Additional Microsoft Defender tools and services that provide security across various platforms and environments
How does a Windows client trust a WDAC signing certificate without explicitly installing the .cer in Trusted Publishers?
shabir magray
0
Reputation points
Hi Team,
I am trying to understand the trust mechanism behind Windows Defender Application Control (WDAC) with respect to code-signing certificates.
Scenario:
I have a .cer certificate (not explicitly installed on the endpoint).
I created a WDAC policy using this certificate as a Signer rule.
I deployed the WDAC policy to multiple client machines.
The policy is working as expected — applications signed with this certificate are allowed.
However, the certificate is NOT manually placed in:
Trusted Root Certification Authorities
Trusted Publishers
Enterprise Trusted Publishers
```### **Question:**
How is the **client machine trusting this certificate** even though the certificate is not present in the trusted certificate stores on the endpoint?
[Moved from Microsoft 365 and Office | Microsoft 365 Defender | For home | Windows]
Microsoft Security | Microsoft Defender | Other
Microsoft Security | Microsoft Defender | Other
Sign in to answer