Option 0 — Enabled:UMCI (User Mode Code Integrity)
2026-05-02
Enabled:UMCI extends Windows Defender Application Control enforcement from kernel-mode code down into the full user-mode execution space. Without this option,
2547 words
|
13 minutes
Option 1 — Enabled:Boot Menu Protection
2026-05-02
Current Support Status: Not currently supported by Windows
2588 words
|
13 minutes
Option 2 — Required:WHQL (Windows Hardware Quality Labs Certification)
2026-05-02
Required:WHQL tightens the kernel-mode driver signing standard from the broader Microsoft-signed requirement to the stricter Windows Hardware Quality Labs cert
2624 words
|
13 minutes
Option 3 — Enabled:Audit Mode (Default)
2026-05-02
Enabled:Audit Mode places an App Control for Business policy in a non-enforcing observation state. When Audit Mode is active, the Code Integrity engine evaluate
2772 words
|
14 minutes
Option 4 — Disabled:Flight Signing
2026-05-02
Disabled:Flight Signing removes the implicit trust that WDAC / App Control for Business policies grant to Windows Insider build certificates. In the default WD
3158 words
|
16 minutes
Option 5 — Enabled:Inherit Default Policy
2026-05-02
XML Value: <Rule><Option>Enabled:Inherit Default Policy</Option></Rule>
2345 words
|
12 minutes
Option 6 — Enabled:Unsigned System Integrity Policy
2026-05-02
XML Value: <Rule><Option>Enabled:Unsigned System Integrity Policy</Option></Rule>
2679 words
|
13 minutes
Option 7 — Allowed:Debug Policy Augmented
2026-05-02
XML Value: <Rule><Option>Allowed:Debug Policy Augmented</Option></Rule>
2366 words
|
12 minutes
Option 10 — Enabled:Boot Audit on Failure
2026-05-02
Applies to Supplemental Policies: No
2003 words
|
10 minutes
Option 8 — Required:EV Signers
2026-05-02
XML Value: <Rule><Option>Required:EV Signers</Option></Rule>
2936 words
|
15 minutes
Option 12 — Required:Enforce Store Applications
2026-05-02
Applies to Supplemental Policies: No
2192 words
|
11 minutes
Option 11 — Disabled:Script Enforcement
2026-05-02
Applies to Supplemental Policies: No
2260 words
|
11 minutes
Option 9 — Enabled:Advanced Boot Options Menu
2026-05-02
XML Value: <Rule><Option>Enabled:Advanced Boot Options Menu</Option></Rule>
3328 words
|
17 minutes
Option 13 — Enabled:Managed Installer
2026-05-02
Applies to Supplemental Policies: Yes
3909 words
|
20 minutes
Option 15 — Enabled:Invalidate EAs on Reboot
2026-05-02
Dependency: Requires Option 14
2810 words
|
14 minutes
Option 14 — Enabled:Intelligent Security Graph Authorization
2026-05-02
Applies to Supplemental Policies: Yes
4803 words
|
24 minutes
Option 17 — Enabled:Allow Supplemental Policies
2026-05-02
Minimum OS Version: Windows 10 version 1903 / Windows Server 2022
4636 words
|
23 minutes
Option 16 — Enabled:Update Policy No Reboot
2026-05-02
Minimum OS Version: Windows 10 version 1709 / Windows Server 2019
2851 words
|
14 minutes
Option 19 — Enabled:Dynamic Code Security
2026-05-02
XML Token: Enabled:Dynamic Code Security
3291 words
|
16 minutes
Option 18 — Disabled:Runtime FilePath Rule Protection
2026-05-02
Minimum OS Version: Windows 10 version 1903 / Windows Server 2022
4407 words
|
22 minutes
Developer Mode Dynamic Code Trust
2026-05-02
XML Token: Enabled:Developer Mode Dynamic Code Trust
4501 words
|
23 minutes
Option 20 — Enabled:Revoked Expired As Unsigned
2026-05-02
XML Token: Enabled:Revoked Expired As Unsigned
4146 words
|
21 minutes
Part 8: AppLocker, Managed Installer (Option 13) & Selective MSI Allowlisting — End-to-End
2026-05-02
AppLocker is a Windows feature that lets administrators restrict which applications users can run. It predates WDAC and operates at a higher abstraction level
7114 words
|
36 minutes
Part 1: Introduction & Key Concepts
2026-05-01
Traditional security solutions are reactive — they respond after a threat has already executed. This creates a gap between detection and response that attackers
2092 words
|
10 minutes