Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
WDAC - Has Anyone setup a custom policy and deployed this before? Looking for advice/suggestions for the best way to deploy this via Intune.
Post Flair (click to view more posts with a particular flair)
Post Body

Hi All

Client of ours has asked to implement WDAC for all thier devices company wide. The plan is to deploy this via Intune

WDAC Has been in audit mode the past month and we have collected the relevant events from event viewer that state which executables/msi's/dll's have been picked up by WDAC and would have bene blocked but were audited instead. These events were pulled from developer devices over the course of a week or so.

Looking into the documentation, the WDAC Wizard creates a base policy then additions need to be made to this policy based on the log file entries that state execution was blocked but allowed as the policy was in audit mode.

For context, Client is needing two different policies.

  • One for developers who need a more leniant policy as they run debuggers/programming scripts that are not installed with intune
  • One for general staff who dont use fancy software and just whatever is deployed to thier device via Intune.

This seems like way to much tedious manual work.. For one user for example theres' something like 500 logs with different MSI's/DLLs and executables bieng run in the background as part of thier day to day work.

I mean I could just slog away and create exceptions for all the individual files the got audited on, but this seems very ridiculous. Is there any easier way to do this? Surely there is?

How has everyone else done this?

Any push in the right direction would be greatly appreciated

Thanks

Author
Account Strength
100%
Account Age
10 years
Verified Email
Yes
Verified Flair
No
Total Karma
45,840
Link Karma
35,921
Comment Karma
8,889
Profile updated: 9 hours ago
Posts updated: 3 months ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
5 months ago