Skip to content

Audit Mode

Windows Defender Application Control (WDAC) audit mode enables administrators to monitor system behavior and policy compliance without enforcing restrictions. This mode is ideal for evaluating policy impacts, identifying potential conflicts, or validating rule sets before transitioning to enforcement. Configuration involves adjusting Group Policy or PowerShell settings to activate audit mode, followed by log analysis to verify compliance and detect unauthorized activity.


Enabling Audit Mode via Group Policy

  1. Open Group Policy Management Console (GPMC) and create/edit a Group Policy Object (GPO).
  2. Navigate to:
    Computer Configuration > Administrative Templates > Windows Components > Windows Defender Application Control
  3. Enable the policy "Configure audit mode" and set it to Enabled.
  4. Optional: Configure audit logging settings (e.g., log file location, retention) under "Audit logging settings".
  5. Link the GPO to the target OU and restart the system for changes to take effect.

Example command to verify audit mode status via PowerShell:

Get-ApplicationControlPolicy | Select-Object PolicyMode


Enabling Audit Mode via PowerShell

Use the Set-ApplicationControlPolicy cmdlet to configure audit mode:

Set-ApplicationControlPolicy -PolicyMode Audit

To verify the current mode:

Get-ApplicationControlPolicy | Select-Object PolicyMode

Note: Ensure the system is in a state where enforcement is disabled (e.g., no WDAC policies are active) before enabling audit mode.


Monitoring Audit Logs

Audit mode logs are stored in the Event Viewer under:
Windows Defender Application Control > Operational Log

Example command to query audit logs via PowerShell:

Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows Defender Application Control/Operational'; ID=10001} | Format-List

Review logs for entries indicating allowed or denied application attempts, policy violations, or rule mismatches.


Key takeaways

  • Audit mode allows policy evaluation without enforcing restrictions.
  • Configure audit mode via Group Policy or PowerShell by setting PolicyMode to Audit.
  • Monitor logs in Event Viewer or via PowerShell to assess compliance and identify risks.
  • Transition to enforcement mode only after validating policies in audit mode.
  • Always test policies in audit mode before applying them to production systems.