Implementing Australian Essential Eight Application Control via Windows Defender Application Control

Portsman 6 Reputation points
2022-02-21T00:48:09.667+00:00

Australian Government recommends implementation of Application Control specifically:

The execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets is prevented on workstations from within standard user profiles and temporary folders used by the operating system, web browsers and email clients.

They recommend using WDAC as a method to achieve this. I am really struggling though to simply put in place this relatively simple requirement.

WDAC Wizard does not appear to support any wildcard or variables for folder path rules, so how can I simply do something like %localappdata%\ ?

I have deployed a WDAC Wizard created policy in audit mode which said only Microsoft executables but after applying other software runs and nothing is logged in CodeIntegrity\Operational as advised should when auditing?

Can someone just read above and tell me what path rules to add that will actually be accepted and apply to block under user profiles and the temp folders? How can I tell if a policy is actually being applied? Seems should be so simple and already hours in and no where.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,990 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.