Removing WDAC Components from Endpoint

Use this task to remove all the associated files and folders related to Windows Defender Application Control (WDAC) from an endpoint.

About this task

The task performs the following actions:
  • Mounts the EFI system partition to access the boot-level WDAC policies.
  • Removes the AllowAll base policy from the endpoint (EFI).
  • Uninstalls the SDK, including SignTool.exe.
  • Deletes the BAC folder from the endpoint.
  • Logs all operations (success, warning, failure) to the BAC\Logs\WDAC_Cleanup.log file.
Refer to the table below to know more about the task's exit code.
Table 1. Exit Codes Table
Exit Code Meaning
0 Success
30 EFI mount failure
40 Policy removal failure
50 WDAC_AllowAll.xml file not found.
60 Refresh failure
70 SDK un-installation failure
Figure 1. Task: Remove WDAC Components from Endpoint

Remove WDAC Components from Endpoint v2.0

Procedure

  1. In the BigFix Console, navigate to All Content > BigFix Application Control > Fixlets and Tasks.
  2. From the Fixlets and Tasks pane, select Task: Remove WDAC Components from Endpoint v2.0.
  3. From the Task: Remove WDAC Components from Endpoint v2.0 pane, click the Applicable Computers(n) tab and view the endpoints on which you want to run the task.
  4. Select the Take Actions tab and select the endpoints on which you want to apply this installer task.
  5. Click OK.

Results

A successful execution of this task results in the following outcomes:
  • Removes all the associated Application Control files and folders from the endpoint.
  • A system reboot is required for the changes to take effect.