mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 14:27:22 +00:00
Update WDAC vs AppLocker guidance
Recommend customers consider WDAC over AppLocker
This commit is contained in:
parent
cc4516dd2e
commit
b9557e265b
@ -31,8 +31,7 @@ Windows 10 includes two technologies that can be used for application control de
|
|||||||
|
|
||||||
WDAC was introduced with Windows 10 and allows organizations to control what drivers and applications are allowed to run on their Windows 10 clients. WDAC was designed as a security feature under the [servicing criteria](https://www.microsoft.com/msrc/windows-security-servicing-criteria) defined by the Microsoft Security Response Center (MSRC).
|
WDAC was introduced with Windows 10 and allows organizations to control what drivers and applications are allowed to run on their Windows 10 clients. WDAC was designed as a security feature under the [servicing criteria](https://www.microsoft.com/msrc/windows-security-servicing-criteria) defined by the Microsoft Security Response Center (MSRC).
|
||||||
|
|
||||||
> [!NOTE]
|
Note that prior to Windows 10, version 1709, Windows Defender Application Control was known as configurable code integrity (CCI) policies. WDAC was also one feature that comprised the now-defunct term 'Device Guard'.
|
||||||
> Prior to Windows 10, version 1709, Windows Defender Application Control was known as configurable code integrity (CCI) policies.
|
|
||||||
|
|
||||||
WDAC policies apply to the managed computer as a whole and affects all users of the device. WDAC rules can be defined based on:
|
WDAC policies apply to the managed computer as a whole and affects all users of the device. WDAC rules can be defined based on:
|
||||||
|
|
||||||
@ -65,20 +64,18 @@ AppLocker policies can be deployed using Group Policy or MDM.
|
|||||||
|
|
||||||
## Choose when to use WDAC or AppLocker
|
## Choose when to use WDAC or AppLocker
|
||||||
|
|
||||||
Although either AppLocker or WDAC can be used to control application execution on Windows 10 clients, the following factors can help you decide when to use each of the technologies.
|
Generally, it is recommended that customers who are able to implement application control using WDAC rather than AppLocker do so. WDAC is undergoing continual improvements and will be getting added support from Microsoft management platforms. AppLocker, on the other hand, will receive security fixes but no new feature improvements.
|
||||||
|
In some cases, however, AppLocker may be the more appropriate technology for your organization. The following factors can help you decide when to use each of the technologies.
|
||||||
|
|
||||||
### WDAC is best when:
|
**WDAC is best when:**
|
||||||
|
|
||||||
- You are adopting application control primarily for security reasons.
|
|
||||||
- Your application control policy can be applied to all users on the managed computers.
|
|
||||||
- All of the devices you wish to manage are running Windows 10.
|
- All of the devices you wish to manage are running Windows 10.
|
||||||
|
- Your application control policy can be applied to all users on the managed computers.
|
||||||
|
|
||||||
### AppLocker is best when:
|
**AppLocker is best when:**
|
||||||
|
|
||||||
- You have a mixed Windows operating system (OS) environment and need to apply the same policy controls to Windows 10 and earlier versions of the OS.
|
- You have a mixed Windows operating system (OS) environment and need to apply the same policy controls to Windows 10 and earlier versions of the OS.
|
||||||
- You need to apply different policies for different users or groups on a shared computer.
|
- You need to apply different policies for different users or groups on shared computers.
|
||||||
- You are using application control to help users avoid running unapproved software, but you do not require a solution designed as a security feature.
|
|
||||||
- You do not wish to enforce application control on application files such as DLLs or drivers.
|
|
||||||
|
|
||||||
## When to use both WDAC and AppLocker together
|
## When to use both WDAC and AppLocker together
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user