diff --git a/CHANGELOG-Japanese.md b/CHANGELOG-Japanese.md index ebf3cb2e..63471d27 100644 --- a/CHANGELOG-Japanese.md +++ b/CHANGELOG-Japanese.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4a273d1b..511730e3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2) diff --git a/docs/applocker-readiness.md b/docs/applocker-readiness.md index c5f3737b..ed3709ac 100644 --- a/docs/applocker-readiness.md +++ b/docs/applocker-readiness.md @@ -1,5 +1,9 @@ # Native AppLocker readiness +### Issue 381 coverage + +AppLocker readiness observes the effective policy, AppIDSvc, and native channels before any optional import. Only an operator-supplied audit-only policy may be imported; existing enforcement policies are preserved, and policy state is kept separate from event generation and Sigma eligibility. + `applocker-readiness` reports local and GP effective policy XML, each of the five rule collections, enforcement modes, rule counts, Application Identity (`AppIDSvc`) state/start mode and relevant AppLocker channel observations. A host with enabled channels but no rules reports `MissingGpPolicy`. Stopped/disabled services, missing channels, unavailable cmdlets and read errors remain explicit. `NotConfigured` with rules is treated as potential enforcement, never as disabled. ```powershell diff --git a/website/docs/resources/changelog.ja.md b/website/docs/resources/changelog.ja.md index d050f6c2..4bf86f73 100644 --- a/website/docs/resources/changelog.ja.md +++ b/website/docs/resources/changelog.ja.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- ネイティブ AppLocker 準備状態の確認と、安全な監査専用ポリシー取込の範囲を文書化しました。 (#381) + - バージョン付きオフライン Intune 監査エクスポートと、割り当てに関する制限を文書化しました。 (#1) - 明示的な GPO エクスポート範囲と、ドメイン展開に関する制限を文書化しました。 (#2) diff --git a/website/docs/resources/changelog.md b/website/docs/resources/changelog.md index 3e39476a..27f44b96 100644 --- a/website/docs/resources/changelog.md +++ b/website/docs/resources/changelog.md @@ -5,6 +5,8 @@ ## 2.2.0 [2026/xx/xx] - Dev Release +- Document native AppLocker readiness checks and safe audit-only policy import boundaries. (Related #381) + - Document the versioned offline Intune audit export and assignment limitations. (Related #1) - Document the explicit GPO export scope and its domain-deployment limitations. (Related #2)