Audit Mode
Windows Defender Application Control (WDAC) audit mode enables administrators to monitor system behavior and policy compliance without enforcing restrictions. This mode is ideal for evaluating policy impacts, identifying potential conflicts, or validating rule sets before transitioning to enforcement. Configuration involves adjusting Group Policy or PowerShell settings to activate audit mode, followed by log analysis to verify compliance and detect unauthorized activity.
Enabling Audit Mode via Group Policy¶
- Open Group Policy Management Console (GPMC) and create/edit a Group Policy Object (GPO).
- Navigate to:
Computer Configuration > Administrative Templates > Windows Components > Windows Defender Application Control - Enable the policy "Configure audit mode" and set it to Enabled.
- Optional: Configure audit logging settings (e.g., log file location, retention) under "Audit logging settings".
- Link the GPO to the target OU and restart the system for changes to take effect.
Example command to verify audit mode status via PowerShell:
Enabling Audit Mode via PowerShell¶
Use the Set-ApplicationControlPolicy cmdlet to configure audit mode:
To verify the current mode:
Note: Ensure the system is in a state where enforcement is disabled (e.g., no WDAC policies are active) before enabling audit mode.
Monitoring Audit Logs¶
Audit mode logs are stored in the Event Viewer under:
Windows Defender Application Control > Operational Log
Example command to query audit logs via PowerShell:
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows Defender Application Control/Operational'; ID=10001} | Format-List
Review logs for entries indicating allowed or denied application attempts, policy violations, or rule mismatches.
Key takeaways¶
- Audit mode allows policy evaluation without enforcing restrictions.
- Configure audit mode via Group Policy or PowerShell by setting
PolicyModetoAudit. - Monitor logs in Event Viewer or via PowerShell to assess compliance and identify risks.
- Transition to enforcement mode only after validating policies in audit mode.
- Always test policies in audit mode before applying them to production systems.