Windows Code Integrity and App Control
Windows Code Integrity and App Control
The Windows Code Integrity subsystem validates kernel-mode code and enforces
configured App Control for Business policies. User-mode enforcement depends on
the active policy and options; Windows does not universally require every
user-mode executable to be signed.
Key Functions of the Windows Code Integrity Engine
- Enforces App Control policies
- It verifies that applications, scripts, and drivers comply with App Control for Business policies, formerly called Windows Defender Application Control (WDAC).
- It blocks unsigned or untrusted code from running if it violates security policies.
- Note: AppLocker is enforced by a separate subsystem (AppIDSvc / AppID.sys) and is not managed by the Code Integrity engine (ci.dll).
- Validates Digital Signatures
- It checks whether an application or driver is signed by a trusted certificate (e.g., Microsoft Code Signing PCA 2011).
- If an application lacks a valid signature and is restricted by WDAC, CI blocks its execution.
- Monitors and Protects the Kernel
- In kernel mode, it ensures that only digitally signed drivers are loaded, preventing rootkits and unauthorized kernel modifications.
- In user mode, it enforces configured User Mode Code Integrity policy; this is not a universal default allowlist.
- Supports Virtualization-Based Security (VBS)
- It integrates with Credential Guard and Hypervisor-Protected Code Integrity (HVCI) to enhance security in virtualized environments.
- VBS isolates sensitive security processes, making them tamper-resistant.
- Works with Other Windows Security Features
- App Control for Business relies on CI to enforce application-control policies.
- Exploit protection provides complementary mitigations such as DEP, ASLR, and CFG independently of App Control policy.
How Windows Code Integrity Works with WDAC
When you deploy App Control for Business, the Code Integrity engine enforces the compiled policy. The process follows this workflow:
flowchart TD A[XML Policy Definition] -->|Compile| B[Binary Policy ,.p7b signed/.bin unsigned] B -->|Load at Boot| C[Windows Code Integrity Engine] C -->|Enforces Policies| D[Allow or Block Execution] D -->|Logs Results| E[Event Viewer: CodeIntegrity Logs]
- Define Policies: Administrators create XML-based WDAC policies specifying allowed applications and drivers.
- Compile to Binary: The XML policy is compiled into a binary file (e.g.,
.p7bfor signed policies,.binfor unsigned policies). - Load During Boot: The compiled policy is loaded into the Windows Code Integrity engine.
- Enforce Policies: CI checks every executable and driver before allowing execution.
- Log Results: If a process violates the policy, CI logs the event in Event Viewer → Code Integrity logs.
Where is the Windows Code Integrity Engine Located?
- Executable Component:
- Integrated into the Windows Kernel as part of
CI.dll(Code Integrity DLL). - Can be found at:
- Integrated into the Windows Kernel as part of
C:\Windows\System32\ci.dll
- Policy Files Stored In:
- Compiled policies are typically located in:
C:\Windows\System32\CodeIntegrity\
- This folder contains policy files such as SiPolicy.p7b, which represents the active WDAC policy.
How to Check if Windows Code Integrity is Active
You can check if Code Integrity is running using the following methods:
- List deployed policies on supported current systems
CiTool.exe --list-policies -json
Inspect each policy's enforcement state. CiTool is included beginning with
Windows 11 version 22H2 and Windows Server 2025.
2. Checking Event Viewer Logs
- Open Event Viewer → Applications and Services Logs → Microsoft → Windows → CodeIntegrity.
- Look for events indicating that WDAC policies are being enforced.
3. Checking if Kernel-Mode Code Integrity is Enabled
SystemInfo | Findstr /C:"Hypervisor enforced Code Integrity"
- If enabled, it will show "Hypervisor enforced Code Integrity: Yes".
Conclusion
The Code Integrity subsystem enforces kernel signing requirements and configured
App Control policies. Its effective posture depends on the active policy set,
policy options, audit or enforcement mode, memory integrity, and Windows build.
References: App Control for Business and CiTool technical reference.