Advice Request Is WDAC policy created online reliable?

Microsoft Defender
23 Replies 2,012 Views
Share practical recommendations that address the author's needs.
Might not be until a user gets acquainted with it. It's pretty comprehensive enough (manually granular) that i just installed it myself. Thanks @Victor M
Yes, her tools are comprehensive, well laid out, and smooth in navigation. She seems highly security-focused, which her tools reflect; the recommendations, where available, are strict, either set to on or warn, with no options disabled. I had just quickly looked at the tools; the features I tested worked well.

I always seek simplicity and usability; I am not a high-risk user to choose security over both of them.
@Andy Ful's tools are better than other hardening tools because they are simple, secure, and user-friendly. They also feature recommended presets from him for most users, without having to configure everything from the beginning. Expert users can further configure security if they desire more. The "Run By SmartScreen" context menu item is unique to his tools, which enhances security and whitelisting.
 
You would do well to put WDAC out of your mind. Microsoft's original software restriction policy (SRP) remains the best, and most capable, version.

AppLocker is Microsoft software restriction policy version 2 (SRPv2) and it is no longer being developed for years. It is in maintenance. Microsoft would get rid of it if it could, but too many enterprises and governments use it, and Microsoft does not want to invoke its big-money-spending clients.

WDAC is Microsoft software restriction policy version 3 (SRPv3) and it is a half-baked messed that is user unfriendly, does not work as intended, does not deploy very well in enterprise and government infrastructure, plus a long list of other issues. Looking at the official WDAC documentation, it appears Microsoft went a bit schizoid with it - not sure or confident of the direction, purpose, or intent of the feature. Way too many ways to do a few things, that only sows confusion and frustration. Then following all that, WDAC doesn't work.

SRPv1 will be shipped in Windows until Microsoft coverts to Apple OS. SRPv1 works, works very well, is easy to use, deploys seamlessly, and most enterprises and governments use it.

@Andy Ful 's Hard_Configurator is all that you need to achieve robust system lockdown - as long as you don't constantly use the Administrator account.

It's your system. Secure it or destroy it if you want to.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top