mirror of
https://github.com/Yamato-Security/WELA.git
synced 2026-10-08 23:35:28 +02:00
docs: document native issue coverage
This commit is contained in:
1 parent
94d69b0280
commit
dbabb8eada
5 files changed
+12
No files matched your search
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381)
|
||||
|
||||
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
|
||||
|
||||
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381)
|
||||
|
||||
- Document the versioned offline Intune audit export and assignment limitations. (Related #1)
|
||||
|
||||
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# Native AppLocker readiness
|
||||
|
||||
### Issue 381 coverage
|
||||
|
||||
AppLocker readiness observes the effective policy, AppIDSvc, and native channels before any optional import. Only an operator-supplied audit-only policy may be imported; existing enforcement policies are preserved, and policy state is kept separate from event generation and Sigma eligibility.
|
||||
|
||||
`applocker-readiness` reports local and GP effective policy XML, each of the five rule collections, enforcement modes, rule counts, Application Identity (`AppIDSvc`) state/start mode and relevant AppLocker channel observations. A host with enabled channels but no rules reports `MissingGpPolicy`. Stopped/disabled services, missing channels, unavailable cmdlets and read errors remain explicit. `NotConfigured` with rules is treated as potential enforcement, never as disabled.
|
||||
|
||||
```powershell
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381)
|
||||
|
||||
- バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1)
|
||||
|
||||
- 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2)
|
||||
|
||||
@@ -5,6 +5,8 @@
|
||||
|
||||
## 2.2.0 [2026/xx/xx] - Dev Release
|
||||
|
||||
- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381)
|
||||
|
||||
- Document the versioned offline Intune audit export and assignment limitations. (Related #1)
|
||||
|
||||
- Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)
|
||||
|
||||
Reference in new issue
Block a user