The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Read effective AppLocker policy | Get-AppLockerPolicy -Effective -Xml | View examples |
| Read Code Integrity events | Get-WinEvent -LogName `
'Microsoft-Windows-CodeIntegrity/Operational' `
-MaxEvents 100 | View examples |
| Collect file identities | Get-AppLockerFileInformation -Directory `
'C:\Program Files\Contoso' -Recurse | View examples |
| Generate audit policy XML | Get-AppLockerFileInformation -EventLog -EventType Audited |
New-AppLockerPolicy -RuleType Publisher,Hash -User Everyone -Xml | View examples |
| Test files against policy | Test-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -Path `
'C:\Apps\*' -User 'CONTOSO\PilotUser' | View examples |
| Preview local AppLocker policy | Set-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIf | View examples |
| Inspect Application Identity | Get-Service AppIDSvc | View examples |
| Read AppLocker EXE events | Get-WinEvent -LogName `
'Microsoft-Windows-AppLocker/EXE and DLL' -MaxEvents `
100 | View examples |
| Create candidate base policy | New-CIPolicy -ScanPath 'C:\Windows' -Level Publisher `
-Fallback Hash -FilePath '.\Base.xml' -UserPEs | View examples |
| Keep audit mode enabled | Set-RuleOption -FilePath '.\Base.xml' -Option 3 | View examples |
| Merge policy XML | Merge-CIPolicy -PolicyPaths `
'.\Base.xml','.\AuditAdditions.xml' -OutputFilePath `
'.\Merged.xml' | View examples |
| Compile policy binary | ConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' `
-BinaryFilePath '.\Merged.cip' | View examples |
| List active App Control policies | CiTool.exe -lp -json | View examples |
| Hash policy artifact | Get-FileHash '.\Merged.cip' -Algorithm SHA256 | View examples |
| Summarize CI event IDs | Get-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500 |
Group-Object Id | View examples |
| Inspect PowerShell language mode | $ExecutionContext.SessionState.LanguageMode | View examples |
Application control changes Windows from allow-by-default to an explicit trust policy. App Control for Business, historically called Windows Defender Application Control or WDAC, is the preferred system-wide control; AppLocker remains available for complementary and legacy scenarios. A flawed policy can block administration, applications, drivers, or boot. Inventory broadly, build trust rules resistant to writable-path abuse, deploy in audit mode, analyze events through business cycles, canary enforcement, and maintain signed recovery procedures.
Step by step
Detailed examples
Choose App Control first and AppLocker deliberately
App Control for Business enforces kernel and user-mode trust at the system level and is Microsoft's preferred application control. AppLocker can apply rule collections by user or group and is useful for complementary scenarios, but its PowerShell cmdlets operate on Group Policy/local policy and not the AppLocker CSP. Feature availability varies by Windows release and edition. Application control complements rather than replaces antivirus, patching, privilege reduction, browser controls, and exploit protection.
Get-AppLockerPolicy -Effective -Xml | Set-Content -LiteralPath '.\effective-applocker.xml'
CiTool.exe -lp -json
Get-WinEvent -ListLog 'Microsoft-Windows-CodeIntegrity/Operational','Microsoft-Windows-AppLocker/*' |
Select-Object LogName, IsEnabled, RecordCount Inventory across business cycles and prefer durable trust
Collect binaries, scripts, installers, packaged apps, DLLs where enabled, drivers, plug-ins, updaters, deployment tools, accessibility utilities, and break-glass tooling. Publisher rules survive updates better than hashes but trust every file covered by the signer and product constraints. Path rules are unsafe when standard users can write to the path. Hash rules are precise but require updates. Event-derived rules reproduce what ran, including potentially unwanted software, so review origin and business owner.
Get-AppLockerFileInformation -Directory 'C:\Program Files\Contoso' -Recurse |
Select-Object Path, Publisher, Hash | Export-Csv '.\contoso-file-inventory.csv' -NoTypeInformation
Get-Acl 'C:\Program Files\Contoso' | Format-List
Get-AuthenticodeSignature 'C:\Program Files\Contoso\app.exe' |
Select-Object Status, StatusMessage, SignerCertificate Test effective AppLocker decisions as representative users
Test-AppLockerPolicy evaluates files against XML or effective policy for a specified user, but it does not execute the application or model every child process, DLL, script host, installer, or runtime download. Test representative users and administrative tooling. Default rules are starting points, not a complete allowlist. Audit all enabled collections before enforcement and verify Application Identity service policy. Group Policy can override local configuration.
$Results = Test-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' `
-Path 'C:\Apps\*' -User 'CONTOSO\PilotUser'
$Results | Group-Object PolicyDecision | Select-Object Name, Count
$Results | Where-Object PolicyDecision -ne Allowed |
Select-Object Path, PolicyDecision, MatchingRule Deploy AppLocker through controlled policy management
Set-AppLockerPolicy changes local policy when Ldap is omitted, or a specified GPO when it is supplied; Merge combines rules while preserving the target GPO's enforcement setting, and omission replaces it. WhatIf resolves the target but cannot predict Group Policy refresh, workflow, or every dependency. Back up previous XML and GPO, audit first, then enforce in phases. AppLocker enforcement depends on Application Identity. Maintain console and recovery access.
Get-AppLockerPolicy -Local -Xml | Set-Content '.\applocker-before.xml'
Get-FileHash '.\applocker-before.xml' -Algorithm SHA256
Set-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIf
Get-Service AppIDSvc | Select-Object Status, StartType Author App Control in audit mode with policy semantics in view
App Control policy options control audit, user-mode code integrity, script enforcement, dynamic code security, supplemental policies, update signing, and other behaviors. Microsoft recommends beginning with Enabled:Audit Mode, option 3; removing it enforces. A deny-only policy requires Allow All rules so unspecified code is not unintentionally blocked. Build from Microsoft templates or Wizard guidance, then add narrowly scoped line-of-business trust. ConfigCI authoring is best run in Windows PowerShell 5.1 on a clean reference system; its mutating XML cmdlets do not provide a deployment WhatIf simulation.
# Run scanning only on a clean, representative reference image.
# New-CIPolicy -ScanPath 'C:\Windows' -Level Publisher -Fallback Hash `
# -FilePath '.\Base.xml' -UserPEs
Set-RuleOption -FilePath '.\Base.xml' -Option 3
Get-FileHash '.\Base.xml' -Algorithm SHA256 Canary compiled policies before broad activation
ConvertFrom-CIPolicy compiles XML but does not deploy it. Deployment method and refresh/restart requirements vary by Windows version, MDM, Group Policy, Configuration Manager, OSConfig, or signed-policy workflow. Server 2025 OSConfig offers its own default policies and prerequisites. Never copy an enforce-mode policy broadly without recovery media and a removal procedure. A policy can affect drivers and early boot, and signed policies are intentionally harder to remove.
ConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' -BinaryFilePath '.\Merged.cip'
Get-Item '.\Merged.xml','.\Merged.cip' | Select-Object Name, Length, LastWriteTimeUtc
Get-FileHash '.\Merged.xml','.\Merged.cip' -Algorithm SHA256
CiTool.exe -lp -json Version policy identity and recovery together
Assign stable policy IDs, semantic versions, owners, ticket references, hashes, and signing certificates. Signing protects policy updates but a lost signing key can make recovery difficult. Secure signing keys in an HSM or controlled service, monitor certificate validity, and test authorized update and removal procedures. Keep known-good boot or recovery media and offline copies of policies. Do not assume Safe Mode, local administrator, or PowerShell will bypass a malformed enforced policy.
$Artifacts = '.\Merged.xml','.\Merged.cip'
$Artifacts | ForEach-Object {
$Hash = Get-FileHash $_ -Algorithm SHA256
[pscustomobject]@{ Path=$Hash.Path; SHA256=$Hash.Hash; Size=(Get-Item $_).Length }
} | Export-Csv '.\policy-manifest.csv' -NoTypeInformation Monitor audit and enforcement as an ongoing control
Code Integrity event 3076 commonly records audit-mode would-block decisions and 3077 enforced blocks, but use current event documentation and related correlated events rather than a single ID. AppLocker has separate EXE/DLL, MSI/Script, packaged-app, and deployment logs. App Control enforcement can place PowerShell into ConstrainedLanguage; do not disable script enforcement casually because it weakens protection. Tune through reviewed supplemental policies and regression tests, never by broad writable-path exceptions.
$Ci = Get-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500
$Ci | Group-Object Id | Sort-Object Count -Descending | Select-Object Name, Count
$ExecutionContext.SessionState.LanguageMode
Get-WinEvent -LogName 'Microsoft-Windows-AppLocker/MSI and Script' -MaxEvents 100 |
Group-Object Id | Select-Object Name, Count Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Microsoft LearnApplication Control for Windowslearn.microsoft.com
- Microsoft LearnUnderstand App Control policy rules and file ruleslearn.microsoft.com
- Microsoft LearnAppLocker overviewlearn.microsoft.com
- Microsoft LearnAppLocker PowerShell modulelearn.microsoft.com
- Microsoft LearnHow App Control works with PowerShelllearn.microsoft.com
- Microsoft LearnConfigure App Control in Windows Serverlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



