Files
windows-itpro-docs/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune.md
2018-05-04 09:19:04 -07:00

2.1 KiB

title, description, ms.assetid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, author, ms.date
title description ms.assetid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype author ms.date
Deploy Windows Defender Application Control (WDAC) policies by using Microsoft Intune (Windows 10) Windows Defender Application Control restricts which applications users are allowed to run and the code that runs in the system core. 8d6e0474-c475-411b-b095-1c61adb2bdbb w10 deploy library security jsuther1974 02/28/2018

Deploy Windows Defender Application Control policies by using Microsoft Intune

Applies to:

  • Windows 10
  • Windows Server 2016

You can apply Windows Defender Application Control (WDAC) to Windows 10 client computers using Microsoft Intune.

  1. Open the Microsoft Intune portal and click Create a compliance policy.

    Create a compliance policy in Intune

  2. Click Create Policy.

    Create a new policy

  3. Type a name for the new policy and for Platform, select Windows 10 and later.

    Select platform

  4. Click Device Health, select Require for the following settings and then click OK:

    • Require BitLocker
    • Require Secure Boot to be enabled on the device
    • Require code integrity

    Device Health settings

  5. Click Device Properties, configure any operating system version requirements and then click OK.

    Device properties

  6. Click System Security, select any security options to include in the policy and then click OK.

    System security settings

  7. When you finish configuring settings, click OK and then click Create.

  8. Click Assignments.

    Assignments

  9. Select any mutually exclusive groups to include or exclude from the policy, or assign it to All users, and then click Save.

    Assign the policy to groups