Hello,
We are using PMPC alongside Intune and the Microsoft Defender Stack. Recently we switched on Attack Surface Reduction (ASR) Rules in Intune. They were designed for improving the security Posture on devices. On reviewing the Block Events we noticed the "PatchMyPC-ScriptRunner.exe" file was blocked by one Rule: "Block credential stealing from the Windows security authority subsystem."
Why is the file blocked for that reason (It needs to try to access the Windows local security subsystem LSASS). Has someone else had a similar experience and did you notice an Impact in App Distribution?
I appreciate any Feedback.
Hello Thadders,
LSASS is used when displaying the "Conflicting Processes" deferral notification to end users, to allow them to postpone the installation if needed.
Are you using the "Manage conflicting processes (https://patchmypc.com/manage-conflicting-processes-when-updating-third-party-applications)" right-click option>
Using that functionality is how the notification is displayed to the logged on user while Intune does the installation of the software in the SYSTEM context.
Please note that Microsoft recommends whitelisting the IMECache folder from AV scans to prevent win32 app installation issues such as this one.
https://patchmypc.com/recommended-antivirus-exclusions (https://patchmypc.com/recommended-antivirus-exclusions)