Our VSTO add-in is blocked at startup by Windows Defender attack surface reduction rules

Jean-François Botalla-Gambetta 6 Reputation points
2021-10-20T11:56:24.793+00:00

Our add-in is developed in .NET C# / VSTO and signed with an up-to-date standard signing certificate.

However we start to have clients complaining about Windows Defender attack surface reduction rules preventing the add-in to start (on Excel startup).
In particular when Excel tries to use a e.g: %localappdata%Temp\2\Deployment\9CNA55QQ.ZA6\WVJ7LGP0.26A.application (the folder is actually random), the rules reject and prompt.

How can we solve this issue, without asking the client to exclude the whole %localappdata%Temp\2\Deployment\ folder from the surface attack rules ?

Should we use an EV signing certificate ?

Is there any others explanations ?

Office Development
Office Development
Office: A suite of Microsoft productivity software that supports common business tasks, including word processing, email, presentations, and data management and analysis.Development: The process of researching, productizing, and refining new or existing technologies.
3,509 questions
0 comments No comments
{count} vote