Skip to content

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant

  • Home
  • Post Series
    • WDAC Wednesday
  • Links library
  • About
    • Home
    • WDAC
WDAC

WDAC Wedesday: Audit mode advantage

Andrew 28 October 2025 0 Comments

Happy WDAC Wednesday! Application control solutions are very powerful, they are like a gate keeper, and determine what installed applications are allowed to run. Applying tighter controls on endpoints, using…

WDAC

WDAC Wedesday: Why anti-virus and EDR isn’t enough

Andrew 21 October 2025 0 Comments

Happy WDAC Wednesday! Welcome to a new series with the aim of detailing and demistifying Microsoft’s Application Control for Business (ACFB), a powerful solution used to allow or block applications…

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

Andrew 12 December 2023 0 Comments

Microsoft today published an update advisory for Windows Defender Application Control (WDAC) Advanced Hunting changes that could have an impact if you have any hunting rules or dashboards in place.…

WDAC

Creating a policy with the WDAC Wizard

Andrew 4 December 2023 0 Comments

The goal of this post is to step through the process of using the WDAC Wizard to create a sample WDAC policy and deploy it to a test Windows 10…

WDAC

Application control with Microsoft WDAC

Andrew 20 November 2023 0 Comments

This blog post will be the first (of many) in a series relating to Microsoft WDAC and how to understand, implement and manage it. In the current cyber security landscape…

WDAC

WDAC feature limitations on Windows Server versions

Andrew 23 May 2023 0 Comments

Windows Defender Application Control (WDAC) is a core component of Windows, since Windows 10 and Server 2016, which can be used as part of your security posture to secure workstations…

WDAC

#TIL WDAC logging and Policy Names from Windows Server 2016

Andrew 17 May 2023 0 Comments

In implementing a Windows Defender Application Control (WDAC) audit policy we discovered an interesting quirk with the information logged in the Windows Event Logs on Server 2016, that can make…

PowerShell WDAC

PowerShell script to convert WDAC XML file to binary CIP format

Andrew 30 March 2023 0 Comments

The Microsoft WDAC Wizard is a great tool for building and modifying WDAC policies, but there are times where it is necessary to manually modify the policy XML file. If…

WDAC

WDAC 3033 error workarounds

Andrew 16 September 2022 0 Comments

On a Windows Defender Application Control (WDAC) project one issue you may encounter is driver .dll or .sys files that are digitally signed, but the certificate has now expired. The…

Uncategorized WDAC

Confirm what WDAC policies are present on a device

Andrew 18 May 2022 0 Comments

Windows Defender Application Control (WDAC) is an application control system integrated into Windows 10/11 and is used within Enterprise to whitelist trusted applications, allowing them to run, and blocking either…

You Missed

WDAC

WDAC Wedesday: Audit mode advantage

WDAC

WDAC Wedesday: Why anti-virus and EDR isn’t enough

Microsoft Entra MIM2016

Looking to migrate from MIM to Microsoft Entra?

Sentinel WDAC

January 2024 WDAC Advanced Hunting changes

IT Dev Lab

Learnings and musings of a Microsoft Identity & Security consultant