Coming Soon: GET:IT Endpoint Management 1-Day Conference on September 28th at 9:30 AM ET Coming Soon: GET:IT Endpoint Management 1-Day Conference on September 28th at 9:30 AM ET
Security|Windows 10|Windows Client OS

Windows 10 Device Guard Versus AppLocker

In this Ask the Admin, I will explain the difference between Device Guard and AppLocker in Windows 10. We will also discuss whether they should be used independently of each other or together.



Sponsored Content

Say Goodbye to Traditional PC Lifecycle Management

Traditional IT tools, including Microsoft SCCM, Ghost Solution Suite, and KACE, often require considerable custom configurations by T3 technicians (an expensive and often elusive IT resource) to enable management of a hybrid onsite + remote workforce. In many cases, even with the best resources, organizations are finding that these on-premise tools simply cannot support remote endpoints consistently and reliably due to infrastructure limitations.

Application control or application whitelisting is an important line of defense for enterprises in the fight against malware. It has long been recognized that signature-based antimalware software is not enough by itself. Removing administrator privileges from end users, while definitely a critical step, also needs to be part of a defense-in-depth strategy.

Software Restriction Policies and AppLocker

Application whitelisting technology first appeared natively in Windows XP as Software Restriction Policies (SRP). It was not widely adopted because it was difficult to implement. AppLocker was introduced as a replacement for SRP in Windows 7. It is more flexible and easier to deploy. So, why does Windows 10 need a new application to control technology?

The tech behind Device Guard is not completely new but it is being exposed for the first time. There are other technologies such as Kernel Mode Code Integrity (KMCI) and User Mode Code Integrity (UMCI). KMCI came as part of Windows Vista and UMCI is new in Windows 10. These enforce policy rules that will allow drivers, user-mode binaries, MSIs, and scripts to run if signed off on by a trusted publisher. Furthermore, in Windows 10, KMCI can be protected by Virtualization-Based Security (VBS) on supported hardware. This isolates KMCI in a virtual machine that protects it. This is especially important should the Windows kernel be owned by malware. VBS can be enabled in Windows 10 by configuring Virtual Secure Mode (VSM) in Group Policy.

Does Device Guard Replace AppLocker?

AppLocker can block unsigned apps but Device Guard offers deeper integration. Using Windows makes it even more robust. It comes with a chain of trust from the hardware through to the kernel. It also provides better protection against tampering when VSM is enabled.

Device Guard should be your first line of defense. AppLocker works with Device Guard if you need to block certain apps from the Windows Store. Device Guard trusts everything from Microsoft and all store apps will run. AppLocker is not completely redundant and is also supported. You can continue to use AppLocker rules after upgrading from Windows 7.

Device Guard Improvements in the Creators Update

Device Guard is available in Windows 10 Enterprise and Education SKUs. There is no management GUI. If you want to enable UMCI, code integrity policies will need more comprehensive testing. Device Guard might not be quite ready to replace AppLocker in your organization. Nevertheless, Microsoft is working to improve Device Guard. Code integrity policies in the Windows 10 Creators Update (version 1703) can be used to determine whether specific plug-ins, add-ins, and modules are able to run. For example, you could block all Word add-ins that are not listed in the policy. Hopefully, future versions of Windows will see Microsoft build upon Device Guard’s capabilities, which helps to improve management.


Don't have a login but want to join the conversation? Sign up for a Petri Account

Comments (1)

One response to “Windows 10 Device Guard Versus AppLocker”

Leave a Reply

IT consultant, Contributing Editor @PetriFeed, and trainer @Pluralsight. All about Microsoft, Office 365, Azure, and Windows Server.
Live Webinar: Active Directory Security: What Needs Immediate Priority!Live on Tuesday, October 12th at 1 PM ET

Attacks on Active Directory are at an all-time high. Companies that are not taking heed are being punished, both monetarily and with loss of production.

In this webinar, you will learn:

  • How to prioritize vulnerability management
  • What attackers are leveraging to breach organizations
  • Where Active Directory security needs immediate attention
  • Overall strategy to secure your environment and keep it secured

Sponsored by: