This page covers only using the Endpoint Protection template to configure two standard WDAC options. While this is good, it would be useful to add a section on implementing a custom WDAC policy in Intune. Without this section, the implication is that you can ONLY use the Endpoint Protection template to configure WDAC in Intune.
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@officedocsbot assign @jvsam
Hi @Air-Git thanks for the feedback. Let me get this over to the Windows content writing team for review and to suggest a brief explanation of all the available Endpoint Protection settings in Microsoft Intune. We'll also add the fix for the following issues as well:
We really appreciate your feedback and thank you for being part of the Microsoft Docs Community and for helping improve the quality of the technical documentation!
Thanks.
I think the first para is incorrect. It should read: "You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure either an Endpoint Protection profile for WDAC, or a Custom profile with an OMA-URI setting for Code Integrity (part of the AppLocker CSP)".
The rest of the current document is then a section on using the Endpoint Protection profile.
Under a new section on the custom OMA-URI setting, it should refer to the AppLocker CSP Code Integrity policy.
Hello @Air-Git, we really appreciate your patience and thank you again for sharing your feedback. Please be informed that the pull request (See PR #5659) that contains suggestions based from your feedback has been approved and merged. This documentation will be updated in the next scheduled publishing run. We will now close this issue, thank you for being part of the community!
@officedocsbot close
Two things:
1) I think, accurately, it is a custom "OMA-URI setting" instead of an "OMA-URI". The OMA-URI is the resource, and the setting is the data applied to the resource.
2) The first para of the correction is a non sequitur. The second sentence describes two methods of using Intune to configure WDAC. The third sentence again implies there is only one method.
Hi @Air-Git, I think in this case, it's best if you can create a Pull Request (PR) to propose the changes? Otherwise, please let us know exactly what you want to add and we can submit a PR on your behalf. Thank you.
CC: @joinimran @illfated
Very well, I am prepared in case you want us to create the pull request for you. In that case, if you could suggest a more detailed phrasing for the text, simply copy the relevant text section from the page, paste it into a new comment field and edit it to say what you feel is the proper wording.
edit: I get the part about "a custom OMA-URI setting" instead of an OMA-URI.
"You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can either configure an Endpoint Protection profile for WDAC, or create a custom profile with an OMA-URI setting. Using an Endpoint Protection profile, you can configure Windows 10 client computers to only run Windows components and Microsoft Store apps, or let them also run reputable apps defined by the Intelligent Security Graph."
Most helpful comment
Thanks.
I think the first para is incorrect. It should read: "You can use Microsoft Intune to configure Windows Defender Application Control (WDAC). You can configure either an Endpoint Protection profile for WDAC, or a Custom profile with an OMA-URI setting for Code Integrity (part of the AppLocker CSP)".
The rest of the current document is then a section on using the Endpoint Protection profile.
Under a new section on the custom OMA-URI setting, it should refer to the AppLocker CSP Code Integrity policy.