Skip to content

Managed Installer Integration

Integrating Managed Installer with Windows Defender Application Control (WDAC)

Windows Defender Application Control (WDAC) and Managed Installer work synergistically to enforce strict application installation and execution rules. While Managed Installer restricts how applications are installed (e.g., limiting sources to trusted publishers), WDAC controls which applications can run. Integrating these ensures layered security, preventing unauthorized installers from executing even if they bypass Managed Installer restrictions.


Enabling Managed Installer

Before creating WDAC policies, ensure Managed Installer is configured to enforce installation rules. This is typically done via Group Policy or registry settings:

# Enable Managed Installer via Group Policy (example)
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Installer\ManagedInstaller" -Name "DisableMSI" -Value 1

This setting disables unsigned MSI installers, aligning with WDAC's enforcement of trusted binaries. For precise configuration, consult Microsoft's official documentation for the correct registry path and Group Policy options.


Creating WDAC Policies for Installer Enforcement

WDAC policies must explicitly allow trusted installers while blocking untrusted ones. Use the Windows Defender Application Control policy editor (via secpol.msc) or PowerShell to define rules:

Example: Allow Only Signed Installers

# Create a WDAC policy allowing only signed installers
$rule = New-WdacRule -RuleType Allow -Publisher "Microsoft Corporation"
New-WdacPolicy -Name "WDACInstallerPolicy" -Path "C:\WDAC\InstallerPolicy.xml" -Rule $rule

Parameters Explanation (Allow Rule): - -Name: Specifies the policy name (e.g., WDACInstallerPolicy). - -Path: Defines the file path where the policy will be saved (e.g., C:\WDAC\InstallerPolicy.xml). - -Rule: Applies a rule object that defines the rule type and criteria (e.g., publisher).

Example: Block Specific Installer Paths

# Block installers from untrusted directories
$rule = New-WdacRule -RuleType Deny -Path "C:\Untrusted\*"
New-WdacPolicy -Name "WDACInstallerPolicy" -Path "C:\WDAC\InstallerPolicy.xml" -Rule $rule

Parameters Explanation (Deny Rule): - -Name: Specifies the policy name (e.g., WDACInstallerPolicy). - -Path: Defines the file path where the policy will be saved (e.g., C:\WDAC\InstallerPolicy.xml). - -Rule: Applies a rule object that defines the rule type and criteria (e.g., path pattern).


Testing and Deployment

  1. Test in a Lab Environment: Use the Set-WdacPolicy cmdlet to enforce the WDAC policy in a controlled setting:

    Set-WdacPolicy -Policy "C:\WDAC\InstallerPolicy.xml" -Scope "LocalMachine"
    

  2. Deploy via Group Policy: Link the WDAC policy file to organizational units (OUs) to enforce it across systems.

  3. Monitor with Event Logs: Check the Windows Defender Application Control event logs (Event ID 1000) to verify enforcement.


Key Takeaways

  • Layered Security: Combine Managed Installer (installation control) with WDAC (execution control) for robust protection.
  • Publisher Signing: Prioritize policies that allow only signed installers, aligning with Managed Installer's trust model.
  • Granular Rules: Use WDAC to block specific paths or publishers, reinforcing Managed Installer restrictions.
  • Test Thoroughly: Validate policies in a lab before production deployment to avoid unintended disruptions.