cant open company portal after enabling applocker default rules for exe

nvdl 1 Reputation point
2021-05-08T10:34:33.483+00:00

after enabling applocker trough endpoint manager with just the default rules ,only on exe files, i cant open the company portal.
i already tried adding the CompanyPortal.exe hash to the rules but i think it could be an other exe file that is started by the company portal that is blocked how do i find out which ?

in event viewer i get this error in system log:
Unable to start a DCOM Server: Microsoft.CompanyPortal_11.0.11491.0_x64__8wekyb3d8bbwe!App as Unavailable/Unavailable. The error:
"2147943660"
Happened while starting this command:
"C:\Program Files\WindowsApps\Microsoft.CompanyPortal_11.0.11491.0_x64__8wekyb3d8bbwe\CompanyPortal.exe" -ServerName:App.AppX6s9cdx1jy5jd6t9ardd3z4mjbjxsftk4.mca

Windows Autopilot
Windows Autopilot
A collection of Microsoft technologies used to set up and pre-configure new devices and to reset, repurpose, and recover devices.
413 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,740 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Markus Männl 56 Reputation points
    2021-05-08T15:36:13.187+00:00

    You must configure a rule under "Packaged App Rule".
    First install the Company Portal over the store and then create the rule...

    2 people found this answer helpful.

  2. Cici Wu-MSFT 1,176 Reputation points
    2021-05-10T09:02:45.34+00:00

    Can I know if the company portal can be opened when applocker enabled on premise not in endpoint manager? The process flow goes like this: We first model the policy we want to implement using AppLocker in Group Policy Editor. We then export the XML for that policy and use it to create a new, custom Windows 10 Device Configuration policy in Intune. Once the custom policy is deployed, the same policy behavior we modeled with AppLocker in Group Policy Editor is then applied to our targeted Windows 10 devices. Therefore, if it restrict Company portal to open, we need to check if the XML file itself has some restriction with Company Portal.

    Reference: https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-using-applocker-to-create-custom-intune-policies-for/ba-p/364981

    Also, according to my test, after configuring one applocker policy, other policies will be set as Deny by default in Applocker, please also check if all the policies in Applocker have any restriction with Company Portal.
    95189-051002.png

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.