{"id":18988,"date":"2024-08-27T01:25:04","date_gmt":"2024-08-27T01:25:04","guid":{"rendered":"https:\/\/www.insentragroup.com\/gb\/insights\/uncategorized\/enable-windows-defender-application-control-with-microsoft-intune\/"},"modified":"2024-08-27T01:25:05","modified_gmt":"2024-08-27T01:25:05","slug":"enable-windows-defender-application-control-with-microsoft-intune","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/gb\/insights\/geek-speak\/secure-workplace\/enable-windows-defender-application-control-with-microsoft-intune\/","title":{"rendered":"Enable Windows Defender Application Control with Microsoft Intune"},"content":{"rendered":"\n<p>Windows Defender Application Control (WDAC) is the next iteration of AppLocker. WDAC is one of the most effective security controls to prevent ransomware attacks.\u202fIt ensures only approved apps can be run on your devices.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WINDOWS EDITION AND LICENSING REQUIREMENTS<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">SUPPORTED WINDOWS EDITION<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-2.png\" alt=\"\" class=\"wp-image-21174\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">REQUIRED LICENSES<\/h3>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-3.png\" alt=\"\" class=\"wp-image-21175\"\/><\/figure>\n\n\n\n<p>In this blog we are going to cover all the steps needed to implement WDAC with Intune.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">CREATE A MANAGED INSTALLER<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Login to the Intune Admin Center at \u202f<a href=\"https:\/\/intune.microsoft.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">https:\/\/intune.microsoft.com<\/a><\/li>\n\n\n\n<li>Click Endpoint Security &gt; App control for Business (Preview)\u202f&nbsp;<\/li>\n\n\n\n<li>Click Managed Installer &gt; Add &gt; and then click add again after reading the instructions as shown in the image&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-13-1024x211.png\" alt=\"\" class=\"wp-image-22463\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">CREATE AN APPLICATION CONTROL POLICIES<\/h2>\n\n\n\n<p>Next, we\u2019re going to create an application control policy.\u202f\u202fClick Endpoint Security &gt; App control for Business &gt; Create policy&nbsp;<\/p>\n\n\n\n<p>To create the policy, we\u2019ll choose create policy and we\u2019ll give it a name like \u201cApp Control\u201d\u202f\u202fand click Next.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-14-1024x374.png\" alt=\"\" class=\"wp-image-22465\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-3.png\" alt=\"\" class=\"wp-image-22455\"\/><\/figure>\n\n\n\n<p>Here, you can see we\u2019ve got a couple of options.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-5-1024x227.png\" alt=\"\" class=\"wp-image-22457\"\/><\/figure>\n\n\n\n<p>We have to enter XML data, which is the preferred way to do this. We will cover both options but let\u2019s start with built-in controls.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-9-1024x196.png\" alt=\"\" class=\"wp-image-22458\"\/><\/figure>\n\n\n\n<p>If we use the built-in controls, we enforce Windows components and Store apps to be trusted. We can also set to audit only. It is recommended that you use the audit only option if you are deploying this in your environment for the first time to gather telemetry on the applications you are using.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-10-1024x262.png\" alt=\"\" class=\"wp-image-22459\"\/><\/figure>\n\n\n\n<p>The other options we get is to select additional rules for trusting apps, which means that we can also trust apps with good reputation and those from managed installers (the one that we configured earlier).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-11-1024x153.png\" alt=\"\" class=\"wp-image-22460\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">WDAC WIZARD<\/h2>\n\n\n\n<p>Now, let\u2019s talk about the XML data as the configuration settings format. The best way to create the XML data is to download the wizard from this link \u2013\u202f<a href=\"https:\/\/webapp-wdac-wizard.azurewebsites.net\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">https:\/\/webapp-wdac-wizard.azurewebsites.net\/<\/a>.<\/p>\n\n\n\n<p>Once you download the wizard, click Policy Creator and click Next.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/08\/image-12-1024x620.png\" alt=\"\" class=\"wp-image-22461\"\/><\/figure>\n\n\n\n<p>Multiple Policy Format and Base Policy will be selected by default, so just click Next.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-31-1024x472.png\" alt=\"\" class=\"wp-image-21683\" style=\"width:561px;height:259px\"\/><\/figure>\n\n\n\n<p>On the next page, select the radio button for Signed and Reputable Mode as the base template, then click Next.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-32-1024x508.png\" alt=\"\" class=\"wp-image-21684\" style=\"width:564px;height:280px\"\/><\/figure>\n\n\n\n<p>On the next page, make sure that all options shown in the image below are turned on.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-33.png\" alt=\"\" class=\"wp-image-21685\" style=\"width:561px;height:322px\"\/><\/figure>\n\n\n\n<p>There is an option to turn on audit mode for this policy template if you wish to.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-34-1024x238.png\" alt=\"\" class=\"wp-image-21686\" style=\"width:560px;height:131px\"\/><\/figure>\n\n\n\n<p>These are the default files that you would see once you Click Next.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-35-1024x700.png\" alt=\"\" class=\"wp-image-21687\" style=\"width:558px;height:381px\"\/><\/figure>\n\n\n\n<p>Click Next again and it will start building your WDAC policy.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-38.png\" alt=\"\" class=\"wp-image-21695\" style=\"width:395px;height:150px\"\/><\/figure>\n\n\n\n<p>Once the policy is created, you will be presented with the file path to download the .cip and .xml file.\u202f&nbsp;<\/p>\n\n\n\n<p>The file path will be \u2013 C:Users(Username)Documents\u202f&nbsp;<\/p>\n\n\n\n<p>Now, jump back to the Intune portal and go to the Create App Control for Business Profile section, browse to the path, then upload the xml file besides the Application control policy option.\u202f&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/au\/wp-content\/uploads\/sites\/22\/2023\/09\/image-37-1024x564.png\" alt=\"\" class=\"wp-image-21689\" style=\"width:564px;height:311px\"\/><\/figure>\n\n\n\n<p>If you have distributed IT, you can use scope tags.\u202f&nbsp;<\/p>\n\n\n\n<p>Finally, assign the profile to a security group containing the devices that you want WDAC to be set up on.\u202f&nbsp;<\/p>\n\n\n\n<p>Voila! That\u2019s it, you\u2019ve successfully configured WDAC with Intune. To ensure that only approved and secured applications run in your environment following the DevSecOps framework, WDAC is something you should consider implementing&nbsp; if you haven\u2019t already.\u202f&nbsp;<\/p>\n\n\n\n<p>If you have any questions or need assistance in implementing Intune, feel free to download our <a href=\"https:\/\/www.insentragroup.com\/gb\/insights\/geek-speak\/secure-workplace\/the-ultimate-guide-to-microsoft-intune\/\" target=\"_blank\" rel=\"noreferrer noopener\">Taming the Device Zoo: The Ultimate Guide to Microsoft Intune<\/a> eBook or\u202f<a href=\"https:\/\/www.insentragroup.com\/gb\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener\">contact us<\/a>. Our experts are here to support you on your journey to a more secure computing environment.\u00a0\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Prevent ransomware attacks with Windows Defender Application Control (WDAC). Learn to configure WDAC using Microsoft Intune for enhanced security. <\/p>\n","protected":false},"author":146,"featured_media":19023,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[20],"tags":[],"class_list":["post-18988","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-secure-workplace","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/18988","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/users\/146"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/comments?post=18988"}],"version-history":[{"count":19,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/18988\/revisions"}],"predecessor-version":[{"id":21830,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/posts\/18988\/revisions\/21830"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/media\/19023"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/media?parent=18988"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/categories?post=18988"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/gb\/wp-json\/wp\/v2\/tags?post=18988"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}