Update: SEPC & AG
It has been a little over two weeks now running SEPC & AG combination. For our use of system, this has become our permanent security choice. Once set up, there is nothing to do but to utilize the system for what you initially intended and enjoy. The combination is feather light, everything is extremely responsive.
We keep the machine light and the attack surface minimized to begin with. Once something is uploaded to the system, the first step is to plug in an external and move copies of it. Then once the external is removed, we use the item for intended purpose and that copy is then deleted from the system. Never storing anything on it.
We have only two applications we use, Office and Snagit. Both for business purposes. Both have been placed in Guarded Apps of AG. Matter of fact, if it was in the add list of guarded apps, and did not break functionality, it more then likely got added. I have removed Vendors from the Trusted Publisher list that were not used/needed for this machine.
I have disabled the main windows vulnerable processes, and a few others not listed here.
cmd.exe
powershell.exe
powershell_ise.exe
wscript.exe
cscript.exe
gpscript.exe
The main Base of the system, is well covered. SEPC covers my network, and internet sessions.
This set up in no way, diminishes productivity, and the only time i have to adjust anything security related is when i am performing maintenance. This will more then likely be my last entry in this thread, as i plan to stick to this combination, unless something unforeseeable happens in the future to either company/product.