Intune blocks software installation on Windows desktops

X-Box-11-2021 105 Reputation points
2023-10-12T04:38:53.23+00:00

Hi guys,

A tech in a company deployed Windows devices protection via Intune and died without leaving any documentation.

What happens now, any attempt to install any software is blocked and this warning pops up.

INTUNE BLOCK APP

Despite it says that the app installation is blocked by Windows Defender Application Control indeed it is blocked somewhere in Intune.

I only have this screenshot which doesn't shed much light on what exactly was configured.

INTUNE BLOCK APP POLICY

If for someone it make any sense for could you please point me where I can temporarily unblock or disable devices protection to install software.

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
147 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,733 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 46,171 Reputation points Microsoft Vendor
    2023-10-12T06:17:12.1466667+00:00

    @X-Box-11-2021, Thanks for posting in Q&A. From the information you provided, it seems there's Windows Defender Application Control policy which deployed via Intune block the software installation. To make the installation working, you can replace the existing policy with a new version of the policy that will "Allow *", like the rules in the example policy at %windir%\schemas\CodeIntegrity\ExamplePolicies\AllowAll.xml. Once the updated policy is deployed, you can then delete the policy from the Intune portal. This deletion will prevent anything from being blocked and fully remove the WDAC policy on the next reboot.

    https://learn.microsoft.com/en-us/windows/security/application-security/application-control/windows-defender-application-control/deployment/deploy-wdac-policies-using-intune#remove-wdac-policies-on-windows-10-1903

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. X-Box-11-2021 105 Reputation points
    2023-10-12T10:10:07.6766667+00:00

    Hi @Crystal-MSFT

    Do I need to do anything in Microsoft Intune?

    Like delete the device under Windows Devices.