Jump to content

Recommended Posts

Posted
I am testing WDAC (instead of Applocker), I have allowed 'Managed Apps' so anything deployed via Intune is allowed, and I am adding certain Publisher rules (Avid, Steinberg, Adobe, Logmein etc) to allow some things to run that will or may get installed manually (e.g. Cubase, Wireshark etc), but what we are finding is that it may start installing, but then errors with '...does not meet enterprise requirements' and a path to a random (unsigned) file in .tmp or appdata or something. I can not see how we can implement WDAC and have any manual installs - which will be very annoying.
 
Applocker allows group based restriction, so we have a 'dont apply to admins' thing which obviously works.
 
Any thoughts?
Thanks
Posted

In my opinion WDAC is not a fit replacement for Applocker. Indeed several modern features  of Intune delivered security profiles now use applocker instead of WDAC.

Furthermore, just because an app comes from the app store, it is not necessarily a "modern app" in the sense WDAC (or applocker) is expecting, these days  they can be used as a distribution tool rather than philosophical statement, hence the unpacked .exe in temp folders during install.

When I was looking at WDAC, (back when and appx/Metro was the future), I got the impression that it was designed to restrict apps to only those specifically approved by IT, on a per machine basis with no regard to the end user.

Posted
46 minutes ago, petben said:
I am testing WDAC (instead of Applocker), I have allowed 'Managed Apps' so anything deployed via Intune is allowed, and I am adding certain Publisher rules (Avid, Steinberg, Adobe, Logmein etc) to allow some things to run that will or may get installed manually (e.g. Cubase, Wireshark etc), but what we are finding is that it may start installing, but then errors with '...does not meet enterprise requirements' and a path to a random (unsigned) file in .tmp or appdata or something. I can not see how we can implement WDAC and have any manual installs - which will be very annoying.
 
Applocker allows group based restriction, so we have a 'dont apply to admins' thing which obviously works.
 
Any thoughts?
Thanks

In this scenario what you would need to do is create catalog files to allow the unsigned code.

Deploy catalog files to support App Control for Business | Microsoft Learn

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...