Skip to content

Code Integrity Rules

Windows Defender Application Control (WDAC) code integrity rules define the execution policies that govern which code can run on a system. These rules are critical for enforcing security boundaries by restricting unsigned, untrusted, or unauthorized code. By leveraging WDAC policies, administrators can ensure that only trusted binaries, signed by approved publishers, or code from specific paths are allowed to execute. This section explains how to define and manage code integrity rules effectively.


Understanding Code Integrity Rule Types

WDAC supports three primary rule types for code integrity:
1. AllSigned: All code must be signed by a trusted certificate. Unsigned or unsigned-by-unknown-publishers code is blocked.
2. RequireSigned: Code must be signed, but unsigned code is allowed (e.g., for legacy applications).
3. Unrestricted: No restrictions (not recommended for production environments).

Rules can also specify allowed publishers using certificate thumbprints or paths. For example, allowing code signed by "Contoso, Inc." or restricting execution to a specific directory.


Creating Code Integrity Rules with PowerShell

Use the New-WdacPolicy cmdlet to define rules. Example:

New-WdacPolicy -Policy AllSigned -FilePath "C:\WDAC\CodeIntegrity.xml" -Publisher "Contoso, Inc." -Thumbprint "A1B2C3D4E5F67890"
This creates a policy that allows only code signed by "Contoso, Inc." with the specified thumbprint.

Example: Restricting Execution to Signed Code

New-WdacPolicy -Policy RequireSigned -FilePath "C:\WDAC\RequireSigned.xml" -Publisher "Microsoft Corporation" -PassThru
The -PassThru parameter outputs potential conflicts (e.g., unsigned binaries) without applying the policy.


Managing Rule Conflicts and Validation

Before deploying a policy, validate it using Test-WdacPolicy:

Test-WdacPolicy -PolicyFilePath "C:\WDAC\CodeIntegrity.xml" -ComputerName "Server01"
This checks for conflicts (e.g., missing dependencies, invalid certificates) and ensures the policy adheres to system constraints.

Troubleshooting Common Issues

  • Invalid Publisher Certificates: Ensure the thumbprint matches the certificate used to sign the code.
  • Missing Dependencies: Verify that all required binaries are signed and included in the policy.
  • Policy Conflicts: Use Get-WdacPolicy to review existing rules and resolve overlaps.

Best Practices for Code Integrity Rules

  1. Limit Publisher Trust: Avoid granting trust to unknown or unverified publishers.
  2. Use Specific Paths: Restrict execution to trusted directories (e.g., C:\Program Files\), not just signed code.
  3. Test in Isolation: Validate policies in a non-production environment before deployment.
  4. Regularly Update Certificates: Rotate or replace expired certificates to maintain compliance.

Key takeaways

  • Code integrity rules enforce execution policies to block unsigned or untrusted code.
  • Use New-WdacPolicy to define rules, specifying publishers or paths as needed.
  • Validate policies with Test-WdacPolicy to identify conflicts before deployment.
  • Prioritize specific publisher trust and path restrictions over broad policies.
  • Always test policies in a controlled environment to avoid unintended disruptions.