Skip to content

Deploy App Control Policy

Violet Hansen edited this page Feb 24, 2025 · 4 revisions

Deploy App Control Policy

AppControl Manager Application's Deploy App Control Policy Page


Use this AppControl Manager page to select XML policy files or .cip binary files to deploy on the local/cloud systems or convert XML files to CIP files for manual deployment.


Important

Intune Cloud Deployment

Please refer to this page for details on how to upload App Control Policies to Intune using AppControl Manager.


Configuration Details for Unsigned XML Policy Files Deployment

  • Browse: Use this button to browse for App Control XML policy files that you want to deploy as unsigned policies.

  • Deploy: Use this button to deploy all of the XML files you selected on the local or cloud system.


Configuration Details for Signed XML Policy Files Deployment

AppControl Manager Application's Content Dialog for Policy Signing details


  • Browse: Use this button to browse for App Control XML policy files that you want to Sign and deploy.

  • Deploy: Use this button to deploy all of the XML files you selected on the local or cloud system.

  • Sign Only - No Deployment: If you only want to sign the policy without deploying it, you can use this button. It will generate the signed CIP file for you that you can use to manually deploy somewhere else.


When signing and deploying App Control Policies, a dialog will be displayed asking for additional information required for signing the policy.

  • Certificate File: Provide the path to the certificate .cer file. It must be a code signing certificate that is either issued by a public certificate authority (CA) or a self-signed certificate. You can generate a self-signed certificate suitable for App Control policy signing in the certificate building page of the AppControl Manager. The certificate's details will be added to the XML policy as signers. The certificate must exist in the Personal store of the Current User certificate stores with private key.

  • Certificate Common Name: The Common Name (CN) of the same certificate file you select.

  • SignTool Path: The path to the SignTool.exe. If you don't have it, you can toggle the Auto Acquire switch. Auto Acquire will try to first find it on the system by checking for installed Windows SDK, if it cannot find it, it will download it from the official Microsoft server.

Once you've provided all 3 items, press the Verify button. It will verify your inputs and then the Submit button will be enabled, allowing you to proceed with policy signing and deployment.

All of the information you submit will be saved in app settings so that the next time they will be automatically populated for you.


Configuration Details for CIP Binary Files Deployment

This section can deploy .CIP binary files on the local or cloud system, whether they are signed or unsigned.

  • Browse: Use this button to browse for App Control CIP binary files that you want to deploy.

  • Deploy: Use this button to deploy all of the CIP files you selected on the local or cloud system.


Configuration Details for Converting XML to CIP Files

Use this section to convert all of your XML files to CIP binaries files in bulk.

  • Browse: Use this button to browse for App Control XML policy files that you want to convert to CIP binary files.

  • Convert: Use this button to convert all of the selected XML policy files to CIP binary files with the same file names.









C#


Clone this wiki locally