Replies: 2 comments 2 replies
-
Hi, A supplemental policy's job is only to expand the scope of a base policy, by allowing more files. You can deploy Microsoft recommended block rules with 2 allow all rules as a stand-alone base policy, then deploy another base policy as your main policy and associate any future supplemental policies with your main policy. That way you can keep the recommended block rules up to date separately than your main base policy. |
Beta Was this translation helpful? Give feedback.
-
^ This is the correct answer. The WDAC feature team and I recommend 2 base policies (1 with your baseline allowlist and the other the recommended block rules). |
Beta Was this translation helpful? Give feedback.
-
Hi, I was wondering what method other people are using to include the Microsoft's recommended Block Rules in their WDAC policies. As far as I can see the choices are:
or
Is one method easier to maintain? Are there any other/better ways of doing this?
Best wishes,
Iain
Beta Was this translation helpful? Give feedback.
All reactions