Disable-WdacBidTrace

Disables Built-in Diagnostics Tracing (BidTrace) for troubleshooting WDAC components.

Syntax

Disable-WdacBidTrace
       [-InputObject] <CimInstance>
       [-AsJob]
       [-CimSession <CimSession>]
       [-PassThru]
       [-ThrottleLimit <Int32>]
       [-Confirm]
       [-WhatIf]
Disable-WdacBidTrace
       [-Path] <String>
       [-AsJob]
       [-CimSession <CimSession>]
       [-PassThru]
       [-Platform <String>]
       [-ProcessId <UInt32>]
       [-ThrottleLimit <Int32>]
       [-Confirm]
       [-WhatIf]
Disable-WdacBidTrace
       [-AsJob]
       [-CimSession <CimSession>]
       [-PassThru]
       [-Platform <String>]
       [-ThrottleLimit <Int32>]
       -Folder <String>
       [-Confirm]
       [-WhatIf]
Disable-WdacBidTrace
       [-AsJob]
       [-CimSession <CimSession>]
       [-PassThru]
       [-Platform <String>]
       [-ThrottleLimit <Int32>]
       [-IncludeAllApplications]
       [-Confirm]
       [-WhatIf]

Description

For more information about data access tracing (Bidtrace), see Data Access Tracing (Windows 8)http://msdn.microsoft.com/en-us/library/hh829624(VS.85).aspx.

Examples

1:

PS C:\> Disable-WdacBidTrace -Path "C:\temp\abc.exe" -Platform 32-bit

This command disables the BidTrace for the application "C:\temp\abc.exe" on the 32-bit platform:

2:

PS C:\> Disable-WdacBidTrace -Path "C:\temp\abc.exe" -ProcessId 1234 -Platform 32-bit

This command disables the BidTrace for the application "C:\temp\abc.exe" on the 32-bit platform and disables BidTrace for a particular instance of "abc.exe" (with Process ID = 1234):

3:

PS C:\> Disable-WdacBidTrace -Folder "C:\temp"

This command disables the BidTrace for all applications located inside C:\temp on the native platform:

4:

PS C:\> Disable-WdacBidTrace -IncludeAllApplications -Platform 64-bit

This command disables the BidTrace for all 64-bit applications:

5:

PS C:\> $bidSetting = Enable-WdacBidTrace -Path "C:\temp\abc.exe" -Platform 64-bit -PassThru
<use C:\temp\abc.exe>
Disable-WdacBidTrace $bidSetting

This command first enables the WDAC BidTrace for the 64-bit application "C:\temp\abc.exe". It also saves the result into a PowerShell variable that can be reused in Disable-WdacBidTrace:

Parameters

-AsJob

ps_cimcommon_asjob

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-CimSession

Runs the cmdlet in a remote session or on a remote computer. Enter a computer name or a session object, such as the output of a New-CimSessionhttp://go.microsoft.com/fwlink/p/?LinkId=227967 or Get-CimSessionhttp://go.microsoft.com/fwlink/p/?LinkId=227966 cmdlet. The default is the current session on the local computer.

Type:CimSession
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type:SwitchParameter
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Folder

Disable BidTrace for all applications under this folder.

Type:String
Position:Named
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-IncludeAllApplications

Disable BidTrace for all applications.

Type:SwitchParameter
Position:Named
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-InputObject

Disable the BidTrace represented by the specified BidTrace setting objects. Enter a variable that contains the objects, or type a command or expression that gets the objects.

Type:CimInstance
Position:1
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-PassThru

Passes the object created by this cmdlet through the pipeline. By default, this cmdlet does not pass any objects through the pipeline.

Type:SwitchParameter
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-Path

Disable BidTrace for this application full path.

Type:String
Position:1
Default value:None
Required:True
Accept pipeline input:True
Accept wildcard characters:False

-Platform

The platform architecture of the WDAC BidTrace setting. Possible values are '32-bit', '64-bit' or 'All'. The default is '32-bit' on a 32-bit process and '64-bit' on a 64-bit process. This is the platform architecture on the remote machine if this command is executed on a remote CIM session.

Type:String
Position:Named
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-ProcessId

Disable BidTrace only for this process ID.

Type:UInt32
Position:Named
Default value:None
Required:False
Accept pipeline input:True
Accept wildcard characters:False

-ThrottleLimit

Specifies the maximum number of concurrent operations that can be established to run the cmdlet. If this parameter is omitted or a value of 0 is entered, then Windows PowerShell® calculates an optimum throttle limit for the cmdlet based on the number of CIM cmdlets that are running on the computer. The throttle limit applies only to the current cmdlet, not to the session or to the computer.

Type:Int32
Position:Named
Default value:None
Required:False
Accept pipeline input:False
Accept wildcard characters:False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type:SwitchParameter
Position:Named
Default value:False
Required:False
Accept pipeline input:False
Accept wildcard characters:False

Outputs

CimInstance[]