Are you coming across AppLocker error after installing an update in Windows 10 or 11? Several users complain about “This app has been blocked by your system administrator” after they received KB5019959 and KB5019980, 08 November 2022 Security patch. When launching the Store apps or start menu this error message appears restricting their access.
We have already written a post in this concern, Fix This app has been blocked by your system administrator Error in Windows 11. But if the solutions there don’t work, follow the methods here to get rid of the AppLocker error message. This problem prevents users from accessing Start menu and Store apps. The issue occurs even when the AppLocker enforcement is disabled.
Table of Contents
This app has been blocked by your system administrator Applocker KB5019980, KB5019959
Here is how to fix Applocker Error after KB5019959, KB5019980 in Windows 10, 11 –
Way-1: Create Default Rules in Local Security Policy
This error pops up because of AppLocker which can help you determine if your organization can benefit from deploying application control policies. Generally, you enforce AppLocker to run and at the same time you don’t want anything to be prohibited.
For this, you will require clicking on the categories “Executable Rules”, “Windows installer Rules”, “Script Rules”, “Packaged app Rules” and “Create Default Rules”. This will fix the AppLocker error message so follow –
- Press Windows and R.
- Type – secpol.msc.
- Hit – Enter.
- Navigate to –
Computer => Policies => Windows Settings => Security Settings => Application Control Policies => AppLocker => Packaged app Rules
- Right-click and select Create Default Rules.
- This modification will allow everyone to run All signed packaged apps.
- Now Go to Application Control Policies => AppLocker.
- Click on Configure rule enforcement.
- Under Executable rules, select Configured. Enforce rules must be selected in drop-down.
- Restart the computer and click on Search.
- Type services.msc and press Enter.
- On the Services window, find Application Identity and make sure it’s in Running state.
- Repeat the same with “Executable Rules”, “Windows installer Rules”, “Script Rules”, and “Create Default Rules”.
The error should have been fixed now.
Way-2: Use RestoreHealth DISM
Sometimes, running the DISM with the parameters /Cleanup-Image and /RestoreHealth helps fix Applocker Error after KB5019959 in and KB5019980 in Windows 10 and 11 –
- Press Windows + I.
- Type –
DISM /Online /Cleanup-Image /RestoreHealth
- Hit Enter.
- This will scan the image to check for corruption and take time depending on the size and performance of the machine. Afterward, you need to do a reboot.
Read – What is DISM in Windows 10 (Deployment Image Servicing and Management)?
Way-3: Clean up AppLocker Directory and delete AppLocker rules
If the above methods could not fix – “This app has been blocked by your system administrator error” after KB5019959, and KB5019980 in Windows 10, and 11 then this is the most effective one. However, you need to be extra careful because this procedure will delete all your previously created AppLocker rules.
- Open Local Security Policy (secpol.msc).
- Go to Computer => Policies => Windows Settings => Security Settings => Application Control Policies => AppLocker.
- Select – Configure rule enforcement.
- Uncheck the option Configured and Click on OK.
- Restart the computer and again open Local Security Policy.
- Right click on Applocker and then select Clear Policy.
- Once more reboot the device.
- Open Notepad.
- Copy the following cmdlet and paste it into the notepad –
<AppLockerPolicy Version="1">
<RuleCollection Type="Exe" EnforcementMode="NotConfigured" />
<RuleCollection Type="Msi" EnforcementMode="NotConfigured" />
<RuleCollection Type="Script" EnforcementMode="NotConfigured" />
<RuleCollection Type="Dll" EnforcementMode="NotConfigured" />
</AppLockerPolicy>
- Click on File > Save as.
- Name this file “clear.xml” and save it in a directory such as C:\temp.
- Now go to C:\temp.
- Open Windows PowerShell as administrator.
- Use the following command to import the AppLocker PoSh module –
import-module AppLocker
- Then run the command –
Set-AppLockerPolicy -XMLPolicy .\clear.xml
- Restart the machine.
In maximum cases, this process will fix Applocker Error and the computer will work as before AppLocker was enabled. If in some cases, the method does not work then you will have to manually clean up the AppLocker directory using the below steps –
- Press Winkey+R.
- Copy paste –
%windir%\System32\AppLocker\
- Click on OK to access the AppLocker directory.
- Select all items there and delete them. In case, AppCahce.dat is in use this will not be deleted.
- Again run the above PowerShell cleanup and restart the machine.
Methods:
Way-1: Create Default Rules in Local Security Policy
Way-2: Use RestoreHealth DISM
Way-3: Clean up AppLocker Directory and delete AppLocker rules
That’s all!!