Skip to content

Publisher Rules

Windows Defender Application Control (WDAC) publisher rules enable administrators to define policies that allow or block applications based on their digital certificate publisher. This is critical for enforcing trusted software execution while preventing unsigned or untrusted applications from running. Publisher rules are particularly useful in environments where software is signed by known vendors, allowing granular control over application sources.


Creating Publisher Allow Rules

To allow applications from a specific publisher, use the Add-WdacPublisherRule cmdlet. This requires the publisher’s certificate thumbprint and the path to the executable or script.

Example: Allow all .exe files signed by "Contoso Inc."

Add-WdacPublisherRule -PublisherThumbprint "ABCD1234EFGH5678" -FilePath "C:\Windows\System32\*.exe"

Steps:
1. Retrieve the publisher’s thumbprint:

Get-ChildItem -Path "Cert:\LocalMachine\My" | Format-Table -Property Thumbprint, Subject
2. Create a WDAC policy using Set-WdacPolicy and add the rule.
3. Deploy the policy via Group Policy or the WDAC tool.


Creating Publisher Block Rules

To block applications from a specific publisher, use Add-WdacBlockPublisherRule. This prevents any executable signed by the specified publisher from running.

Example: Block all applications from "Untrusted Dev Co."

Add-WdacBlockPublisherRule -PublisherThumbprint "XYZ123456789ABCDEF"

Note: Block rules apply to all executables from the specified publisher, regardless of file path.


Testing and Validation

Before deploying, validate the policy using Test-WdacPolicy to ensure rules are correctly applied:

Test-WdacPolicy -FilePath "C:\TestApp.exe"
This confirms whether the file meets the publisher rule criteria.


Deployment Considerations

  • Group Policy: Use the WDAC template (.wdat) file in the Group Policy Management Console (GPMC).
  • Local Policy: Apply the policy via Set-WdacPolicy on the target machine.
  • Certificate Trust: Ensure the publisher’s certificate is trusted in the local machine store; otherwise, the rule may fail.

Key takeaways

  • Publisher rules enforce application control based on digital certificates.
  • Use Add-WdacPublisherRule to allow trusted publishers and Add-WdacBlockPublisherRule to block untrusted ones.
  • Validate policies with Test-WdacPolicy before deployment.
  • Always ensure certificates are trusted and accessible in the local store.
  • Combine publisher rules with other WDAC policies (e.g., path rules) for layered security.