Forum Discussion

DiogoSousa's avatar
DiogoSousa
Iron Contributor
Jan 04, 2023

WDAC not applying via Group Policy

Hello and greetings from Portugal!

 

I'm trying to implement WDAC via group policy.

I've used WDAC Wizard and if I copy the *.cip file to "C:\Windows\System32\CodeIntegrity\CiPolicies\Active" I see that WDAC get enabled, for example using the MSInfo32.


But, I cannot enable  WDAC via GPO. I've converted the *.xml to *.bin and enable the "Deploy Windows Defender Application Control".

I see the event id 7010 "Device Guard successfully processed the Group Policy: Configurable Code Integrity Policy = Enabled" but the thing is MSInfo still doesn't show that WDAC is activated.

 

Can someone please help?

Resources