Configuring Application Control
A new feature to Intune is Application Control, which extends the Windows Defender Application Control (WDAC) functionality but with an easier deployment.
There are two methods of deploying Application Control – via a GUI with boxes to select and using an XML file created for WDAC.
For this example, we will be using the GUI method, but if you would rather have more granular control, you can use the WDAC wizard from Microsoft to assist in creating the file.
You can read more about that here: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/wdac-wizard.
How to do it…
Before we can create our policy, we need to activate Managed Installer. This allows the Intune Management extension to install applications without restrictions. Follow these steps to configure it in your environment:
- Click on Endpoint Security and then App Control for Business.
- At the top, click...