Mar 30 2023 01:39 PM
Hi all,
I've been experiencing with ASR exclusions at several clients with same results...
1. Rules in Audit mode, exclusion added but file keep comming back in report for all exclusions...
2. Using Get-MpPreference on endpoint do not show any exclusion at all
Endpoints are W10/11 22h2
My questions are
1. Do exclusions only get pushed to endpoint on block mode?
2. Exclusions are being added to the asr policy, do i need to set them some place else? GPO?
3. If I create a audit policy and a block policy with different group assignment, setting same exclusions in both. Moving endpoint from the audit group to the block group. Will this work? Ive been told only one asr policy can be in place audit or block....
4. Per rule exclusions, ive been told not to use... not working... is this true?
Thank you
Mar 30 2023 11:49 PM
Apr 20 2023 01:40 PM
Apr 21 2023 04:58 AM
Apr 21 2023 10:58 AM
Apr 21 2023 12:38 PM
Apr 21 2023 01:03 PM
SolutionApr 25 2023 12:30 PM
Apr 26 2023 06:04 AM
Dec 11 2023 01:32 PM - edited Dec 11 2023 01:33 PM
ASR does not work as expected: exceptions on Windows 10 (Update 10/2023) are simply ignored. On Windows 2019 Server they work, but not on Windows 10.
After wasting a lot of time, I removed all the rules, it makes no sense.
Exceptions are reported to the clients via GPO, also get-mpprefence shows the list correctly, but saving a PS Script from OneNote to the any folder will still be blocked:
Pfad: C:\Users\Test\Downloads\myscript.ps1
Prozessname: C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE
Event ID 1121
3B576869-A4EC-4529-8536-B80A7769E899
The exception for onenote.exe is ignored.
After removing this ASR rule, everythink works again
it is really annoying
Dec 24 2023 12:05 AM
Jan 18 2024 12:09 PM
Apr 21 2023 01:03 PM
Solution