Table of Contents
Option A: Using Group Policy (Recommended for Organizations)
Option B: Using PowerShell (For IT Admins)
Option C: Using Windows Features (GUI)
Configure Edge Integration
Configure Office Integration
Monitoring
Common Issues & Fixes
Home System Tutorial Windows Series How to manage Windows Defender Application Guard

How to manage Windows Defender Application Guard

Jul 30, 2025 am 04:10 AM

Ensure your system meets the requirements: Windows 10/11 Enterprise or Education (64-bit), 6th-gen Intel Core or equivalent AMD with virtualization enabled, at least 8 GB RAM, Hyper-V available and enabled. 2. Enable WDAG via Group Policy (navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Application Guard and set to Enabled), PowerShell (run Enable-WindowsOptionalFeature with HypervisorPlatform and Windows-Defender-ApplicationGuard features), or Windows Features GUI (enable Windows Defender Application Guard and Virtual Machine Platform, then restart). 3. Configure WDAG for Microsoft Edge and Office apps using Group Policy to define trusted and untrusted sites and files, ensuring untrusted content opens in isolated containers while trusted content opens normally. 4. Monitor WDAG through Event Viewer under Microsoft > Windows > AppLocker and Hypervisor-Debug logs or via Microsoft Defender for Endpoint, and troubleshoot issues like "Application Guard not available" by verifying virtualization settings and Windows edition, address performance issues by ensuring sufficient RAM and excluding trusted sites, resolve Office file issues by checking file properties and policies, and manage Hyper-V conflicts by adjusting third-party virtualization software usage. 5. Follow best practices: integrate with Microsoft Defender for Endpoint, define clear trust policies, educate users about isolated windows, test deployment in a pilot group, and keep systems updated. Managing WDAG effectively enhances protection against web and document-based threats by isolating untrusted content in a lightweight virtual machine, provided prerequisites are met and configurations are correctly applied.

How to manage Windows Defender Application Guard

Windows Defender Application Guard (WDAG) is a security feature in Windows 10 and Windows 11 Enterprise and Education editions that helps protect your system by isolating untrusted websites and documents in a lightweight virtual machine. This prevents potentially malicious content from reaching your host operating system. Managing WDAG effectively involves enabling, configuring, monitoring, and troubleshooting it appropriately.

How to manage Windows Defender Application Guard

Here’s how to manage Windows Defender Application Guard:


1. Check System and Edition Requirements

Before managing WDAG, ensure your system meets the requirements:

How to manage Windows Defender Application Guard
  • Supported editions: Windows 10/11 Enterprise or Education (64-bit)
  • Processor: 6th generation Intel Core or later (or equivalent AMD with virtualization support)
  • Virtualization-based security (VBS): Must be supported and enabled in BIOS/UEFI
  • RAM: At least 8 GB recommended
  • Hyper-V: Must be available and enabled

? You can check your Windows edition by going to Settings > System > About.


2. Enable or Disable Application Guard

  1. Open the Group Policy Management Console (GPMC) or Local Group Policy Editor (gpedit.msc).

    How to manage Windows Defender Application Guard
  2. Navigate to:
    Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Application Guard

  3. Configure one or more of the following:

    • Turn on Microsoft Defender Application Guard: Set to Enabled
    • Allow WDAG on computers with unsupported processors: Only enable if necessary (not recommended)
    • Configure Windows Defender Application Guard for Office applications: Enable isolation for untrusted documents
  4. Apply and run gpupdate /force in Command Prompt to refresh policies.

Option B: Using PowerShell (For IT Admins)

To enable WDAG:

Enable-WindowsOptionalFeature -Online -FeatureName "HypervisorPlatform", "Windows-Defender-ApplicationGuard"

To disable:

Disable-WindowsOptionalFeature -Online -FeatureName "Windows-Defender-ApplicationGuard"

⚠️ You’ll need to restart the computer after enabling or disabling.

Option C: Using Windows Features (GUI)

  1. Open Control Panel > Programs > Turn Windows features on or off
  2. Check:
    • Windows Defender Application Guard
    • Virtual Machine Platform (and possibly Windows Hypervisor Platform)
  3. Click OK and restart.

3. Configure Application Guard for Browsers and Office

Once enabled, WDAG works primarily with:

  • Microsoft Edge (Chromium-based): Automatically uses Application Guard for untrusted sites if configured.
  • Microsoft Office apps (Word, Excel, PowerPoint): Can open untrusted documents in isolated containers.

Configure Edge Integration

  1. Use Group Policy:

    • Go to:
      Computer Configuration > Administrative Templates > Microsoft Edge > Application Guard
    • Set Enable Application Guard in Microsoft Edge to Enabled
    • Define Allow sites to load in the container or Block sites from loading in the container via URL lists
  2. Trusted sites will open normally; untrusted sites launch in a secure container.

Configure Office Integration

  1. In Group Policy, go to:
    Computer Configuration > Administrative Templates > Microsoft Office > Security > Application Guard
  2. Enable Control application guard in Office apps
  3. Define:
    • Files from the internet and email are opened in isolation
    • Files from trusted locations (e.g., internal network paths) open normally

4. Monitor and Troubleshoot WDAG

Monitoring

  • Check Event Viewer:
    Look under Applications and Services Logs > Microsoft > Windows > AppLocker and Hypervisor-Debug for WDAG-related events.
  • Use Microsoft Defender for Endpoint: Provides visibility into WDAG usage and security events.

Common Issues & Fixes

  • "Application Guard is not available on this machine"
    → Ensure virtualization is enabled in BIOS (Intel VT-x / AMD-V).
    → Confirm your Windows edition supports WDAG.

  • Performance slowdowns
    → WDAG uses system resources. Ensure sufficient RAM (16 GB ideal).
    → Exclude trusted internal sites from containerization.

  • Office files not opening in container
    → Verify policy settings and that files are marked as "from the internet" (check file properties).

  • Hyper-V conflicts with other virtualization software (e.g., VMware, Docker)
    → Some apps may not work when WDAG is enabled due to exclusive hypervisor access.


5. Best Practices for Managing WDAG

  • Use with Microsoft Defender for Endpoint for centralized monitoring.
  • Define clear trusted site and file policies to balance security and usability.
  • Educate users that some sites or files may open in a separate, isolated window.
  • Test in a pilot group before enterprise-wide deployment.
  • Keep Windows and drivers updated to avoid compatibility issues.

Managing Windows Defender Application Guard effectively enhances protection against web and document-based threats. While setup requires planning and compatible hardware, the isolation benefits are strong for high-risk environments.

Basically, it’s about enabling it correctly, defining what’s trusted, and keeping an eye on how it integrates with Edge and Office. Not overly complex—but easy to misconfigure if you skip the prerequisites.

The above is the detailed content of How to manage Windows Defender Application Guard. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undress AI Tool

Undress AI Tool

Undress images for free

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

PHP Tutorial
1517
276
How to fix 'DPC WATCHDOG VIOLATION' error? How to fix 'DPC WATCHDOG VIOLATION' error? Jul 20, 2025 am 12:05 AM

When encountering the "DPCWATCHDOGVIOLATION" blue screen error, 1. First update or roll back the driver, especially graphics card, network card and motherboard driver, you can use the device manager or manufacturer tools; 2. Disable or uninstall third-party antivirus software and use WindowsDefender instead; 3. Check the storage device and driver, update the SSD firmware or replace the AHCI driver; 4. Disable the CoreIsolation function to eliminate system settings conflicts, and in most cases, try these methods in order to solve the problem.

Best 123Movies Alternatives in 2025 (Free & Legal Streaming Options) Best 123Movies Alternatives in 2025 (Free & Legal Streaming Options) Jul 28, 2025 pm 12:02 PM

Read our disclosure page to find out how can you help MSPoweruser sustain the editorial team Read more123Movies used to be a go-to destination for free online movie streaming, but it came with serious downsides — from aggressive pop-up ads and potent

How to Change ChatGPT Personality in Settings (Cynic, Robot, Listener, Nerd) How to Change ChatGPT Personality in Settings (Cynic, Robot, Listener, Nerd) Aug 08, 2025 am 09:33 AM

Visit our disclosure page to learn how you can support MSPoweruser in maintaining the editorial team Read moreWant ChatGPT to reflect your mood or communication style? With the launch of ChatGPT 5, OpenAI introduces five distinct personalities – choo

How to Download and Use CapCut AI Video Editor on Windows PC [Full Guide] How to Download and Use CapCut AI Video Editor on Windows PC [Full Guide] Jul 25, 2025 am 02:48 AM

Read our disclosure page to learn how you can support the MSPoweruser editorial team. Read moreFor video creators, finding the right editing tool is crucial, and how to download, install, and use the CapCut AI video editor on Windows PC has become a

How to run Command Prompt as administrator? How to run Command Prompt as administrator? Jul 23, 2025 am 03:20 AM

To run CMD as an administrator, you can do it through three methods: Start menu, Win X menu, or Create Shortcuts. First, after searching for "cmd" in the start menu, right-click and select "Run as administrator"; secondly, press the Win X key and select "Command Prompt (Administrator); finally, create a new shortcut to cmd.exe, and set "Run as administrator" in the properties. If you encounter insufficient permissions, you need to check whether the account is an administrator group, group policy restrictions or contact the IT department. These three methods are applicable to different operating habits and scenarios, ensuring the safety of the system while meeting management needs.

How to customize Windows 11 power modes How to customize Windows 11 power modes Jul 19, 2025 am 01:37 AM

To customize Windows 11 power mode, first you can switch pre-design plans in the taskbar battery icon or control panel, such as "Balance", "High Performance" and "Power Saving"; secondly, click "Create Power Plan" to select the template and set the name, turn off the monitor and sleep time; then, adjust advanced options such as processor power management, hard disk sleep time and USB settings through "Change Plan Settings". Finally, advanced users can further optimize through the powercfg command or registry, such as viewing plans, modifying settings or exporting configurations. It is also recommended to adjust strategies according to the device type, such as notebooks distinguish between battery and power supply, desktops focus on performance settings, and tablets strengthen energy saving.

My Windows laptop display drivers keep crashing My Windows laptop display drivers keep crashing Jul 21, 2025 am 03:29 AM

Windows laptop display drivers frequently crash, usually caused by outdated or damaged drivers, software conflicts, overheating, or hardware problems. 1. First try to update or reinstall the graphics card driver through Device Manager, or download the latest version from the official website of the GPU manufacturer. 2. Check for overheating problems, use tools such as HWMonitor to monitor temperature, clean the vents, avoid using the notebook on soft surfaces, and check whether there are high GPU occupancy programs through the Task Manager. 3. Adjust the display settings, turn off hardware acceleration and visual effects, and temporarily change the resolution or refresh rate. 4. Check and install Windows updates, roll back the driver or system version if necessary, and check for possible conflicting software such as antivirus software, screen recording tools or overwrite applications. this

How to fix 'Critical Process Died' on Windows? How to fix 'Critical Process Died' on Windows? Jul 21, 2025 am 03:31 AM

Solutions to the "CriticalProcessDied" blue screen error include: 1. Check and uninstall the recently installed driver or software, enter safe mode test and perform a clean boot; 2. Run the sfc and DISM commands with administrator permissions to repair the system files; 3. Update Windows, use the system restore point, or reset this computer. These steps can check driver conflicts, system file corruption or other system problems in turn, and ultimately solve the blue screen phenomenon caused by critical process crashes.

See all articles