mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Metadata updates
This commit is contained in:
parent
d78a5dd183
commit
59f4147942
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Testing and Debugging AppId Tagging Policies
|
||||
description: Testing and Debugging AppId Tagging Policies to ensure your policies are deployed successfully.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jgeurten
|
||||
ms.reviewer: jsuther1974
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 04/29/2022
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Testing and Debugging AppId Tagging Policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,25 +1,13 @@
|
||||
---
|
||||
title: Deploying Windows Defender Application Control AppId tagging policies
|
||||
description: How to deploy your WDAC AppId tagging policies locally and globally within your managed environment.
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: jgeurten
|
||||
ms.reviewer: jsuther1974
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 04/29/2022
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Deploying Windows Defender Application Control AppId tagging policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and later
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control are only available on specific Windows versions. For more information, see [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Create your Windows Defender Application Control AppId Tagging Policies
|
||||
description: Create your Windows Defender Application Control AppId tagging policies for Windows devices.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jgeurten
|
||||
ms.reviewer: jsuther1974
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 04/29/2022
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Creating your WDAC AppId Tagging Policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
@ -43,7 +25,6 @@ You can use the Windows Defender Application Control (WDAC) Wizard and the Power
|
||||
> If your AppId Tagging Policy does build off the base templates or does not allow Windows in-box processes, you will notice significant performance regressions, especially during boot. For this reason, it is strongly recommended to build off the base templates.
|
||||
For more information on the issue, see the [AppId Tagging Known Issue](../operations/known-issues.md#slow-boot-and-performance-with-custom-policies).
|
||||
|
||||
|
||||
2. Set the following rule-options using the Wizard toggles:
|
||||
|
||||

|
||||
@ -58,7 +39,6 @@ You can use the Windows Defender Application Control (WDAC) Wizard and the Power
|
||||
- Package app name rules: Create a rule based off the package family name of an appx/msix.
|
||||
- Hash rules: Create a rule based off the PE Authenticode hash of a file.
|
||||
|
||||
|
||||
For more information on creating new policy file rules, see the guidelines provided in the [creating policy file rules section](../design/wdac-wizard-create-base-policy.md#creating-custom-file-rules).
|
||||
|
||||
4. Convert to AppId Tagging Policy:
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Designing, creating, managing and troubleshooting Windows Defender Application Control AppId Tagging policies
|
||||
title: Designing, creating, managing and troubleshooting Windows Defender Application Control AppId Tagging policies
|
||||
description: How to design, create, manage and troubleshoot your WDAC AppId Tagging policies
|
||||
keywords: security, malware, firewall
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jgeurten
|
||||
ms.reviewer: jsuther1974
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 04/27/2022
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# WDAC Application ID (AppId) Tagging guide
|
||||
|
||||
**Applies to**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2022 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Add rules for packaged apps to existing AppLocker rule-set
|
||||
description: This topic for IT professionals describes how to update your existing AppLocker policies for packaged apps using the Remote Server Administration Toolkit (RSAT).
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Add rules for packaged apps to existing AppLocker rule-set
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Administer AppLocker
|
||||
description: This topic for IT professionals provides links to specific procedures to use when administering AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 02/28/2019
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Administer AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker architecture and components
|
||||
description: This topic for IT professional describes AppLocker’s basic architecture and its major components.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker architecture and components
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker functions
|
||||
description: This article for the IT professional lists the functions and security levels for the Software Restriction Policies (SRP) and AppLocker features.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker functions
|
||||
|
@ -1,9 +1,6 @@
|
||||
---
|
||||
title: AppLocker
|
||||
description: This article provides a description of AppLocker and can help you decide if your organization can benefit from deploying AppLocker application control policies.
|
||||
ms.author: vinpa
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.collection:
|
||||
- highpri
|
||||
- tier3
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker deployment guide
|
||||
description: This topic for IT professionals introduces the concepts and describes the steps required to deploy AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker deployment guide
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker design guide
|
||||
description: This topic for the IT professional introduces the design and planning steps required to deploy application control policies by using AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker design guide
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker policy use scenarios
|
||||
description: This topic for the IT professional lists the various application control scenarios in which AppLocker policies can be effectively implemented.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker policy use scenarios
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker processes and interactions
|
||||
description: This topic for the IT professional describes the process dependencies and interactions when AppLocker evaluates and enforces rules.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker processes and interactions
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker settings
|
||||
description: This topic for the IT professional lists the settings used by AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker settings
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: AppLocker technical reference
|
||||
description: This overview topic for IT professionals provides links to the topics in the technical reference.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# AppLocker technical reference
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Configure an AppLocker policy for audit only
|
||||
description: This topic for IT professionals describes how to set AppLocker policies to Audit only within your IT environment by using AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 06/08/2018
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Configure an AppLocker policy for audit only
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Configure an AppLocker policy for enforce rules
|
||||
description: This topic for IT professionals describes the steps to enable the AppLocker policy enforcement setting.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Configure an AppLocker policy for enforce rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Add exceptions for an AppLocker rule
|
||||
description: This topic for IT professionals describes the steps to specify which apps can or cannot run as exceptions to an AppLocker rule.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Add exceptions for an AppLocker rule
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Configure the AppLocker reference device
|
||||
description: This topic for the IT professional describes the steps to create an AppLocker policy platform structure on a reference computer.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Configure the AppLocker reference device
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Configure the Application Identity service
|
||||
description: This topic for IT professionals shows how to configure the Application Identity service to start automatically or manually.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 07/01/2021
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Configure the Application Identity service
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create a rule for packaged apps
|
||||
description: This article for IT professionals shows how to create an AppLocker rule for packaged apps with a publisher condition.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create a rule for packaged apps
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create a rule that uses a file hash condition
|
||||
description: This topic for IT professionals shows how to create an AppLocker rule with a file hash condition.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create a rule that uses a file hash condition
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create a rule that uses a path condition
|
||||
description: This topic for IT professionals shows how to create an AppLocker rule with a path condition.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create a rule that uses a path condition
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create a rule that uses a publisher condition
|
||||
description: This topic for IT professionals shows how to create an AppLocker rule with a publisher condition.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create a rule that uses a publisher condition
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create AppLocker default rules
|
||||
description: This topic for IT professionals describes the steps to create a standard set of AppLocker rules that will allow Windows system files to run.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create AppLocker default rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create a list of apps deployed to each business group
|
||||
description: This topic describes the process of gathering app usage requirements from each business group to implement application control policies by using AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create a list of apps deployed to each business group
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create Your AppLocker policies
|
||||
description: This overview topic for the IT professional describes the steps to create an AppLocker policy and prepare it for deployment.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create Your AppLocker policies
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Create Your AppLocker rules
|
||||
description: This topic for the IT professional describes what you need to know about AppLocker rules and the methods that you can to create rules.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Create Your AppLocker rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Delete an AppLocker rule
|
||||
description: This article for IT professionals describes the steps to delete an AppLocker rule.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 03/10/2023
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Delete an AppLocker rule
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Deploy AppLocker policies by using the enforce rules setting
|
||||
description: This topic for IT professionals describes the steps to deploy AppLocker policies by using the enforcement setting method.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Deploy AppLocker policies by using the enforce rules setting
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Deploy the AppLocker policy into production
|
||||
description: This topic for the IT professional describes the tasks that should be completed before you deploy AppLocker application control settings.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Deploy the AppLocker policy into production
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Determine the Group Policy structure and rule enforcement
|
||||
description: This overview topic describes the process to follow when you're planning to deploy AppLocker rules.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Determine the Group Policy structure and rule enforcement
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Find digitally signed apps on a reference device
|
||||
description: This topic for the IT professional describes how to use AppLocker logs and tools to determine which applications are digitally signed.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Determine which apps are digitally signed on a reference device
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Determine your application control objectives
|
||||
description: Determine which applications to control and how to control them by comparing Software Restriction Policies (SRP) and AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Determine your application control objectives
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Display a custom URL message when users try to run a blocked app
|
||||
description: This topic for IT professionals describes the steps for displaying a customized message to users when an AppLocker policy denies access to an app.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Display a custom URL message when users try to run a blocked app
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: DLL rules in AppLocker
|
||||
description: This topic describes the file formats and available default rules for the DLL rule collection.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# DLL rules in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Document Group Policy structure & AppLocker rule enforcement
|
||||
description: This planning topic describes what you need to investigate, determine, and record in your application control policies plan when you use AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Document the Group Policy structure and AppLocker rule enforcement
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Document your app list
|
||||
description: This planning topic describes the app information that you should document when you create a list of apps for AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Document your app list
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Document your AppLocker rules
|
||||
description: Learn how to document your AppLocker rules and associate rule conditions with files, permissions, rule source, and implementation.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Document your AppLocker rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Edit an AppLocker policy
|
||||
description: This topic for IT professionals describes the steps required to modify an AppLocker policy.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Edit an AppLocker policy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Edit AppLocker rules
|
||||
description: This topic for IT professionals describes the steps to edit a publisher rule, path rule, and file hash rule in AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Edit AppLocker rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Enable the DLL rule collection
|
||||
description: This topic for IT professionals describes the steps to enable the DLL rule collection feature for AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Enable the DLL rule collection
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Enforce AppLocker rules
|
||||
description: This topic for IT professionals describes how to enforce application control rules by using AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Enforce AppLocker rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Executable rules in AppLocker
|
||||
description: This topic describes the file formats and available default rules for the executable rule collection.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Executable rules in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Export an AppLocker policy from a GPO
|
||||
description: This topic for IT professionals describes the steps to export an AppLocker policy from a Group Policy Object (GPO) so that it can be modified.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Export an AppLocker policy from a GPO
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Export an AppLocker policy to an XML file
|
||||
description: This topic for IT professionals describes the steps to export an AppLocker policy to an XML file for review or testing.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Export an AppLocker policy to an XML file
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: How AppLocker works
|
||||
description: This topic for the IT professional provides links to topics about AppLocker architecture and components, processes and interactions, rules and policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# How AppLocker works
|
||||
|
@ -1,14 +1,8 @@
|
||||
---
|
||||
title: Import an AppLocker policy from another computer
|
||||
description: This topic for IT professionals describes how to import an AppLocker policy.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.technology: itpro-security
|
||||
ms.date: 12/31/2017
|
||||
---
|
||||
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Import an AppLocker policy into a GPO
|
||||
description: This topic for IT professionals describes the steps to import an AppLocker policy into a Group Policy Object (GPO).
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Import an AppLocker policy into a GPO
|
||||
|
@ -1,14 +1,8 @@
|
||||
---
|
||||
title: Maintain AppLocker policies
|
||||
description: Learn how to maintain rules within AppLocker policies. View common AppLocker maintenance scenarios and see the methods to use to maintain AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.technology: itpro-security
|
||||
ms.date: 12/31/2017
|
||||
---
|
||||
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Manage packaged apps with AppLocker
|
||||
description: Learn concepts and lists procedures to help you manage packaged apps with AppLocker as part of your overall application control strategy.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Manage packaged apps with AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Merge AppLocker policies by using Set-ApplockerPolicy
|
||||
description: This topic for IT professionals describes the steps to merge AppLocker policies by using Windows PowerShell.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Merge AppLocker policies by using Set-ApplockerPolicy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Merge AppLocker policies manually
|
||||
description: This topic for IT professionals describes the steps to manually merge AppLocker policies to update the Group Policy Object (GPO).
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Merge AppLocker policies manually
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Monitor app usage with AppLocker
|
||||
description: This topic for IT professionals describes how to monitor app usage when AppLocker policies are applied.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Monitor app usage with AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Optimize AppLocker performance
|
||||
description: This topic for IT professionals describes how to optimize AppLocker policy enforcement.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Optimize AppLocker performance
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Packaged apps and packaged app installer rules in AppLocker
|
||||
description: This topic explains the AppLocker rule collection for packaged app installers and packaged apps.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 10/13/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Packaged apps and packaged app installer rules in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Plan for AppLocker policy management
|
||||
description: This topic describes the decisions you need to make to establish the processes for managing and maintaining AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Plan for AppLocker policy management
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Refresh an AppLocker policy
|
||||
description: This topic for IT professionals describes the steps to force an update for an AppLocker policy.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Refresh an AppLocker policy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Requirements for deploying AppLocker policies
|
||||
description: This deployment topic for the IT professional lists the requirements that you need to consider before you deploy AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Requirements for deploying AppLocker policies
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Requirements to use AppLocker
|
||||
description: This topic for the IT professional lists software requirements to use AppLocker on the supported Windows operating systems.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Requirements to use AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Run the Automatically Generate Rules wizard
|
||||
description: This topic for IT professionals describes steps to run the wizard to create AppLocker rules on a reference device.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Run the Automatically Generate Rules wizard
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Script rules in AppLocker
|
||||
description: This article describes the file formats and available default rules for the script rule collection.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 06/15/2022
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Script rules in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Security considerations for AppLocker
|
||||
description: This topic for the IT professional describes the security considerations you need to address when implementing AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Security considerations for AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Select the types of rules to create
|
||||
description: This topic lists resources you can use when selecting your application control policy rules by using AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Select the types of rules to create
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Test an AppLocker policy by using Test-AppLockerPolicy
|
||||
description: This topic for IT professionals describes the steps to test an AppLocker policy prior to importing it into a Group Policy Object (GPO) or another computer.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Test an AppLocker policy by using Test-AppLockerPolicy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Test and update an AppLocker policy
|
||||
description: This topic discusses the steps required to test an AppLocker policy prior to deployment.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Test and update an AppLocker policy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Tools to use with AppLocker
|
||||
description: This topic for the IT professional describes the tools available to create and administer AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Tools to use with AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understand AppLocker enforcement settings
|
||||
description: This topic describes the AppLocker enforcement settings for rule collections.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understand AppLocker enforcement settings
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understand AppLocker policy design decisions
|
||||
description: Review some common considerations while you're planning to use AppLocker to deploy application control policies within a Windows environment.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 10/13/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understand AppLocker policy design decisions
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understand AppLocker rules and enforcement setting inheritance in Group Policy
|
||||
description: This topic for the IT professional describes how application control policies configured in AppLocker are applied through Group Policy.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understand AppLocker rules and enforcement setting inheritance in Group Policy
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understand the AppLocker policy deployment process
|
||||
description: This planning and deployment topic for the IT professional describes the process for using AppLocker when deploying application control policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understand the AppLocker policy deployment process
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker allow and deny actions on rules
|
||||
description: This topic explains the differences between allow and deny actions on AppLocker rules.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker allow and deny actions on rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker default rules
|
||||
description: This topic for IT professional describes the set of rules that can be used to ensure that required Windows system files are allowed to run when the policy is applied.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker default rules
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker rule behavior
|
||||
description: This topic describes how AppLocker rules are enforced by using the allow and deny options in AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker rule behavior
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker rule collections
|
||||
description: This topic explains the five different types of AppLocker rules used to enforce AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker rule collections
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker rule condition types
|
||||
description: This topic for the IT professional describes the three types of AppLocker rule conditions.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker rule condition types
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding AppLocker rule exceptions
|
||||
description: This topic describes the result of applying AppLocker rule exceptions to rule collections.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding AppLocker rule exceptions
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding the file hash rule condition in AppLocker
|
||||
description: This topic explains the AppLocker file hash rule condition, the advantages and disadvantages, and how it's applied.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding the file hash rule condition in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding the path rule condition in AppLocker
|
||||
description: This topic explains the AppLocker path rule condition, the advantages and disadvantages, and how it's applied.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding the path rule condition in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Understanding the publisher rule condition in AppLocker
|
||||
description: This topic explains the AppLocker publisher rule condition, what controls are available, and how it's applied.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Understanding the publisher rule condition in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Use a reference device to create and maintain AppLocker policies
|
||||
description: This topic for the IT professional describes the steps to create and maintain AppLocker policies by using a reference computer.
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.reviewer:
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Use a reference device to create and maintain AppLocker policies
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Use AppLocker and Software Restriction Policies in the same domain
|
||||
description: This article for IT professionals describes concepts and procedures to help you manage your application control strategy using Software Restriction Policies and AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 11/07/2022
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Use AppLocker and Software Restriction Policies in the same domain
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Use the AppLocker Windows PowerShell cmdlets
|
||||
description: This topic for IT professionals describes how each AppLocker Windows PowerShell cmdlet can help you administer your AppLocker application control policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Use the AppLocker Windows PowerShell cmdlets
|
||||
|
@ -1,14 +1,8 @@
|
||||
---
|
||||
title: Using Event Viewer with AppLocker
|
||||
description: This article lists AppLocker events and describes how to use Event Viewer with AppLocker.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.technology: itpro-security
|
||||
ms.date: 02/02/2023
|
||||
---
|
||||
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Use Software Restriction Policies and AppLocker policies
|
||||
description: This topic for the IT professional describes how to use Software Restriction Policies (SRP) and AppLocker policies in the same Windows deployment.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Use Software Restriction Policies and AppLocker policies
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: What Is AppLocker
|
||||
description: This topic for the IT professional describes what AppLocker is and how its features differ from Software Restriction Policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# What Is AppLocker?
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Windows Installer rules in AppLocker
|
||||
description: This topic describes the file formats and available default rules for the Windows Installer rule collection.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Windows Installer rules in AppLocker
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Working with AppLocker policies
|
||||
description: This topic for IT professionals provides links to procedural topics about creating, maintaining, and testing AppLocker policies.
|
||||
ms.reviewer:
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: vinaypamnani-msft
|
||||
manager: aaroncz
|
||||
ms.topic: conceptual
|
||||
ms.date: 09/21/2017
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Working with AppLocker policies
|
||||
|
@ -1,15 +1,9 @@
|
||||
---
|
||||
title: Working with AppLocker rules
|
||||
description: This topic for IT professionals describes AppLocker rule types and how to work with them for your application control policies.
|
||||
ms.reviewer:
|
||||
manager: aaroncz
|
||||
ms.author: vinpa
|
||||
ms.prod: windows-client
|
||||
author: vinaypamnani-msft
|
||||
ms.localizationpriority: medium
|
||||
msauthor: v-anbic
|
||||
ms.date: 08/27/2018
|
||||
ms.technology: itpro-security
|
||||
ms.topic: conceptual
|
||||
---
|
||||
|
||||
|
@ -1,23 +1,13 @@
|
||||
---
|
||||
title: Allow LOB Win32 apps on Intune-managed S Mode devices
|
||||
description: Using Windows Defender Application Control (WDAC) supplemental policies, you can expand the S Mode base policy on your Intune-managed devices.
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 04/05/2023
|
||||
ms.technology: itpro-security
|
||||
ms.topic: how-to
|
||||
---
|
||||
|
||||
# Allow line-of-business Win32 apps on Intune-managed S Mode devices
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. For more information, see [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Use audit events to create WDAC policy rules
|
||||
title: Use audit events to create WDAC policy rules
|
||||
description: Audits allow admins to discover apps, binaries, and scripts that should be added to the WDAC policy.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 05/03/2018
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Use audit events to create WDAC policy rules
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Application Control feature availability](../feature-availability.md).
|
||||
|
||||
@ -59,7 +41,7 @@ To familiarize yourself with creating WDAC rules from audit events, follow these
|
||||
4. Use [New-CIPolicy](/powershell/module/configci/new-cipolicy) to generate a new WDAC policy from logged audit events. This example uses a **FilePublisher** file rule level and a **Hash** fallback level. Warning messages are redirected to a text file **EventsPolicyWarnings.txt**.
|
||||
|
||||
```powershell
|
||||
New-CIPolicy -FilePath $EventsPolicy -Audit -Level FilePublisher -Fallback SignedVersion,FilePublisher,Hash –UserPEs -MultiplePolicyFormat 3> $EventsPolicyWarnings
|
||||
New-CIPolicy -FilePath $EventsPolicy -Audit -Level FilePublisher -Fallback SignedVersion,FilePublisher,Hash -UserPEs -MultiplePolicyFormat 3> $EventsPolicyWarnings
|
||||
```
|
||||
|
||||
> [!NOTE]
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Create a code signing cert for Windows Defender Application Control
|
||||
title: Create a code signing cert for Windows Defender Application Control
|
||||
description: Learn how to set up a publicly issued code signing certificate, so you can sign catalog files or WDAC policies internally.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
ms.topic: conceptual
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 12/01/2022
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Optional: Create a code signing cert for Windows Defender Application Control
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,25 +1,13 @@
|
||||
---
|
||||
title: Deploy catalog files to support Windows Defender Application Control
|
||||
description: Catalog files simplify running unsigned applications in the presence of a Windows Defender Application Control (WDAC) policy.
|
||||
ms.prod: windows-client
|
||||
ms.localizationpriority: medium
|
||||
ms.topic: how-to
|
||||
author: jsuther1974
|
||||
ms.reviewer: jgeurten
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 11/30/2022
|
||||
ms.technology: itpro-security
|
||||
---
|
||||
|
||||
# Deploy catalog files to support Windows Defender Application Control
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and later
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control are only available on specific Windows versions. For more information, see [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Deploy WDAC policies via Group Policy
|
||||
title: Deploy WDAC policies via Group Policy
|
||||
description: Windows Defender Application Control (WDAC) policies can easily be deployed and managed with Group Policy. Learn how by following this step-by-step guide.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 01/23/2023
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Deploy Windows Defender Application Control policies by using Group Policy
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,25 +1,13 @@
|
||||
---
|
||||
title: Deploy WDAC policies using Mobile Device Management (MDM)
|
||||
title: Deploy WDAC policies using Mobile Device Management (MDM)
|
||||
description: You can use an MDM like Microsoft Intune to configure Windows Defender Application Control (WDAC). Learn how with this step-by-step guide.
|
||||
ms.prod: windows-client
|
||||
ms.technology: itpro-security
|
||||
ms.localizationpriority: medium
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 01/23/2023
|
||||
ms.topic: how-to
|
||||
---
|
||||
|
||||
# Deploy WDAC policies using Mobile Device Management (MDM)
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,12 +1,6 @@
|
||||
---
|
||||
title: Deploy Windows Defender Application Control policies with Configuration Manager
|
||||
description: You can use Microsoft Configuration Manager to configure Windows Defender Application Control (WDAC). Learn how with this step-by-step guide.
|
||||
ms.prod: windows-client
|
||||
ms.technology: itpro-security
|
||||
author: jgeurten
|
||||
ms.reviewer: aaroncz
|
||||
ms.author: jogeurte
|
||||
manager: aaroncz
|
||||
ms.date: 06/27/2022
|
||||
ms.topic: how-to
|
||||
ms.localizationpriority: medium
|
||||
@ -14,12 +8,6 @@ ms.localizationpriority: medium
|
||||
|
||||
# Deploy WDAC policies by using Microsoft Configuration Manager
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
> [!NOTE]
|
||||
> Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,28 +1,14 @@
|
||||
---
|
||||
title: Deploy Windows Defender Application Control (WDAC) policies using script
|
||||
title: Deploy Windows Defender Application Control (WDAC) policies using script
|
||||
description: Use scripts to deploy Windows Defender Application Control (WDAC) policies. Learn how with this step-by-step guide.
|
||||
keywords: security, malware
|
||||
ms.prod: windows-client
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: aaroncz
|
||||
ms.author: jogeurte
|
||||
ms.manager: jsuther
|
||||
manager: aaroncz
|
||||
ms.date: 01/23/2023
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
# Deploy WDAC policies using script
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Application Control feature availability](/windows/security/threat-protection/windows-defender-application-control/feature-availability).
|
||||
|
||||
|
@ -1,31 +1,13 @@
|
||||
---
|
||||
title: Remove Windows Defender Application Control policies
|
||||
title: Remove Windows Defender Application Control policies
|
||||
description: Learn how to disable both signed and unsigned Windows Defender Application Control policies, within Windows and within the BIOS.
|
||||
keywords: security, malware
|
||||
ms.assetid: 8d6e0474-c475-411b-b095-1c61adb2bdbb
|
||||
ms.prod: windows-client
|
||||
ms.mktglfcycl: deploy
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: vinpa
|
||||
manager: aaroncz
|
||||
ms.date: 11/04/2022
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
---
|
||||
|
||||
# Remove Windows Defender Application Control (WDAC) policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
@ -1,28 +1,14 @@
|
||||
---
|
||||
title: Enforce Windows Defender Application Control (WDAC) policies
|
||||
title: Enforce Windows Defender Application Control (WDAC) policies
|
||||
description: Learn how to switch a WDAC policy from audit to enforced mode.
|
||||
keywords: security, malware
|
||||
ms.prod: windows-client
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: jogeurte
|
||||
ms.manager: jsuther
|
||||
manager: aaroncz
|
||||
ms.date: 04/22/2021
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
# Enforce Windows Defender Application Control (WDAC) policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
@ -55,8 +41,7 @@ Alice previously created and deployed a policy for the organization's [fully man
|
||||
$EnforcedPolicyID = $EnforcedPolicyID.Substring(11)
|
||||
```
|
||||
|
||||
|
||||
3. *[Optionally]* Use [Set-RuleOption](/powershell/module/configci/set-ruleoption) to enable rule options 9 (“Advanced Boot Options Menu”) and 10 (“Boot Audit on Failure”). Option 9 allows users to disable WDAC enforcement for a single boot session from a pre-boot menu. Option 10 instructs Windows to switch the policy from enforcement to audit only if a boot critical kernel-mode driver is blocked. We strongly recommend these options when deploying a new enforced policy to your first deployment ring. Then, if no issues are found, you can remove the options and restart your deployment.
|
||||
3. *[Optionally]* Use [Set-RuleOption](/powershell/module/configci/set-ruleoption) to enable rule options 9 ("Advanced Boot Options Menu") and 10 ("Boot Audit on Failure"). Option 9 allows users to disable WDAC enforcement for a single boot session from a pre-boot menu. Option 10 instructs Windows to switch the policy from enforcement to audit only if a boot critical kernel-mode driver is blocked. We strongly recommend these options when deploying a new enforced policy to your first deployment ring. Then, if no issues are found, you can remove the options and restart your deployment.
|
||||
|
||||
```powershell
|
||||
Set-RuleOption -FilePath $EnforcedPolicyXML -Option 9
|
||||
|
@ -1,28 +1,14 @@
|
||||
---
|
||||
title: Merge Windows Defender Application Control policies (WDAC)
|
||||
title: Merge Windows Defender Application Control policies (WDAC)
|
||||
description: Learn how to merge WDAC policies as part of your policy lifecycle management.
|
||||
keywords: security, malware
|
||||
ms.prod: windows-client
|
||||
audience: ITPro
|
||||
author: jsuther1974
|
||||
ms.reviewer: jogeurte
|
||||
ms.author: jogeurte
|
||||
ms.manager: jsuther
|
||||
manager: aaroncz
|
||||
ms.date: 04/22/2021
|
||||
ms.technology: itpro-security
|
||||
ms.topic: article
|
||||
ms.localizationpriority: medium
|
||||
---
|
||||
|
||||
# Merge Windows Defender Application Control (WDAC) policies
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10
|
||||
- Windows 11
|
||||
- Windows Server 2016 and above
|
||||
|
||||
>[!NOTE]
|
||||
>Some capabilities of Windows Defender Application Control (WDAC) are only available on specific Windows versions. Learn more about the [Windows Defender Application Control feature availability](../feature-availability.md).
|
||||
|
||||
|
Some files were not shown because too many files have changed in this diff Show More
Loading…
x
Reference in New Issue
Block a user