Forum Discussion
StuartK73
Jul 22, 2020Steel Contributor
Can't get rid of WDAC Block
Hi All We rolled out an Endpoint Protection policy with WDAC on, but it has had a negative effect on some users. Now we have unassigned the Endpoint Protection policy with WDAC, yet apps are ...
StuartK73
Oct 16, 2020Steel Contributor
Hi Buddy
I think we had some National Cyber Security Centre (NCSC) Endpoint Protection policies deployed that had a WDAC payload.
Check what configs are being deployed to your devices.
Regards
r0bu
Oct 17, 2020Brass Contributor
You can apply another policy with WDAC set to audit and that will remove the enforcement.
- dj675414Oct 17, 2020Copper ContributorThat’s exactly what I did last night, keep in mind this does cause a force reboot on all client machines this policy deploys to.
The problem for us, I use a 3rd party packager when Win32app doesn’t fit the bill. Some of those apps looked foreign to defender and it blocked used access to them after a change in the policy.