Previously known as Windows Defender Application Control. On Windows it blocks any driver or app that its policy does not permit, and Microsoft suggests choosing it over AppLocker.
Also called formerly Windows Defender Application Control, WDAC, Windows Defender Application Control.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains App Control for Business in context, with comparison tables and the common traps.
Terms in this definition
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- AppLocker
Microsoft now steers customers to App Control for Business, since this legacy feature gets no new capabilities. It controls which executables, scripts, installers, DLLs and packaged apps may run through Group Policy rules.
Related terms
- Audit mode
Lets exploit protection or App Control for Business policies be trialled before enforcement: blocked actions are allowed but logged.
- Managed installer
Software deployed through a nominated distribution tool, Intune or Configuration Manager for instance, is trusted automatically under this App Control for Business feature, tracked via an AppLocker rule collection. Earlier installs are not tagged retrospectively.
- Multiple policy format
Lets several base and supplemental App Control for Business policies be in force simultaneously, starting with Windows Server 2022 and Windows 10 1903. Delivery through Group Policy supports single-format policies only.
- Supplemental policy
Adds further allow rules on top of an App Control for Business base policy but can never take away anything the base policy permits.
- UMCI
User Mode Code Integrity: an App Control for Business setting that makes a policy cover user-mode apps and scripts, not just kernel drivers.