From c5e4881a7dba143afb0df83ecb8668b50c666b49 Mon Sep 17 00:00:00 2001 From: Jordan Geurten Date: Fri, 23 Sep 2022 12:54:41 -0400 Subject: [PATCH] Updated SAC-recommended section per feedback --- .../microsoft-recommended-block-rules.md | 8 -------- .../windows-defender-application-control.md | 8 ++++++++ 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md index 47db6cbef8..80be7ef669 100644 --- a/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md +++ b/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules.md @@ -1530,14 +1530,6 @@ Select the correct version of each .dll for the Windows release you plan to supp > [!NOTE] > To create a policy that works on both Windows 10, version 1803 and version 1809, you can create two different policies, or merge them into one broader policy. -## Smart App Control Considerations -Smart App Control enforces the Microsoft Recommended Block Rules above, with a few exceptions for compatibility considerations. The following are not blocked by Smart App Control: - -- Infdefaultinstall.exe -- Microsoft.Build.dll -- Microsoft.Build.Framework.dll -- Wslhost.dll - ## More information - [Merge Windows Defender Application Control policies](merge-windows-defender-application-control-policies.md) diff --git a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md index e8ea61c23d..963d8a8748 100644 --- a/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md +++ b/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control.md @@ -58,6 +58,14 @@ Smart App Control is only available on clean installation of Windows 11 version | 1 | Enforce | | 2 | Evaluation | +### Smart App Control Enforced Blocks +Smart App Control enforces the [Microsoft Recommended Driver Block rules](microsoft-recommended-driver-block-rules.md) and the [Microsoft Recommended Block Rules](microsoft-recommended-block-rules.md), with a few exceptions for compatibility considerations. The following are not blocked by Smart App Control: + +- Infdefaultinstall.exe +- Microsoft.Build.dll +- Microsoft.Build.Framework.dll +- Wslhost.dll + > [!IMPORTANT] > Once you turn Smart App Control off, it can't be turned on without resetting or reinstalling Windows.