Policy Enforcement
WDAC Templates and Policy Enforcement¶
Windows Defender Application Control (WDAC) enables granular application control by enforcing a whitelist of trusted applications. Templates define the allowed applications and enforcement rules, while Group Policy (GPO) ensures these policies are applied consistently across systems. This section explains how to create and deploy WDAC policies using GPO.
Creating a WDAC Template¶
A WDAC template is a policy file that defines allowed applications, enforcement modes, and trusted boot requirements. Templates are created using the Windows Defender Application Control Policy Creation Tool (GUI) or command-line tools.
Step-by-Step Template Creation¶
- Open the Policy Creation Tool:
-
Run
WindowsDefenderApplicationControlPolicyCreationTool.exefrom the Windows SDK or via PowerShell: -
Select Enforcement Mode:
-
Choose Audit mode to test the policy without enforcing it, or Enforce mode for production.
-
Define Trusted Applications:
-
Add allowed applications by specifying paths, hashes, or publishers. For example:
- Path-based rule:
C:\Windows\System32\cmd.exe - Publisher rule:
Microsoft Corporation
- Path-based rule:
-
Configure Trusted Boot:
-
Ensure the system boots into a trusted state by enabling Trusted Boot and specifying a trusted certificate.
-
Export the Template:
- Save the template as an
.xmlfile (e.g.,MyWDACPolicy.xml). This file will be deployed via GPO.
Deploying WDAC via GPO¶
Once the template is created, deploy it using GPO to enforce application control across managed systems.
GPO Configuration Steps¶
- Create a New GPO:
- Open the Group Policy Management Console (GPMC).
-
Right-click the target OU, select Create a GPO, and name it (e.g.,
WDAC Application Control). -
Link the GPO to the OU:
-
Ensure the GPO is linked to the organizational unit containing target systems.
-
Configure WDAC Settings:
- Navigate to Computer Configuration > Administrative Templates > Windows Components > Windows Defender Application Control.
-
Enable the following policies:
- Enforce WDAC signed policy: Set to Enabled and specify the path to your
.xmlfile. - Trusted boot: Enable this to ensure the system boots into a trusted state.
- Audit mode: Disable this in production environments after testing.
- Enforce WDAC signed policy: Set to Enabled and specify the path to your
-
Deploy the Template:
- Use the Windows Defender Application Control tool to import the
.xmlfile and apply it to the GPO.
Example: Enforcing a WDAC Policy via PowerShell¶
# Set the WDAC policy using the exported XML file
Set-ExecutionPolicy -ExecutionPolicy AllSigned -Scope LocalMachine
Note: The
Set-ExecutionPolicycmdlet is for AppLocker. For WDAC, use the GPO settings to enforce the template.
Key Takeaways¶
- Templates define allowed applications and enforcement rules, ensuring only trusted software runs.
- GPO deployment ensures consistent policy application across systems.
- Test in audit mode before enforcing to avoid unintended disruptions.
- Trusted boot is critical to prevent tampering with the policy or boot process.
- Always sign templates with a trusted certificate to avoid GPO enforcement failures.