Harden-Windows-Security
Harden-Windows-Security copied to clipboard
Upcoming Windows change: 🚀 Citool shows which policies are Signed
Currently only available in Windows insider builds in Dev channel and above, Citool has many new features and capabilities, including showing whether a deployed policy is signed or not.
When the change reaches the stable build of Windows, WDACConfig module should be updated to use this new capability.
https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/operations/citool-commands
At the moment, the latest Windows insider Dev build is: https://blogs.windows.com/windows-insider/2023/07/19/announcing-windows-11-insider-preview-build-23506/
Remove-WDACConfig -UnsignedOrSupplementalshould not allow removing policies marked as signed in Citool.