--- title: Create policies to enable applications description: Learn how to create policies to enable the installation and execution of apps on Windows SE. ms.date: 05/23/2023 ms.topic: tutorial appliesto: - ✅ Windows 11 SE, version 22H2 and later --- # Create policies to enable applications :::image type="content" source="./images/create-policies.png" alt-text="Diagram showing the three tutorial steps, highlighting the policy creation step." border="false"::: You can create AppLocker policies to allow apps that are [semi-compatible](./validate-apps.md#semi-compatible-apps) or [incompatible](./validate-apps.md#incompatible-apps) with the managed installer to run. Additional AppLocker policies work by configuring other apps to be *managed installers*. However, since anything downloaded or installed by a managed installer is trusted to run, it creates a significant security risk. For example, if the executable for a third-party browser is set as a managed installer, anything downloaded from that browser will be allowed to run. To allow apps to run by setting their installers as managed installers, follow the guidance here: - [Edit an AppLocker policy][WIN-5] - [Allow apps deployed with a WDAC managed installer][WIN-6] ## Next steps Before moving on to the next section, ensure that you've completed the following tasks. For a WDAC supplemental policy: > [!div class="checklist"] > > - Create a policy, targeting the base policy: **82443e1e-8a39-4b4a-96a8-f40ddc00b9f3** For an AppLocker policy: > [!div class="checklist"] > > - Only applied to an updater or installer > - Created the policy with the **Merge** option Advance to the next article to learn how to deploy the WDAC supplemental policies or AppLocker policies to Windows 11 SE devices. --> Advance to the next article to learn how to deploy the AppLocker policies to Windows 11 SE devices. > [!div class="nextstepaction"] > [Next: deploy policies >](deploy-policies.md) [EXT-1]: https://webapp-wdac-wizard.azurewebsites.net/ [WIN-1]: /windows/security/threat-protection/windows-defender-application-control/types-of-devices [WIN-2]: /windows/security/threat-protection/windows-defender-application-control/wdac-wizard-create-supplemental-policy [WIN-3]: /windows/security/threat-protection/windows-defender-application-control/audit-windows-defender-application-control-policies [WIN-5]: /windows/security/threat-protection/windows-defender-application-control/applocker/edit-an-applocker-policy [WIN-6]: /windows/security/threat-protection/windows-defender-application-control/configure-authorized-apps-deployed-with-a-managed-installer