The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Read effective AppLocker policyGet-AppLockerPolicy -Effective -XmlView examples
Read Code Integrity eventsGet-WinEvent -LogName ` 'Microsoft-Windows-CodeIntegrity/Operational' ` -MaxEvents 100View examples
Collect file identitiesGet-AppLockerFileInformation -Directory ` 'C:\Program Files\Contoso' -RecurseView examples
Generate audit policy XMLGet-AppLockerFileInformation -EventLog -EventType Audited | New-AppLockerPolicy -RuleType Publisher,Hash -User Everyone -XmlView examples
Test files against policyTest-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -Path ` 'C:\Apps\*' -User 'CONTOSO\PilotUser'View examples
Preview local AppLocker policySet-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIfView examples
Inspect Application IdentityGet-Service AppIDSvcView examples
Read AppLocker EXE eventsGet-WinEvent -LogName ` 'Microsoft-Windows-AppLocker/EXE and DLL' -MaxEvents ` 100View examples
Create candidate base policyNew-CIPolicy -ScanPath 'C:\Windows' -Level Publisher ` -Fallback Hash -FilePath '.\Base.xml' -UserPEsView examples
Keep audit mode enabledSet-RuleOption -FilePath '.\Base.xml' -Option 3View examples
Merge policy XMLMerge-CIPolicy -PolicyPaths ` '.\Base.xml','.\AuditAdditions.xml' -OutputFilePath ` '.\Merged.xml'View examples
Compile policy binaryConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' ` -BinaryFilePath '.\Merged.cip'View examples
List active App Control policiesCiTool.exe -lp -jsonView examples
Hash policy artifactGet-FileHash '.\Merged.cip' -Algorithm SHA256View examples
Summarize CI event IDsGet-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500 | Group-Object IdView examples
Inspect PowerShell language mode$ExecutionContext.SessionState.LanguageModeView examples

Application control changes Windows from allow-by-default to an explicit trust policy. App Control for Business, historically called Windows Defender Application Control or WDAC, is the preferred system-wide control; AppLocker remains available for complementary and legacy scenarios. A flawed policy can block administration, applications, drivers, or boot. Inventory broadly, build trust rules resistant to writable-path abuse, deploy in audit mode, analyze events through business cycles, canary enforcement, and maintain signed recovery procedures.

Step by step

Detailed examples

01

Choose App Control first and AppLocker deliberately

App Control for Business enforces kernel and user-mode trust at the system level and is Microsoft's preferred application control. AppLocker can apply rule collections by user or group and is useful for complementary scenarios, but its PowerShell cmdlets operate on Group Policy/local policy and not the AppLocker CSP. Feature availability varies by Windows release and edition. Application control complements rather than replaces antivirus, patching, privilege reduction, browser controls, and exploit protection.

Inventory existing controls and event channels
Get-AppLockerPolicy -Effective -Xml | Set-Content -LiteralPath '.\effective-applocker.xml'
CiTool.exe -lp -json
Get-WinEvent -ListLog 'Microsoft-Windows-CodeIntegrity/Operational','Microsoft-Windows-AppLocker/*' |
    Select-Object LogName, IsEnabled, RecordCount
Back to quick reference ↑
02

Inventory across business cycles and prefer durable trust

Collect binaries, scripts, installers, packaged apps, DLLs where enabled, drivers, plug-ins, updaters, deployment tools, accessibility utilities, and break-glass tooling. Publisher rules survive updates better than hashes but trust every file covered by the signer and product constraints. Path rules are unsafe when standard users can write to the path. Hash rules are precise but require updates. Event-derived rules reproduce what ran, including potentially unwanted software, so review origin and business owner.

Create an offline inventory artifact
Get-AppLockerFileInformation -Directory 'C:\Program Files\Contoso' -Recurse |
    Select-Object Path, Publisher, Hash | Export-Csv '.\contoso-file-inventory.csv' -NoTypeInformation
Get-Acl 'C:\Program Files\Contoso' | Format-List
Get-AuthenticodeSignature 'C:\Program Files\Contoso\app.exe' |
    Select-Object Status, StatusMessage, SignerCertificate
Back to quick reference ↑
03

Test effective AppLocker decisions as representative users

Test-AppLockerPolicy evaluates files against XML or effective policy for a specified user, but it does not execute the application or model every child process, DLL, script host, installer, or runtime download. Test representative users and administrative tooling. Default rules are starting points, not a complete allowlist. Audit all enabled collections before enforcement and verify Application Identity service policy. Group Policy can override local configuration.

Compare candidate outcomes for a pilot identity
$Results = Test-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' `
    -Path 'C:\Apps\*' -User 'CONTOSO\PilotUser'
$Results | Group-Object PolicyDecision | Select-Object Name, Count
$Results | Where-Object PolicyDecision -ne Allowed |
    Select-Object Path, PolicyDecision, MatchingRule
Back to quick reference ↑
04

Deploy AppLocker through controlled policy management

Set-AppLockerPolicy changes local policy when Ldap is omitted, or a specified GPO when it is supplied; Merge combines rules while preserving the target GPO's enforcement setting, and omission replaces it. WhatIf resolves the target but cannot predict Group Policy refresh, workflow, or every dependency. Back up previous XML and GPO, audit first, then enforce in phases. AppLocker enforcement depends on Application Identity. Maintain console and recovery access.

Back up and preview a local-policy change
Get-AppLockerPolicy -Local -Xml | Set-Content '.\applocker-before.xml'
Get-FileHash '.\applocker-before.xml' -Algorithm SHA256
Set-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIf
Get-Service AppIDSvc | Select-Object Status, StartType
Back to quick reference ↑
05

Author App Control in audit mode with policy semantics in view

App Control policy options control audit, user-mode code integrity, script enforcement, dynamic code security, supplemental policies, update signing, and other behaviors. Microsoft recommends beginning with Enabled:Audit Mode, option 3; removing it enforces. A deny-only policy requires Allow All rules so unspecified code is not unintentionally blocked. Build from Microsoft templates or Wizard guidance, then add narrowly scoped line-of-business trust. ConfigCI authoring is best run in Windows PowerShell 5.1 on a clean reference system; its mutating XML cmdlets do not provide a deployment WhatIf simulation.

Build and retain audit mode in a candidate policy
# Run scanning only on a clean, representative reference image.
# New-CIPolicy -ScanPath 'C:\Windows' -Level Publisher -Fallback Hash `
#     -FilePath '.\Base.xml' -UserPEs
Set-RuleOption -FilePath '.\Base.xml' -Option 3
Get-FileHash '.\Base.xml' -Algorithm SHA256
Back to quick reference ↑
06

Canary compiled policies before broad activation

ConvertFrom-CIPolicy compiles XML but does not deploy it. Deployment method and refresh/restart requirements vary by Windows version, MDM, Group Policy, Configuration Manager, OSConfig, or signed-policy workflow. Server 2025 OSConfig offers its own default policies and prerequisites. Never copy an enforce-mode policy broadly without recovery media and a removal procedure. A policy can affect drivers and early boot, and signed policies are intentionally harder to remove.

Compile and inspect without deploying
ConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' -BinaryFilePath '.\Merged.cip'
Get-Item '.\Merged.xml','.\Merged.cip' | Select-Object Name, Length, LastWriteTimeUtc
Get-FileHash '.\Merged.xml','.\Merged.cip' -Algorithm SHA256
CiTool.exe -lp -json
Back to quick reference ↑
07

Version policy identity and recovery together

Assign stable policy IDs, semantic versions, owners, ticket references, hashes, and signing certificates. Signing protects policy updates but a lost signing key can make recovery difficult. Secure signing keys in an HSM or controlled service, monitor certificate validity, and test authorized update and removal procedures. Keep known-good boot or recovery media and offline copies of policies. Do not assume Safe Mode, local administrator, or PowerShell will bypass a malformed enforced policy.

Create approval evidence for policy artifacts
$Artifacts = '.\Merged.xml','.\Merged.cip'
$Artifacts | ForEach-Object {
    $Hash = Get-FileHash $_ -Algorithm SHA256
    [pscustomobject]@{ Path=$Hash.Path; SHA256=$Hash.Hash; Size=(Get-Item $_).Length }
} | Export-Csv '.\policy-manifest.csv' -NoTypeInformation
Back to quick reference ↑
08

Monitor audit and enforcement as an ongoing control

Code Integrity event 3076 commonly records audit-mode would-block decisions and 3077 enforced blocks, but use current event documentation and related correlated events rather than a single ID. AppLocker has separate EXE/DLL, MSI/Script, packaged-app, and deployment logs. App Control enforcement can place PowerShell into ConstrainedLanguage; do not disable script enforcement casually because it weakens protection. Tune through reviewed supplemental policies and regression tests, never by broad writable-path exceptions.

Summarize recent decisions without changing policy
$Ci = Get-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500
$Ci | Group-Object Id | Sort-Object Count -Descending | Select-Object Name, Count
$ExecutionContext.SessionState.LanguageMode
Get-WinEvent -LogName 'Microsoft-Windows-AppLocker/MSI and Script' -MaxEvents 100 |
    Group-Object Id | Select-Object Name, Count
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnApplication Control for Windowslearn.microsoft.com
  2. Microsoft LearnUnderstand App Control policy rules and file ruleslearn.microsoft.com
  3. Microsoft LearnAppLocker overviewlearn.microsoft.com
  4. Microsoft LearnAppLocker PowerShell modulelearn.microsoft.com
  5. Microsoft LearnHow App Control works with PowerShelllearn.microsoft.com
  6. Microsoft LearnConfigure App Control in Windows Serverlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback