Skip to content

Latest commit

 

History

History
51 lines (39 loc) · 3.29 KB

WDAC.md

File metadata and controls

51 lines (39 loc) · 3.29 KB

10. WDAC: (Windows Defender Application Control)

!!! danger

**Work in Progress,** please review all content before starting, and be cautious in deployment
Start in Test/UAT and avoid outliers like Developers
Documentation on this page is **very** light at the moment and needs more review

Troubleshooting:

From Eric Mannon:

  • https://www.linkedin.com/feed/update/urn:li:activity:6996238396973051904/
  • Read the above article first
  • 1st- Install WDACme on all W10 workstations
  • 2nd- Enable "Smart Application Control" in Evaluation mode on W11 endpoints that support it
  • 3rd- Lock down Tier 0 (DC's, ADFS & AD Connect servers) with WDAC Microsoft-only mode in block mode. (No 3rd party software should ever be installed on the Tier 0 server type)
  • 4th- Deploy a supplemental policy to block the Microsoft recommended block list
  • 🔑Golden rule: "Audit is better than nothing"
  • 🎯Desired state: "Zero Trust for unapproved code"

🎒Resources:

Deeper Background

Additional Resources