Hi,
I have created a new group, turned off inheritance, created a new file fingerprint list using checksum on my own laptop and added it to Policy Components using the SEPM gui. I then turned on System Lockdown for that group, setting it for Step 1 because I only want to log. I then added the file fingerprint list to the approved applications list in the System Lockdown settings. I then moved my laptop to this new group. Once I confirmed that I had received the new policy, I started running applications that were not on my machine when I originally ran checksum. However, I don't see any events in my client's logs (Control) nor in the SEPM Logs (Checked Application and Device Control logs in Monitors). Am I looking in the right places? If so, how can I troubleshoot why I am not seeing any events for running an application that is not whitelisted?
Thanks in advance,
Bob