Using Windows Application Control via an Intune template

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 มิ.ย. 2023
  • In this video you'll see how to apply Windows Application Control using a standard Intune Endpoint Protection policy. You'll also see how you can use the Microsoft Intelligent Security Graph to also allow 'trusted applications' to run in your environment. Finally, there are are some tips and tricks with this process that will also be shared.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 20

  • @alanrahal7306
    @alanrahal7306 8 หลายเดือนก่อน +2

    Thanks Robert, nice and easy to understand

  • @ToTCaMbIu
    @ToTCaMbIu 6 หลายเดือนก่อน +2

    Great explanation! Any idea how one configures WDAC to be able to override it with a local admin account? e.g. install one single application for a single machine. Similar to what is possible with AppLocker.

    • @directorcia
      @directorcia  5 หลายเดือนก่อน

      WDAC is a device NOT user policy. If you want a user policy use AppLocker. WDAC because it is a device policy is far more secure.

  • @muhammadhassansiddiqui9129
    @muhammadhassansiddiqui9129 2 หลายเดือนก่อน

    Hi Robert, can we allow only notepad to a user and apply only to the user's group

  • @fbifido2
    @fbifido2 ปีที่แล้ว +1

    How can you enable Windows Application Control, plus allow your LOB apps, be it either 32bit or 64bit?

    • @directorcia
      @directorcia  ปีที่แล้ว +2

      You will probably need to use a more granular control like custom WDAC policies. But it can be done but custom apps probably need a custom WDAC policy, which can still be deployed via Intune. See my other videos on that here.

    • @GregThomson
      @GregThomson ปีที่แล้ว

      @directorcia might be worth a video?

    • @directorcia
      @directorcia  ปีที่แล้ว

      @@GregThomson sorry, far too complicated. Besides that’s WDAC and I have already done a video on that.

  • @jameseduard2092
    @jameseduard2092 ปีที่แล้ว

    awesome video guide, how can we manage to control on specific application to block only?

    • @directorcia
      @directorcia  ปีที่แล้ว

      Create a custom policy

    • @jameseduard2092
      @jameseduard2092 ปีที่แล้ว

      @@directorcia awesome thanks, do you have any guide sir, like for example we only want to block only specific apps like brave browser or we can specify which app is block, and not only the trusted Microsoft apps is it possible?

    • @directorcia
      @directorcia  ปีที่แล้ว

      @@jameseduard2092 Sorry, no. I suggest you consult the MS docs.

  • @clivebuckwheat
    @clivebuckwheat 7 หลายเดือนก่อน

    Can you do a white list of trusted apps for your organization?

    • @directorcia
      @directorcia  7 หลายเดือนก่อน

      Yes

    • @clivebuckwheat
      @clivebuckwheat 7 หลายเดือนก่อน

      @@directorcia how would I do this?

    • @directorcia
      @directorcia  7 หลายเดือนก่อน

      @@clivebuckwheatI suggest you review the MS docs. Basically instead of a line in the XML file blocking an app you'd have one allowing the app. Provided the software has a cert you could do it by public cert.

    • @clivebuckwheat
      @clivebuckwheat 7 หลายเดือนก่อน

      @@directorcia So blocking Apps would be much easier I have too much to white list, on your opinion?

    • @directorcia
      @directorcia  7 หลายเดือนก่อน

      @@clivebuckwheat I block known/unknown bad apps rather than allowing good apps. Far easier yes.