Windows Defender Application Control (WDAC) Basics

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ก.ค. 2021
  • Windows Defender Application Control is a way to whitelist applications and DLLs on your Windows 10 Professional and Enterprise environments. This video demonstrates the basic operation and configuration of WDAC on a stand alone Windows 10 Enterprise workstation.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 33

  • @timtol5176
    @timtol5176 2 ปีที่แล้ว +1

    Good quick intro. Thanks.

  • @ozyeo
    @ozyeo 3 ปีที่แล้ว +1

    Love the first principles approach to this

  • @zokm8165
    @zokm8165 2 ปีที่แล้ว +2

    Thanks Rob, do you have a good source on whitelisting additional programs in the XML file?

    • @directorcia
      @directorcia  2 ปีที่แล้ว +1

      I don't whitelist I blacklist, far easier to manage.

  • @zedninja
    @zedninja 2 ปีที่แล้ว +1

    Cool. All very clear but I'm not really sure why I'm running the ConvertFrom-CIPolicy PS - what is it actually doing?

    • @directorcia
      @directorcia  2 ปีที่แล้ว +2

      Converts an .xml file that contains a Code Integrity policy into binary format.

  • @idatoo
    @idatoo 2 ปีที่แล้ว

    How would you add exceptions (whitelist) software such as Adobe Acrobat Reader?

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      Create a suitable policy and apply that. The policy would provide customised handing for Acrobat executables based on their location or executable file properties.

  • @pradeeppowduri166
    @pradeeppowduri166 2 ปีที่แล้ว

    Followed similar steps. But unable to see putty is blocked by wdac on windows 11. Are there any extra configurations needed ?

    • @directorcia
      @directorcia  2 ปีที่แล้ว +1

      R U using W11 Enterprise? It won't work stand alone on anythign else.

  • @Simpuhl
    @Simpuhl 2 ปีที่แล้ว +1

    How/Where do you create the code Integrity policy? Where did you get your example policies in the video?
    What if I wanted to white-list putty.exe, can that be done by hash or anything?

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      Example policies are here - C:\Windows\schemas\CodeIntegrity\ExamplePolicies. You can whitelist anything you wish.

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      See this on how to create policies - techcommunity.microsoft.com/t5/core-infrastructure-and-security/deploying-windows-10-application-control-policy/ba-p/2486267

  • @arshdeep221
    @arshdeep221 ปีที่แล้ว +1

    Is this applicable for windows 10 home edition?

    • @directorcia
      @directorcia  ปีที่แล้ว

      No. Business versions only as far as I know, although someone did say here that with the latest latest update to Windows 11 it will be but I'd suggest no as it is too complex for home users

  • @coryshannon449
    @coryshannon449 ปีที่แล้ว +1

    How do i remove this permanently? It automatically blocks everything. Including powershell and CMD and prevents all diver installations. Its bricked the computer. All i can do is run Microsoft edge and the windows store.

    • @directorcia
      @directorcia  ปีที่แล้ว

      learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/disable-windows-defender-application-control-policies

  • @tox_anituber
    @tox_anituber 5 หลายเดือนก่อน

    I've been getting an Error Your Organization has used WDAC to block this app on my virtual box . I tried everything and It's still not working any ideas?

    • @directorcia
      @directorcia  5 หลายเดือนก่อน +1

      Clearly there is a policy in play. Look at the MS guide to troublehooting WDAC. Note many things can apply a WDAC policy.

  • @PhrostyGaming
    @PhrostyGaming 2 ปีที่แล้ว

    Is there a way to block an app and prompt the user send a message to the administrator requesting whitelist? I believe my previous employer had something that did this, but I cant for the life of me remember what it was. I believe it started with "bit" like "bitlocker"...

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      Not with MDAC no. There is no user interaction.

    • @PhrostyGaming
      @PhrostyGaming 2 ปีที่แล้ว

      @@directorcia Do you know of a way to do this? It would help a ton!

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      @@PhrostyGaming Third Party app

  • @fbifido2
    @fbifido2 3 ปีที่แล้ว +3

    ConvertFrom-CIPolicy -XmlFilePath 'c:\Windows\schemas\CodeIntegrity\ExamplePolicies\DefaultWindows_Enforced.xml' -BinaryFilePath c:\Windows\System32\CodeIntegrity\SIPolicy.p7b

  • @nvidiashield495
    @nvidiashield495 2 ปีที่แล้ว

    WDAC you state is more secure than Applocker.
    Is WDAC more secure than Whitelisting in SRP via Group Politics ?

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      Yes as WDAC is applied prior to system boot.

    • @nvidiashield495
      @nvidiashield495 2 ปีที่แล้ว

      @@directorcia I have Win 10 Pro build 19043 .1526 and i see it's supported. Once i enabled "Turn on script execution" in the Windows Components\Windows Power Shell in Group Policy and i noticed the ` character at the end of top 2 lines of text , the script ran correctly however nothing has changed and windows defender is enabled . Any ideas why that didn't work
      Trying to help my 88 yr old mother who almost lost everything to scammers by protecting her from herself.

    • @directorcia
      @directorcia  2 ปีที่แล้ว

      @@nvidiashield495 I wouldn’t be doing wdac for your mother. It is designed for commercial machines. Use app locker for her if u must.

    • @nvidiashield495
      @nvidiashield495 2 ปีที่แล้ว +1

      @@directorcia applocker as you know is for Enterprise and she has Pro. She only needs to run a few windows programs and browse the internet. I also enjoy learning and I’m trying this on my machine and it has pro also. Once I test this out on my pc I’ll find what works best for her .
      Thanks Robert

    • @nvidiashield495
      @nvidiashield495 2 ปีที่แล้ว +1

      Ok I got it working via group policy under system\Device guard\deploy windows Defender App control.Great video and thanks for your time.
      Note: just notes for myself. I know your aware already of GPO’s