Detection rules › Sigma

Deployment Of The AppX Package Was Blocked By The Policy

Severity
medium
Author
frack113
Source
upstream

Detects an appx package deployment that was blocked by the local computer policy. The following events indicate that an AppX package deployment was blocked by a policy: - Event ID 441: The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy - Event ID 442: Deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps to non-system volumes" policy." - Event ID 453: Package blocked by a platform policy. - Event ID 454: Package blocked by a platform policy.

Event coverage

ProviderEvent IDTitle
AppXDeployment-Server441The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy.
AppXDeployment-Server442Deployment of package PackageFullName to volume MountPoint failed because deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps...
AppXDeployment-Server453Package PackageFullName is blocked by a platform policy: PolicyReason.
AppXDeployment-Server454Package PackageFullName is blocked by a platform policy: PolicyReason.

Stages and Predicates

Stage 1: selection