Skip to content

Best Practices

Windows Defender Application Control (WDAC) managed installers provide a controlled way to allow unsigned installers to execute while maintaining security. Proper configuration and management of these installers require careful policy design, regular validation, and strict access controls. Below are best practices to ensure secure and effective integration of managed installers within a WDAC environment.


1. Enforce Strict Policy Enforcement

Always use the "Allow" rule type for managed installers, specifying exact paths or hashes to minimize attack surfaces. Avoid broad permissions that could inadvertently allow malicious software.
Example:

# Create a WDAC policy allowing a specific installer (e.g., C:\Tools\CustomInstaller.exe)
New-WdacPolicy -Name "CustomInstallerPolicy" -Path "C:\Policies\CustomInstallerPolicy.xml" -Rule "Allow" -Path "C:\Tools\CustomInstaller.exe"
This ensures only the specified installer is permitted, reducing the risk of unauthorized execution.


2. Regularly Audit and Update Policies

Periodically review and update your WDAC policies to reflect changes in software dependencies or organizational needs. Use tools like the Windows Defender Application Control Management Console or PowerShell to validate rule compliance.
Example:

# Check for policy violations in a test environment
Test-WdacPolicy -PolicyFilePath "C:\Policies\CustomInstallerPolicy.xml" -FilePath "C:\Tools\UntrustedInstaller.exe"
This helps identify if unintended software is being allowed.


3. Use Hash Rules for Critical Installers

For high-security environments, use hash-based rules to lock down specific installers. This prevents tampering or substitution of the installer binary.
Example:

<!-- Example hash rule in WDAC policy -->
<Policy>
  <Rule>
    <Match>
      <Path>C:\Tools\CriticalInstaller.exe</Path>
      <Hash Algorithm="SHA256">ABCE1234567890ABCDEF1234567890ABCDEF1234567890</Hash>
    </Match>
    <Action Allow />
  </Rule>
</Policy>
Ensure the hash is calculated using certutil -hashfile or PowerShell’s Get-FileHash.


4. Isolate and Test in Controlled Environments

Before deploying managed installer policies, test them in isolated lab environments to avoid disruptions. Use test mode to simulate execution without enforcing policies.
Example:

# Enable test mode for policy validation
Set-WdacPolicy -PolicyFilePath "C:\Policies\CustomInstallerPolicy.xml" -TestMode
This allows you to verify behavior without affecting production systems.


5. Monitor and Log Installer Activity

Enable detailed logging to track managed installer execution and detect anomalies. Use Event Viewer (Event ID 1000-1010) or Windows Security logs to analyze access patterns.
Example:

# Query logs for installer-related events
Get-WinEvent -FilterHashtable @{LogName='Security'; ID=1000,1001,1002} | Format-List
Regular monitoring helps identify potential misuse or policy bypasses.


Key takeaways

  • Use precise rules (paths, hashes) to avoid over-permissioning.
  • Audit policies regularly to align with evolving software needs.
  • Test policies in isolation before production deployment.
  • Enable logging to detect suspicious installer activity.
  • Prioritize hash-based rules for critical or sensitive installers.