How would the Publisher rule approach work in practice? Do we need to run commands on every end-user device to get the publisher name, or should we build this from one reference machine?
How would the Publisher rule approach work in practice? Do we need to run commands on every end-user device to get the publisher name, or should we build this from one reference machine?
Hello,
Thanks for reaching out to Hexnode Connect.
You do not need to collect publisher details from every end-user device. The best practice is to use a single reference machine (like an IT test laptop or VM) where the required applications are installed.
You can identify the exact Publisher value on that Windows reference machine by following these steps:
You can then copy that complete Publisher string and use it when creating your corresponding Windows app rule in Hexnode.
One important note: Hexnode applies these rules through Microsoft’s AppLocker CSP. Once enforced, AppLocker acts as a “deny-by-default” system for that rule category. Make sure you account for all your other required applications (using additional allow rules or suitable wildcards) before pushing the policy, otherwise legitimate desktop apps may be inadvertently blocked.
I hope this helps or resolves your issue. Feel free to reach out if you have any more doubts or need further assistance.
Best regards,
George,
Hexnode UEM
Don't have an account? Sign up