Customers running Active Roles in environments with Windows Defender Application Control enabled may see execution-related issues if WDAC/Code Integrity blocks required runtime components.
Active Roles may start successfully and connect to Active Directory, but workflows, policies, scripts, or automation tasks may fail if components such as .NET, PowerShell, or dynamic compilation tools are restricted.
An enhancement request (711832) has been created detailing the feature above.
Active Roles relies on Microsoft .NET, PowerShell, and dynamic runtime execution for several product functions. If WDAC blocks these components, Active Roles functionality can be impacted even though the service itself appears healthy.
An enhancement/documentation request has been created for Development to publish official vendor guidance for Active Roles under WDAC enforcement, including:
STATUS
The product team will evaluate the request, and this feature may become available on a future release of the product.
Please refer to this article for updates or contact support referencing the Enhancement Request ID: 711832.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center