What steps are required to block PowerShell with Custom Rules in App Control?
Environment
App Control Console: All Supported Versions
App Control Agent: All Supported Versions
Microsoft Windows: All Supported Versions
Resolution
Due to the deep integration with the operating system it is not recommended to outright block PowerShell. Instead, the approach should be to restrict aspects of PowerShell while monitoring others.
When using App Control to restrict PowerShell, it can be done through the use of the Rapid Config: Powershell Protection.
Log in to the Console and navigate to Rules > Software Rules > Rapid Configs.
Click View Details (pencil icon) next to Powershell Protection
Change the Status to Enabled
It is recommended to initially start Rapid Configs:
In Report mode
Limited to a specific Policy
Monitor Reports > Events accordingly.
This will allow for tuning the Rapid Config accordingly to eliminate false positives before changing to Block.
Additional Information
Command Line Exceptions may be required to allow known-good, trusted software to properly execute.