Device Guard: using catalog files


hello!

the following article says must create temporary policy before creating catalog file:

https://technet.microsoft.com/itpro/windows/keep-secure/getting-apps-to-run-on-device-guard-protected-devices

the final step in article copy catalog file windows folder:

q1: should result of such copying - in other words how catalog file alone can increase security (as remember ci policy running in audit mode)?

 

this article says:

https://technet.microsoft.com/en-us/itpro/windows/manage/add-unsigned-app-to-code-integrity-policy

q2: don't understand how policies need when creating catalog files: article above says 1) "code integrity policy", 2) "create catalog files" - means creating second temporary code integrity policy 3) "default policy" , 4) "existing ci policies" - how of these policies relates each other?

q2-1: why can't create catalog file using code integrity policy (already created , running in audit mode)?

zhttps://technet.microsoft.com/en-us/itpro/windows/keep-secure/creating-a-device-guard-policy-for-signed-apps?f=255&mspperror=-2147217396


q3: doesn't hash keyword means can add unsigned apps code integrity policies without catalog files?

this webinar (in russian, ~at 25:40) - https://channel9.msdn.com/series/windows-10-device-protection-with-device-guard/01 - explains following command:

new-cipolicy -level pcacertificate -filepath $initialcipolicy -userpes -fallback hash

...will add policy both signed (by pcacertificate rule) , unsigned (hash rule) applications.

in case why need catalog files?

thank in advance,

michael



hi mf47,

as known windows server tp has not been released, suggest upgrade version latest see if helps or waiting official released version.

please check if following link helpful:

https://social.technet.microsoft.com/forums/windowsserver/en-us/ad73a0c3-28ce-4e6a-9e61-ce6476a151cd/device-guard?forum=win10itprogeneral

besides, seems issue more related win10, better help, suggest post on forum below:

https://social.technet.microsoft.com/forums/en-us/home?category=winpreview2014

best regards,


andy_pan



Windows Server  >  Windows Server Technical Preview



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...