Skip to content

Policy Creation

Windows Defender Application Control (WDAC) policies define the allowed applications and execution rules for a system. Creating these policies involves configuring rules that specify which executables, scripts, or signed code are permitted. This section explains how to create WDAC policies using the Microsoft Management Console (MMC) and PowerShell.


Prerequisites

Before creating WDAC policies:
1. Ensure the system runs Windows 10/11 or Windows Server 2016/2019/2022 with WDAC enabled.
2. Install the Windows Assessment and Deployment Kit (ADK) to access the WDAC snap-in.
3. Have a clear understanding of the applications or code you want to allow (e.g., signed binaries, specific executables, or trusted publishers).


Creating WDAC Policies via MMC

The MMC method uses the WDAC snap-in to define policies graphically.

Steps:

  1. Open Group Policy Management Console (GPMC).
  2. Right-click the target Organizational Unit (OU) and select Create a GPO.
  3. Name the GPO (e.g., WDAC Policy - Trusted Executables).
  4. Edit the GPO and navigate to:
    Computer Configuration > Administrative Templates > Windows Components > Windows Defender Application Control.
  5. Enable "Configure Windows Defender Application Control policy" and browse to the WDAC policy file (.wam or .xml).
  6. Link the GPO to the target OU and enforce the policy.

Example: Creating a Rule File

Use the WDAC snap-in to generate a rule file:

# Open WDAC snap-in (via MMC) and create a new policy  
# Example rule: Allow all signed executables from Microsoft  
# Save the rule file as C:\WDACRules\MicrosoftSigned.wam

Note: The MMC method is ideal for complex rule sets but requires manual configuration.


Creating WDAC Policies via PowerShell

PowerShell provides flexibility for scripting policy creation. Use the New-WdacPolicy cmdlet to define rules.

Basic Syntax:

New-WdacPolicy -PolicyFilePath "C:\WDACPolicy\MyPolicy.wam" -RuleFilePath "C:\WDACRules\Rules.xml"
- -PolicyFilePath: Path to the output WDAC policy file (.wam).
- -RuleFilePath: Path to the rule definition file (.xml).

Example: Allow Specific Executables

Create an XML rule file (Rules.xml) with the following content:

<WDACPolicy>
  <Rule>
    <Match>
      <FilePublisher>TrustedPublisher</FilePublisher>
      <FileHash>1234567890abcdef</FileHash>
    </Match>
    <Action>Allow</Action>
  </Rule>
</WDACPolicy>

Note: Replace TrustedPublisher and FileHash with actual values.

Example: Enforce Policy via PowerShell

# Apply the policy to the local machine  
Set-WdacPolicy -PolicyFilePath "C:\WDACPolicy\MyPolicy.wam" -Enforce

Testing and Validation

  1. Test the policy before deployment:
    Test-WdacPolicy -PolicyFilePath "C:\WDACPolicy\MyPolicy.wam"
    
  2. Audit mode (non-enforcing):
    New-WdacPolicy -PolicyFilePath "C:\WDACPolicy\AuditPolicy.wam" -RuleFilePath "C:\WDACRules\Rules.xml" -Audit
    
  3. Monitor Event Viewer (Event ID 1000) for policy violations.

Key Takeaways

  • MMC is suitable for graphical rule creation, while PowerShell offers scriptability.
  • Policies must be signed with a trusted certificate to enforce.
  • Always test policies in audit mode before enforcing.
  • Use XML rule files to define allowed applications, publishers, or hashes.
  • Deploy policies via GPO or registry for centralized management.