Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WDAC rules are not generated on Windows Server 2019 #39

Open
simon-baer opened this issue Jul 24, 2023 · 1 comment
Open

WDAC rules are not generated on Windows Server 2019 #39

simon-baer opened this issue Jul 24, 2023 · 1 comment

Comments

@simon-baer
Copy link

WDAC is supported on Windows Server 2016 and later.
However the Create-Policies script does not generate WDAC policies and reports the following:
AaronLocker supports WDAC on Windows 10 version 1903 (build 18362) and greater. Current build is 17763. Processing AppLocker only.

After I disabled the check in Create-Policies.ps1, the script reports errors on the Set-CIPolicyIdInfo command because on Windows Server 2019 this commandlet does not have a -ResetPolicyID parameter.

@AaronMargosis
Copy link

WDAC is supported on WS2016 and later, but the WDAC feature set has evolved quite a lot since its first release in 2015. The features required for AaronLocker-like functionality using WDAC aren't present in WS2016 or WS2019.
The required AppLocker features are all present, though.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants