How does a Windows client trust a WDAC signing certificate without explicitly installing the .cer in Trusted Publishers?

shabir magray 0 Reputation points
2026-01-19T18:57:31.0366667+00:00

Hi Team,

I am trying to understand the trust mechanism behind Windows Defender Application Control (WDAC) with respect to code-signing certificates.

Scenario:

I have a .cer certificate (not explicitly installed on the endpoint).

I created a WDAC policy using this certificate as a Signer rule.

I deployed the WDAC policy to multiple client machines.

The policy is working as expected — applications signed with this certificate are allowed.

However, the certificate is NOT manually placed in:

Trusted Root Certification Authorities

  Trusted Publishers

  
     Enterprise Trusted Publishers
```### **Question:**

How is the **client machine trusting this certificate** even though the certificate is not present in the trusted certificate stores on the endpoint?  
  
[Moved from Microsoft 365 and Office | Microsoft 365 Defender | For home | Windows]
Microsoft Security | Microsoft Defender | Other

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.