Skip to content

10. Windows Defender App Control (WDAC)

10. WDAC: (Windows Defender Application Control)

Danger

Work in Progress, please review all content before starting, and be cautious in deployment Start in Test/UAT and avoid outliers like Developers Documentation on this page is very light at the moment and needs more review

Troubleshooting: - https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/operations/wdac-debugging-and-troubleshooting

From Eric Mannon: - https://www.linkedin.com/feed/update/urn:li:activity:6996238396973051904/ - Read the above article first - 1st- Install WDACme on all W10 workstations - 2nd- Enable "Smart Application Control" in Evaluation mode on W11 endpoints that support it - 3rd- Lock down Tier 0 (DC's, ADFS & AD Connect servers) with WDAC Microsoft-only mode in block mode. (No 3rd party software should ever be installed on the Tier 0 server type) - 4th- Deploy a supplemental policy to block the Microsoft recommended block list - 🔑Golden rule: "Audit is better than nothing" - 🎯Desired state: "Zero Trust for unapproved code"

🎒Resources:

Deeper Background

Additional Resources