petben Posted June 2 Posted June 2 I am testing WDAC (instead of Applocker), I have allowed 'Managed Apps' so anything deployed via Intune is allowed, and I am adding certain Publisher rules (Avid, Steinberg, Adobe, Logmein etc) to allow some things to run that will or may get installed manually (e.g. Cubase, Wireshark etc), but what we are finding is that it may start installing, but then errors with '...does not meet enterprise requirements' and a path to a random (unsigned) file in .tmp or appdata or something. I can not see how we can implement WDAC and have any manual installs - which will be very annoying. Applocker allows group based restriction, so we have a 'dont apply to admins' thing which obviously works. Any thoughts? Thanks
psydii Posted June 2 Posted June 2 In my opinion WDAC is not a fit replacement for Applocker. Indeed several modern features of Intune delivered security profiles now use applocker instead of WDAC. Furthermore, just because an app comes from the app store, it is not necessarily a "modern app" in the sense WDAC (or applocker) is expecting, these days they can be used as a distribution tool rather than philosophical statement, hence the unpacked .exe in temp folders during install. When I was looking at WDAC, (back when and appx/Metro was the future), I got the impression that it was designed to restrict apps to only those specifically approved by IT, on a per machine basis with no regard to the end user.
NicholasEsping Posted June 2 Posted June 2 46 minutes ago, petben said: I am testing WDAC (instead of Applocker), I have allowed 'Managed Apps' so anything deployed via Intune is allowed, and I am adding certain Publisher rules (Avid, Steinberg, Adobe, Logmein etc) to allow some things to run that will or may get installed manually (e.g. Cubase, Wireshark etc), but what we are finding is that it may start installing, but then errors with '...does not meet enterprise requirements' and a path to a random (unsigned) file in .tmp or appdata or something. I can not see how we can implement WDAC and have any manual installs - which will be very annoying. Applocker allows group based restriction, so we have a 'dont apply to admins' thing which obviously works. Any thoughts? Thanks In this scenario what you would need to do is create catalog files to allow the unsigned code. Deploy catalog files to support App Control for Business | Microsoft Learn
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now