[USER_PROFILE] Prefix for Application Control Exceptions are ignored by Windows 10 Clients
Last Updated December 05, 2018
On Windows 10, an application launched from a Windows user's profile directory such as C:\Users\Firstname_Lastname\AppData\MyApplication.exe does not work as expected when Symantec Endpoint Protection (SEP) is installed with Application Control enabled. The application may appear to hang or freeze for some period of time.
You create and apply an Exception Policy for Application Control using the optional predefined prefix [USER_PROFILE], but that does not resolve the issue.
An Exception Policy for Application Control without the [USER_PROFILE] prefix, but with the absolute path such as C:\Users\Firstname_Lastname\AppData\MyApplication.exe does resolve the issue.
This only affects Windows 10 Clients.
The [USER_PROFILE] Prefix Application Control Exception policy works as expected on Windows 7, Server 2008R2, Server 2012R2 and Server 2016 clients
Symantec is aware and currently investigating this issue. This document will be updated when more information is available.
Use the absolute path to the user's profile directory if possible:
For example: C:\Users\Firstname_Lastname\AppData\MyApplication.exe
Use the executable file name only without any prefix or path:
For example: MyApplication.exe
Subscribing will provide email updates when this Article is updated. Login is required to Subscribe