A community where customers and the community can provide feedback to make a better product for everyone! For more details on how we prioritize requests, please see:
Create WDAC policy from "Right-Click Options" Menu
The PMPC Publisher downloads apps before packaging them for Intune.
The New-CIPolicy cmdlet can read the Publisher cert and export a small WDAC policy in .xml format.
Customers can then use the WDAC Wizard to merge this policy with their existing WDAC Base or Supplemental policy.
Guest
Sep 30, 2026
We would like to add to this comment that it would be great to be able to publish a "cumulative" WDAC supplement policy for all products being published by PmP with some options for file versions or other basic detection logic. WDAC Managed Installer is a decent balance today of flexibility vs security but it would be better to be able to specifically target applications via traditional AppLocker style enforcement.
With some basic file version detection, we would use this for policy enforcement. Ie., all applications must be updated x days after the new version is pushed; older versions will be blocked from running due to the updated WDAC supplement. It could be setup to publish pointing at update rings following the Windows Update rollout schedule.
We would like to add to this comment that it would be great to be able to publish a "cumulative" WDAC supplement policy for all products being published by PmP with some options for file versions or other basic detection logic. WDAC Managed Installer is a decent balance today of flexibility vs security but it would be better to be able to specifically target applications via traditional AppLocker style enforcement.
With some basic file version detection, we would use this for policy enforcement. Ie., all applications must be updated x days after the new version is pushed; older versions will be blocked from running due to the updated WDAC supplement. It could be setup to publish pointing at update rings following the Windows Update rollout schedule.