-
Notifications
You must be signed in to change notification settings - Fork 8k
Add support for new WDAC API #17247
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add support for new WDAC API #17247
Conversation
|
This pull request has been automatically marked as Review Needed because it has been there has not been any activity for 7 days. |
|
Ping - @anamnavi, @TravisEz13, @daxian-dbw |
|
Sorry for the delay. Will do the review next Monday 😄 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, with a minor comment.
src/System.Management.Automation/resources/SecuritySupportStrings.resx
Outdated
Show resolved
Hide resolved
…ngs.resx Co-authored-by: Dongbo Wang <dongbow@microsoft.com>
|
This PR has Quantification details
Why proper sizing of changes matters
Optimal pull request sizes drive a better predictable PR flow as they strike a
What can I do to optimize my changes
How to interpret the change counts in git diff output
Was this comment helpful? 👍 :ok_hand: :thumbsdown: (Email) |
|
🎉 Handy links: |
|
There was a breaking change in Windows 11 22H2 related to this feature which defaults CI script policy to block. We should not backport this to 7.2 until we verify that this issue has been resolved. |
PR Summary
Implement new WDAC policy script file block option.
PR Context
WDAC API now supports the ability to allow/block PowerShell script files, whereas before the option was only to allow full/constrained language modes. This PR implements the new API with fallback to original system lock down behavior.
PR Checklist
.h,.cpp,.cs,.ps1and.psm1files have the correct copyright headerWIP:or[ WIP ]to the beginning of the title (theWIPbot will keep its status check atPendingwhile the prefix is present) and remove the prefix when the PR is ready.(which runs in a different PS Host).