplayer.dll." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=ADOBE SYSTEMS INCORPORATED, L=SAN JOSE, S=CALIFORNIA, C=US" ProductName="" BinaryName="">
          <BinaryVersionRange LowSection="26.0.0.137" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="61b52edb-cfad-47ad-9e83-14c2a1c05667" Name="Google Chrome's Flash Player v32.0.0.171 and above" Description="Custom hand-edited because of a bug in AppLocker's PowerShell cmdlets. Signed by O=ADOBE INC., L=SAN JOSE, S=CA, C=US.&#xD;&#xA;Original path: C:\Users\USERNAME\AppData\Local\Google\Chrome\User Data\PepperFlash\32.0.0.171\pepflashplayer.dll." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=ADOBE INC., L=SAN JOSE, S=CA, C=US" ProductName="" BinaryName="">
          <BinaryVersionRange LowSection="32.0.0.171" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="1b6125fd-2373-471e-9bcf-0530111bb2ef" Name="OneDrive (Win10 v1607 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in : %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="5c53b2b7-dcbe-48f8-b4fa-b3f4b4b014f8" Name="OneDrive (Win10 v1607 initial state): SQMAPI.DLL" Description="Product: MICROSOFT® WINDOWS® OPERATING SYSTEM&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\SQMAPI.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="SQMAPI.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="1899501c-2fac-43e3-83c4-46e81b8d9563" Name="OneDrive (Win10 v1607 initial state): ETWLOG.DLL" Description="Product: WINDOWS LIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\ETWLOG.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="WINDOWS LIVE" BinaryName="ETWLOG.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FileHashRule Id="0eaf08a8-2acf-41f4-9f9e-36ea8b1e0310" Name="OneDrive (Win10 v1607 initial state): FileCoAuthLib.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\FILECOAUTHLIB.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0xB9C37DE4028829EAEAB1C8DA9B6B3CD9502462D76C3D92E93341D9232C6AB880" SourceFileName="FileCoAuthLib.dll" SourceFileLength="26816" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="925fc4ee-da59-4bac-9ff1-b2c4ae55830a" Name="OneDrive (Win10 v1607 initial state): ClientTelemetry.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\CLIENTTELEMETRY.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x7702129FA5E7E5790FB11F4006F724844D8E3F6ACA6B4DFC2700F726561035D0" SourceFileName="ClientTelemetry.dll" SourceFileLength="679624" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="4b5a9475-90b3-43aa-b943-c64ec9e96d2b" Name="OneDrive (Win10 v1607 initial state): ClientTelemetry.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\AMD64\CLIENTTELEMETRY.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x193744053F117D24FAC50F05D21CC5AD5F57E29F1FAF1EC1850610B8ABCB834E" SourceFileName="ClientTelemetry.dll" SourceFileLength="959168" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="9d6522b1-0cd0-4d61-a59c-bcb21bf64ff7" Name="OneDrive (Win10 v1607 initial state): FileCoAuthLib64.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6381.0405\AMD64\FILECOAUTHLIB64.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x77618980B668364F7C27A45E36A58D456E9F2D41852B2666F886DE9728BA32BD" SourceFileName="FileCoAuthLib64.dll" SourceFileLength="31936" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FilePublisherRule Id="5071b459-2051-41fd-bfcf-40b798b39d15" Name="OneDrive (Win10 v1803 initial state): MICROSOFT® ADAL" Description="Product: MICROSOFT® ADAL&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® ADAL" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="12e989f0-5c71-403b-af6f-34696433e79a" Name="OneDrive (Win10 v1803 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="60cb506e-df9b-48d3-8c4b-092b18397e67" Name="OneDrive (Win10 v1803 initial state): QT5" Description="Product: QT5&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="QT5" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="dbd41e34-402b-4e2f-944c-545670035c59" Name="OneDrive (Win10 v1803 initial state): QT QUICK 2D RENDERER (QT 5.7.0)" Description="Product: QT QUICK 2D RENDERER (QT 5.7.0)&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="QT QUICK 2D RENDERER (QT 5.7.0)" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="163349b2-d660-4a3b-b17a-4c113c765773" Name="OneDrive (Win10 v1803 initial state): SQMAPI.DLL" Description="Product: MICROSOFT® WINDOWS® OPERATING SYSTEM&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313\SQMAPI.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="SQMAPI.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="694104ff-f175-40a7-a9c5-9cc503eae24c" Name="OneDrive (Win10 v1803 initial state): ETWLOG.DLL" Description="Product: WINDOWS LIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313\ETWLOG.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="WINDOWS LIVE" BinaryName="ETWLOG.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FileHashRule Id="33ec42cf-0875-42b7-b4a5-59629516606b" Name="OneDrive (Win10 v1803 initial state): libGLESv2.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313\LIBGLESV2.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0x1AA358B0772081FACDCF7D4E6F8432E085A3A62D8813E0EBF5185296F1FFF4E7" SourceFileName="libGLESv2.dll" SourceFileLength="2005632" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FileHashRule Id="d76fc55c-386a-46ef-8183-a7c2233fe115" Name="OneDrive (Win10 v1803 initial state): libEGL.dll - HASH RULE" Description="Identified in: %OSDRIVE%\USERS\testuser\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\17.3.6816.0313\LIBEGL.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FileHashCondition>
          <FileHash Type="SHA256" Data="0xB12D338844E4DCDFAD8CDFC9B250361C0AED871225AA053C2DA87178D82DAD7A" SourceFileName="libEGL.dll" SourceFileLength="26752" />
        </FileHashCondition>
      </Conditions>
    </FileHashRule>
    <FilePublisherRule Id="f294511b-c197-481a-ad0e-f4cb7b4f9fcc" Name="OneDrive (Win10 v1809 initial state): MICROSOFT ONEDRIVE" Description="Product: MICROSOFT ONEDRIVE&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT ONEDRIVE" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="558016fe-88c2-4e6e-ac81-4996ecd82b75" Name="OneDrive (Win10 v1809 initial state): LIBEGL" Description="Product: LIBEGL&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="LIBEGL" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="fc1d10ac-4f36-4221-9a01-8397ddd81d7b" Name="OneDrive (Win10 v1809 initial state): LIBGLESV2" Description="Product: LIBGLESV2&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="LIBGLESV2" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="f16b3006-2816-4524-aa4a-ee31ae61272d" Name="OneDrive (Win10 v1809 initial state): MICROSOFT AD RMS" Description="Product: MICROSOFT AD RMS&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT AD RMS" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="53a25cb3-dbff-496c-a87d-4e8fa3cc2da3" Name="OneDrive (Win10 v1809 initial state): MICROSOFT© ADAL" Description="Product: MICROSOFT© ADAL&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT© ADAL" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="44d69c96-a3bb-44ea-8db4-99df69883ddf" Name="OneDrive (Win10 v1809 initial state): MICROSOFT.OFFICE.IRM.MSOPROTECTOR" Description="Product: MICROSOFT.OFFICE.IRM.MSOPROTECTOR&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT.OFFICE.IRM.MSOPROTECTOR" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="b7d0363b-e9cd-42e0-b24f-b83beaf38b4d" Name="OneDrive (Win10 v1809 initial state): MICROSOFT.OFFICE.IRM.OFCPROTECTOR" Description="Product: MICROSOFT.OFFICE.IRM.OFCPROTECTOR&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT.OFFICE.IRM.OFCPROTECTOR" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="de951a56-3748-448e-abcf-0638e7588994" Name="OneDrive (Win10 v1809 initial state): MICROSOFT.OFFICE.IRM.PDFPROTECTOR" Description="Product: MICROSOFT.OFFICE.IRM.PDFPROTECTOR&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT.OFFICE.IRM.PDFPROTECTOR" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="a6fa74fa-ecb6-4b5e-bec0-87b2a1b5d93d" Name="OneDrive (Win10 v1809 initial state): THE OPENSSL TOOLKIT" Description="Product: THE OPENSSL TOOLKIT&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="THE OPENSSL TOOLKIT" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="de6f943f-a4df-4c43-bc1a-93930f97e79c" Name="OneDrive (Win10 v1809 initial state): QT5" Description="Product: QT5&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;File(s) found in: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="QT5" BinaryName="*">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="1316b862-9b71-413b-b67c-624587d3dd9d" Name="OneDrive (Win10 v1809 initial state): APISETSTUB" Description="Product: MICROSOFT® WINDOWS® OPERATING SYSTEM&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002\API-MS-WIN-CORE-CONSOLE-L1-1-0.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="APISETSTUB">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
    <FilePublisherRule Id="295101fd-6030-4ac2-b938-235855af29c1" Name="OneDrive (Win10 v1809 initial state): UCRTBASE.DLL" Description="Product: MICROSOFT® WINDOWS® OPERATING SYSTEM&#xD;&#xA;Publisher: O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US&#xD;&#xA;Original path: %OSDRIVE%\USERS\ABBY\APPDATA\LOCAL\MICROSOFT\ONEDRIVE\18.143.0717.0002\UCRTBASE.DLL" UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
        <FilePublisherCondition PublisherName="O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US" ProductName="MICROSOFT® WINDOWS® OPERATING SYSTEM" BinaryName="UCRTBASE.DLL">
          <BinaryVersionRange LowSection="*" HighSection="*" />
        </FilePublisherCondition>
      </Conditions>
    </FilePublisherRule>
  </RuleCollection>" 375 | } 376 | ] 377 | } 378 | 379 | 380 | "@ 381 | #################################################### 382 | 383 | Add-DeviceConfigurationPolicy -Json $Aaronlocker 384 | 385 | 386 | 387 | 388 | --------------------------------------------------------------------------------