
Explanation:

Does AppLocker use any services for its rule enforcement?
Yes, AppLocker uses the Application Identity service (AppIDSvc) for rule enforcement. For AppLocker rules to be enforced, this service must be set to start automatically in the GPO.
Before you can enforce AppLocker policies, you must start the Application Identity service by using the Services snap-in console.
Membership in the local Administrators group, or equivalent, is the minimum required to complete this procedure.
To start the Application Identity service
* Click Start, click Administrative Tools, and then click Services.
* In the Services snap-in console, double-click Application Identity.
* In the Application Identity Properties dialog box, click Automatic in the Startup type list, click Start, and then click OK.