Avantec AG
Zug
HP Wolf Security vs Windows Defender Application Guard – Tec-Bite
- 07 August 2026
- 100%
- Permanent position
- Zug
Job summary
HP Wolf Security and Microsoft Windows Defender Application Guard offer unique isolation solutions.
Tasks
- Explore the key differences and advantages of both security options.
- Evaluate installation and configuration processes for each solution.
- Analyze licensing models and compatibility with various systems.
Skills
- Understanding of endpoint security and isolation technologies.
- Knowledge of security software and its deployment.
- Ability to assess and compare security solutions effectively.
Is this helpful?
About the job
In conversations with customers, I often hear the statement that Microsoft with its Windows Defender Application Guard also offers isolation. So why should one still buy an additional solution like HP Wolf Security? With this blog article, I want to highlight the differences between the two solutions. Although I am somewhat biased on this topic, I try to approach the whole matter objectively. The advantages and disadvantages speak for themselves. Battle of the Titans Not quite as epic as in the Titanomachy, but certainly comparable to a battle of the titans, there is a certain rivalry between HP and Microsoft. With the purchase of Bromium at the end of 2019, HP seriously entered the endpoint security market and has since integrated Bromium as HP Sure Click into its business notebooks. More information can be found here. HP Sure Click has since become HP Wolf Security, but the fundamental technology of Bromium remains intact. In addition to isolation, HP SureSense, a NextGen AV solution, was also added. Microsoft, of course, has not been idle in recent years and has invested heavily in the security sector. They are also much more broadly positioned than HP, which, however, has no direct influence on the isolation solution per se. Microsoft is now a serious competitor for various security solution providers, whether on the endpoint or for other purposes. To continue the titan battle metaphor, I simply hope that HP does not suffer the same fate as the Titans here. Basics Technology Microsoft’s Windows Defender Application Guard is based on their "Hyper-V" hypervisor. There are also two different variants: Windows Defender Application Guard for Edge and Windows Defender Application Guard for Office. HP Wolf Security runs with a proprietary hypervisor. To ensure compatibility with the Microsoft VBS features based on Hyper-V in Windows, HP Wolf Security uses the WHP interface from Microsoft, available since Windows 1909, which controls access to the CPU. Installation / Configuration WDAG is installed as a role in Windows. This is done either via GPOs or additional Microsoft tools such as Intune or SCCM. WDAG for Office requires integration into Azure AD. The configuration options for WDAG for Edge via GPO are rather limited: Group Policy Settings in Windows Anyone who works with Group Policies knows that it can sometimes be tedious. Especially when problems arise, troubleshooting is cumbersome. For example, the current status of a client cannot be easily read out, for instance, to find out which setting from which policy is currently active when policies overlap. HP Wolf Security is installed on the endpoint in the form of an agent secured with kernel and file filter drivers. Installation is managed via existing software distribution. Policy configuration is done via a web UI and offers extensive options for granular settings based on computer groups: HP Wolf Security Controller – Policy editing In addition, a device view provides a convenient way to see which option from which policy is currently active. The connection between endpoint and server runs over HTTPS. Licensing As mentioned, there is a variant of WDAG for the Edge browser and one for Office. WDAG for Edge is free, whereas the licensing requirements for WDAG for Office are considerable. A Windows Enterprise Edition as well as a Microsoft 365 E5 or Microsoft 365 E5 Security Agreement are required. For SMEs, an E5 agreement is often too expensive. In addition, the Azure Cloud with Intune as a basis is a prerequisite. A purely on-premises installation is not possible. For a roughly comparable setup to HP Wolf Security, both WDAG for Edge and WDAG for Office are needed. Licensing for HP Wolf Security, on the other hand, is simple: one license is required per installed agent. There are volume discounts as with all manufacturers. For completeness, it must be mentioned that there are three different variants of HP Wolf Security: "Wolf Pro Security Edition", "Wolf Pro Security" and "Wolf Enterprise Edition". The differences between the variants mainly concern the handling and possibilities of the policy. An important point is also the aforementioned HP SureSense. SureSense is exclusively included in "Wolf Pro Security". Here is an overview: HP Wolf Security Editions I focus in this article on the "Wolf Enterprise Edition". What can be isolated? Web Isolation With WDAG for Edge, only the Edge browser is isolated. There are also browser extensions for Google Chrome and Mozilla Firefox that redirect defined URLs to the isolated Edge. HP Wolf Security isolates the IE as well as Firefox ESR x64 and also offers its own specially hardened secure browser based on the Chromium engine. As with WDAG, there is also the option to redirect unsafe content to the secure browser via browser extensions for Google Chrome, Mozilla Firefox and Microsoft Edge. File Isolation With WDAG for Edge, PDFs opened in the browser are also isolated, but once saved and then opened, they are no longer protected. With WDAG for Office, Word, Excel and PowerPoint files can be isolated. A small but fine detail is active content such as macros and ActiveX controls. To use these, the WDAG protection must be removed. To remove the protection, an internet connection is required. All other file types such as PDFs, images, videos, archive files or executables cannot be isolated. WDAG for Office uses ADS Zone Identifiers to identify files that need protection. Depending on the URL, a corresponding ID is set on the downloaded file and it is decided whether the file is isolated or not. However, an ADS Zone Identifier can be easily manipulated, allowing the protection to be bypassed. Email attachments, one of the biggest risk factors, are only secured for the initial emails received from external senders. Thus, forwarding the email results in the loss of the protection function. USB sticks are only protected with WDAG for Office if the stick is formatted with the NTFS file system and the file is saved with a corresponding ADS Zone ID. With near certainty, USB sticks found on trains do not fall into this category. HP Wolf Security offers advantages in all these points. On the one hand, many more file types can be isolated (see here). In addition, for downloads, a combination of ADS Zone IDs and the source URL is checked by policy. The protection of the "untrusted" status is secured by a file filter driver. Thus, if a file is downloaded and saved from an isolated, "untrusted" website, it remains isolated even if the file is later copied from the original location. HP Wolf Security also offers more flexibility and security with email attachments. Not only the attachment of the initially received email from an external sender is isolated, but also when forwarded internally. For USB sticks, the file format does not matter. Data on a USB stick is always isolated per se; an ADS Zone Identifier is not checked. The stick found on the train can therefore be safely plugged in. Macros can also be used in isolated files. To remove protection, an internet connection is not necessarily required. During an offline check, a microVM is created in the background, the file is analysed there and, if not malicious, the protection is removed. Optionally, in online mode, the HP Threat Cloud can also be used for additional threat intelligence. Summary Mentioning all possibilities in detail would exceed the scope of this blog and probably the willingness of most readers to read. In summary, however, it can be said with a clear conscience and completely impartially that Microsoft with their Application Guard offers a lot, but HP with Wolf Security still has the edge. In my humble opinion, HP scores in all relevant areas: price, scope, operation, security. To complete the titan war: Microsoft would be locked in Tartarus. The German BSI (Federal Office for Information Security) has also recognised the advantages of isolation and provides corresponding guidelines in its guides for "Minimum Standard of the BSI for Web Browsers" and "Ransomware Measures Catalogue": Excerpt from BSI guidelines The article HP Wolf Security vs Windows Defender Application Guard first appeared on Tec-Bite.