Although SAC uses WDAC-based policies, it cannot be fully replicated by WDAC and vice versa.
For example:
- SAC allows by default PE files (EXE, DLL, etc.) that are signed with any valid certificates (the certificate does not have to be specified). WDAC cannot replicate this (you must explicitly include a concrete certificate in the policy).
- SAC blocks by default some file types downloaded from the Internet (such as APPREF-MS, BAT, CMD, CHM, CPL, IMG, ISO, JS, JSE, LNK, MSC, MSP, REG, VBE, VBS, VDH, VHDX, and WSF). WDAC does not block scripts but can restrict their content (VBScript, JScript, PowerShell).
In WHHLight, I use SAC + SWH or WDAC light settings + SWH.
SWH can block far more file types than SAC.
WDAC Wizard and Spynetgirl's App Control Manager do not work on Windows Home. Managing WDAC on Windows Home requires another treatment, which I use in WHHLight.