PSE15 causing bootloops? Win 10 (1607), Bitlocker, AD Domain
Hi, all...
Just got a new copy of PSE 15 for some of our staff. The machines in question are Thinkpads on Windows 10 (Build 1607) joined to an AD domain with a functional level of 2016. All of our machines run with Bitlocker drive encryption, DeviceGaurd, and Applocker rules set to check path and hash (programfiles, sysWOW64, and System32), but not enforce signatures.
Both machines are now unable to boot (single user ok.) into windows, doesn't seem to be any hardware error related log entries on either. When in singleuser I checked Autoruns and found a few unsigned codec and multiplexor services loading on boot, but disabling them in registry doesn't seem to fix it. System restore and startup repair both fail after some time, and moving to restore points does not work either.
If there's any code that it requires to load from outside of programfiles I need to know the path so I can update the applocker policy accordingly.
Considering that this is userspace software, I see no reason to require exceptions to our security policies. Injecting code into the BCD or requiring any system services to start as nt\system is unnecessary and very insecure.
So, the question is, has anyone had similar experiences with this software causing system failures, and if so how it was resolved.
