Microsoft начала тестирование Application Guard, уникальной «песочницы» браузера Edge
Если вам нужен безопасный браузер, то стоит взглянуть на последнюю версию Windows 10 Insider Preview. Она включает в себя Windows Defender Application Guard, «песочницу» для Microsoft Edge. Эта фича была анонсирована в сентябре прошлого года, но стала доступна для тестирования только сейчас. Она изолирует Edge на виртуальной машине, что не позволяет вредоносными программам повлиять на работу вашего ПК.
Как попробовать Application Guard?
Чтобы включить его, вам нужно открыть окно «Включение или отключение компонентов Windows», а затем установить флажок «Windows Defender Application Guard».Теперь, когда вы открываете Microsoft Edge и нажимаете на меню, вы увидите опцию «Новое окно Application Guard». Выберите её, и откроется новое специальное окно браузера.
Как устроена эта фича?
Она стала возможной благодаря технологии Virtualization Based Security (VBS), используемой в Windows 10. Виртуальный ПК, создаваемый Application Guard, будет изолировать Edge от хранилища, других приложений и ядра Windows 10. Другие браузеры также предлагают «песочницы», но Microsoft заявляет, что её технология уникальна, поскольку использует аппаратный контейнер, который делает невозможным проникновение вредоносных программ.

Application Guard изолирует непроверенные сайты на аппаратном уровне
Однако есть несколько минусов. Запуск Edge на виртуальной машине, скорее всего, замедлит его работу, и поскольку сеанс каждого браузера изолирован, то все данные и файлы cookie будут потеряны после закрытия. Кроме того, пока что он доступен только для корпоративных пользователей, потому что их потребности в безопасности намного выше обычных.
How to set up Microsoft Defender Application Guard on Windows 11
If you want to protect your computer from online attacks more, you should also use Application Guard, and here’s how on Windows 11.

On Windows 11, the «Microsoft Defender Application Guard» feature lets you browse untrusted websites securely using Microsoft Edge.
The feature creates a tiny virtual machine using the Hyper-V technology with enough components to run Microsoft Edge. Using this approach, you can use a version of the browser isolated from the main installation, which you can use to navigate to any website without the risk of hacker attacks or infecting the computer with malware. Furthermore, this feature makes the isolation container anonymous, which means that an attacker won’t be able to steal your device credentials.
The only caveat is that this feature is only available for Windows 11 Pro, Enterprise, and other variants, but it’s not an option for the Home edition.
In this Windows 11 guide, we will walk you through the steps to enable and use Application Guard on Microsoft Edge.
How to enable Defender Application Guard on Windows 11
To enable Application Guard on Windows 11, use these steps:
- Open Settings.
- Click on Apps.
- Click the Optional features page on the right side.
- Under the «Related settings» section, click the More Windows features setting.
- Check the Microsoft Defender Application Guard option.
- Click the OK button.
- Click the Restart now button.
Once you complete the steps, the feature will be available through the Microsoft Edge browser to load untrusted websites.
How to use Defender Application Guard on Windows 11
To use Microsoft Defender Application Guard feature to browse the web, use these steps:
- Open Microsoft Edge.
- Click the Settings and more (three-dotted) menu button in the top-right corner.
- Select the New Application Guard window option. Quick tip: You can also use the Ctrl + Shift + Q keyboard shortcut to open a Guard window.
- Continue with the Application Guard session to browse the untrusted website.
After you complete the steps, a new window will open with a shield icon next to the address bar, letting you know that you are using Application Guard.
Since you are using a virtualized and isolated session of Microsoft Edge, you won’t be able to sync your settings with your profile. However, your favorites will be available when using the feature.
Also, you will be able to download and view files, but only from a virtual machine hosting the browser session. You can’t transfer the files to the host computer.
Furthermore, all the settings and changes will be discarded when you restart your computer.
Windows 10 – All Things About Application Guard
While working on a Customers ‘requests on Windows Defender Application Guard related to Microsoft Endpoint Manager – Attack Surface Reduction Policies, I could not find an up-to-date and detailed document from internet search. I have ended up digging more on the topic and combining the WDAG information.
Today we would discuss about all things related to Windows Defender Application Guard included features, advantages, installation, configuration, testing and troubleshooting.
Application Guard features could be applied to both Edge browser and Office 365 applications.
- For Microsoft Edge, Application Guard helps to isolate enterprise-defined untrusted sites from trusted web sites, cloud resources, and internal networks defined by administrator’s configured list. Everything not on the lists is considered to be untrusted. If an employee goes to an untrusted site through either Microsoft Edge or Internet Explorer, then Microsoft Edge is kicked in and Edge opens the site in an isolated Hyper-V-enabled container.

- For Microsoft Office, Application Guard helps prevents untrusted Word, PowerPoint and Excel files from accessing trusted resources. Application Guard opens untrusted files in an isolated Hyper-V-enabled container. The isolated Hyper-V container is separate from the host operating system. This container isolation means that if the untrusted site or file turns out to be malicious, the host device is protected, and the attacker can’t get to your enterprise data.
Application Guard Prerequisite for Windows 10 systems:
- For Edge Browser
- 64 bit CPU with 4 cores
- CPU supported for virtualization, Intel VT-x or AMD-V
- 8GB of RAM or more.
- 5GB of HD free space for Edge
- Input/Output Memory Management Unit (IOMMU) is not required but strongly recommended.
- Windows 10 Ent version 1709 or higher, Windows 10 Pro version 1803 or higher, Windows 10 Pro Education version 1803 or higher, Windows 10 Edu version 1903 or higher.
- Office : Office Current Channel and Monthly Enterprise Channel, Build version 2011 16.0.13530.10000 or later
- Intune or any other 3rd party mobile device management (MDM) solutions are not supported with WDAG for Professional editions.
- CPU and RAM same as Application Guard for Edge Browser.
- 10GB of HD free space.
- Office : Office Current Channel and Monthly Enterprise Channel, Build version 2011 16.0.13530.10000 or later.
- Windows 10 Enterprise edition, Client Build version 2004 (20H1) build 19041 or later
- security update KB4571756
Application Guard Installation
Windows 10 Application Guard feature is turned off by default.
§ To enable Application Guard by using the Control Panel-features
> Open the Control Panel , click Programs, and then click Turn Windows features on or off .

> Restart device.
§ To enable Application Guard by using PowerShell
> Run Windows PowerShell as administrator .
> Restart the device.
§ To deploy Application Guard by using (Intune) Endpoint Manager
- Go to https://endpoint.microsoft.com and sign in.
- Choose Enpoint security > Attack surface reduction > + Create profile , and do the following:
- In the Platform list, select Windows 10 and later .
- In the Profile list, select App and browser isolation .
- Choose Create .
- Name and Description
- In the Select a category to configure settings section, choose Microsoft Defender Application Guard .
- In the Application Guard list, choose: “Enable for Edge” or “Enable for isolated Windows environment” or “Enable for Edge AND isolated Windows environment”

4. Choose your preferences for print options ,

5. Define Network boundaries: internal network IP ranges, Cloud Resources IP ranges or FQDNs, Network Domains, Proxy Server IP addresses and Neutral resources ( e.g Azure signin URLs)
- Internal network IP range example:

- Cloud Resources example:

- Network Domains example:

- Neutral resources example:


- Review and Save
- On the Include tab, in the Assign to list, choose an option.
- If you have any devices or users you want to exclude from this endpoint protection profile, specify those on the Exclude tab.
- Click Save , Create.
After the profile is created, and applied to Windows 10 mobile systems, users might have to restart their devices in order for protection to be in place.
§ To Enable Application Guard using GPO
Microsoft Defender Application Guard (Application Guard) works with Group Policy to help you manage the following settings:
- Network Isolation settings ,
Computer ConfigurationAdministrative TemplatesNetworkNetwork Isolation, wildcard “.” could be used

- Application Guard settings (clipboard copying, printing, non-enterprise web content in IE and Edge, Allowed persistent container, download file to OS Host, Allow Extension in Container, Allow Favorite sync, …)
Computer ConfigurationAdministrative TemplatesWindows ComponentsMicrosoft Defender Application Guard

After the profile is created, and applied to client systems, users might have to restart their devices in order for protection to be in place.
- Testing for Office application.
You could refer to techblog article named “Microsoft Defender Application Guard for Office” of John Barbe for information and testing steps.
- Testing for Edge Browser.
You could test application guard on Standard mode for home users or Enterprise mode for domain users. We are focusing on Enterprise mode testing:
- Start Microsoft Edge and type https://www.microsoft.com.
After you submit the URL, Application Guard determines the URL is trusted because it uses the domain you’ve marked as trusted and shows the site directly on the host PC instead of in Application Guard.

- In the same Microsoft Edge browser, type any URL that isn’t part of your trusted or neutral site lists.
After you submit the URL, Application Guard determines the URL is untrusted and redirects the request to the hardware-isolated environment.

- To reset (clean up) a container and clear persistent data inside the container:
- Open a command-line program and navigate to Windows/System32.
2. Type wdagtool.exe cleanup . The container environment is reset, retaining only the employee-generated data.
3. Type wdagtool.exe cleanup RESET_PERSISTENCE_LAYER . The container environment is reset, including discarding all employee-generated data.
- Starting Application Guard too quickly after restarting the device might cause it to take a bit longer to load. However, subsequent starts should occur without any perceivable delays.
- Make sure to enable “Allow auditing events” for Application Guard if you want to collect Event Viewer log and report log to Microsoft Defender for Endpoint
- Configure network proxy (IP-Literal Addresses) for Application Guard:
Application Guard requires proxies to have a symbolic name, not just an IP address. IP-Literal proxy settings such as 192.168.1.4:81 can be annotated as itproxy:81 or using a record such as P19216810010 for a proxy with an IP address of 192.168.100.10. This applies to Windows 10 Enterprise edition, version 1709 or higher. These would be for the proxy policies under Network Isolation in Group Policy or Intune.
Application Guard Extension for third-party web browsers
The Application Guard Extension available for Chrome and Firefox allows Application Guard to protect users even when they are running a web browser other than Microsoft Edge or Internet Explorer.
Once a user has the extension and its companion app installed on their enterprise device, you can run through the following scenarios.
- Open either Firefox or Chrome — whichever browser you have the extension installed on.
- Navigate to an enterprise website, i.e. an internal website maintained by your organization. You might see this evaluation page for an instant before the site is full loaded.

- Navigate to a non-enterprise, external website site, such as www.bing.com. The site should be redirected to Microsoft Defender Application Guard Edge.
Troubleshooting Windows Defender Application Guard
The Application Guard known issues are listed in the following table:
Root Cause and Solution
An encryption driver prevents a VHD from being mounted or from being written to, Application Guard does not work because of disk mount failure.
Application Guard might not work correctly on NTFS compressed volumes. If this issue persists, try uncompressing the volume.
ERR_NAME_NOT_RESOLVED
Firewall blocks DHCP UDP communication
You need to create 2 Firewall rules for DHCP Server and Clients, detail is here
Can not launch Application Guard when Exploit Guard is enabled
if you change the Exploit Protection settings for CFG (Control Flow Guard) and possibly others, hvsimgr cannot launch. To mitigate this issue,
> go to Windows Security
> App and Browser control
> Exploit Protection Setting, and then switch CFG to use default.
Application Guard Container could not load due to Device Control Policy for USB disk
Allow installation of devices that match any of the following device IDs:
Demystifying Windows Defender Application Guard
Windows Defender Application Guard (Application Guard) was introduced with Windows 10 build 1709 and is designed to protect from current and future attacks against internet exposed applications such as Edge or Office applications. WDAG leverages Microsoft virtualization and hardware isolation technology, in fact Hyper-V containers to isolate applications from the operating system. Hyper-V containers seem to be an ideal solution for this as the have a more secure virtualization abstraction layer than classic container.

For more information on Hyper-V containers see here:
Windows Defender Application Guard in Depth
Disclaimer: The following details have been discovered by myself and may not be 100% accurate, based on process tracking and reverse engineering my assumptions could be wrong. However, this is what I’ve found out so far.
WDAG is an optional component to install / activate on Windows 10 Enterprise and Professional. To enable the feature (which requires a reboot):
After reboot you’ll notify that your available user memory has significantly decreased, which is because of a new hidden Hyper-V container instance beeing spun up behind the scenes. As soon as new application guard windows are started the memory footprint of the corresponding vmmem.exe process will increase significantly. I’ve observed up to 1.3GB working set with just a few web pages opened. Vmmem reflects the memory used inside a virtual machine or in this case here, the Hyper-V Container.
You won’t find this container instance using regular management tools such as docker client, because it is hidden from the management layer. However as any other windows container it is managed by the “Container Manager Service”. Protected applications (currently Edge exclusively) are started within this container while they are seamlessly presented on the host operating system using a tiny version of the RDP client. So very simplified, think of a remote app, launched in a container, presented to the host OS via RDP.

Depending on the mode (standalone or enterprise), Browser Broker get’s called manually or automatically based on the entered URL / address. Windows Defender Guard Manager talks to the Container Manager Service which initiates the launch of a new Edge Browser instance inside the pre-launched container. A special RDP Client (HvsiRdpClient) displays content and allows KVM interaction to the edge app running inside the Hyper-V Container.
Standalone vs. Enterprise Mode
There are two working modes for WDAG. The difference is quite simple. The enterprise mode automatically detects safe versus unsafe URLs, based on group policy settings and launches the url within a guarded Edge process inside the WDAG container. In contrary, with standalone mode, the user has to explicitly launch a new guarded window/tab. Enterprise mode requires Windows 10 Enterprise SKU.

How to configure Windows Defender Application Guard
Configuration of WDAG settings can be done via GPO (requires enterprise SKU) or via settings application.

Summary
Windows Defender Application Guard protects the operating system from malicious software as it runs the application inside a Hyper-V Container. Using this technology you can now safely speak of a real “sand boxed Browser”. Enterprise organisations can keep a high level of security and control, while still allowing users to access non-trusted websites through the isolated environment enriching the overall user experience. Although there is some interaction between the host OS and the app running inside the container, it’s very secure by default, as no file, process, registry or RPC access is allowed with the “mother” OS. Files can be printed out if configured by the admin, but not saved outside the container environment. Copy and paste (RDP Clip only) can also be enabled as well as keeping settings and cookies for the containerized browser. Very nice move, we’ll see what other types of applications will leverage this technology in the future.