Publisher Rules
Windows Defender Application Control (WDAC) publisher rules enable administrators to define policies that allow or block applications based on their digital certificate publisher. This is critical for enforcing trusted software execution while preventing unsigned or untrusted applications from running. Publisher rules are particularly useful in environments where software is signed by known vendors, allowing granular control over application sources.
Creating Publisher Allow Rules¶
To allow applications from a specific publisher, use the Add-WdacPublisherRule cmdlet. This requires the publisher’s certificate thumbprint and the path to the executable or script.
Example: Allow all .exe files signed by "Contoso Inc."
Steps:
1. Retrieve the publisher’s thumbprint:
Set-WdacPolicy and add the rule.3. Deploy the policy via Group Policy or the WDAC tool.
Creating Publisher Block Rules¶
To block applications from a specific publisher, use Add-WdacBlockPublisherRule. This prevents any executable signed by the specified publisher from running.
Example: Block all applications from "Untrusted Dev Co."
Note: Block rules apply to all executables from the specified publisher, regardless of file path.
Testing and Validation¶
Before deploying, validate the policy using Test-WdacPolicy to ensure rules are correctly applied:
Deployment Considerations¶
- Group Policy: Use the WDAC template (.wdat) file in the Group Policy Management Console (GPMC).
- Local Policy: Apply the policy via
Set-WdacPolicyon the target machine. - Certificate Trust: Ensure the publisher’s certificate is trusted in the local machine store; otherwise, the rule may fail.
Key takeaways¶
- Publisher rules enforce application control based on digital certificates.
- Use
Add-WdacPublisherRuleto allow trusted publishers andAdd-WdacBlockPublisherRuleto block untrusted ones. - Validate policies with
Test-WdacPolicybefore deployment. - Always ensure certificates are trusted and accessible in the local store.
- Combine publisher rules with other WDAC policies (e.g., path rules) for layered security.