Fix Configuration Manager Applications Blocked by WDAC Managed Installer
Question details
Users in a co-managed environment need to resolve an issue where applications installed via Configuration Manager are blocked by Windows Defender Application Control (WDAC).
- Product
- Windows Defender Application Control (WDAC)
- Device & OS
- Windows
- Scenario
- Deploying enterprise applications using Configuration Manager in an Intune co-managed environment with WDAC policies enforced.
- Observed behavior
- Configuration Manager applications are blocked by WDAC during installation, even though the agent was reinstalled with the ManagedInstaller=1 parameter and Managed Installer is enabled.
Ensure you have collected the latest WDAC policy XML file, deployment configurations, and relevant Windows Event Logs (specifically AppLocker or CodeIntegrity logs) to analyze the block events before requesting support.
Request Specialized Deployment Assistance via Microsoft Q&A
Because WDAC and Intune co-management involves complex enterprise security policies, consulting Microsoft deployment specialists is the most effective path to resolve intricate blocking issues.
In complex co-managed environments, application blocking by WDAC can stem from policy misconfigurations, timing issues with agent registration, or missing trust rules for the Managed Installer.
Since this requires deep analysis of deployment policies, reaching out to Microsoft's dedicated Q&A community is recommended.
Collect your current WDAC policy, Intune deployment configuration details, and relevant CodeIntegrity or AppLocker event logs showing the blocked executions.
Open your web browser and navigate to the official Microsoft Q&A platform (learn.microsoft.com/en-us/answers).
Create a new detailed question under the 'Windows Defender Application Control' topic. Include your installation details (e.g., ManagedInstaller=1) and the gathered logs so deployment specialists can investigate the root cause.
Deploy WPS Office as Your Lightweight, Secure Office Suite
While troubleshooting enterprise application deployments and WDAC blocks, consider providing your users with a highly compatible, easy-to-deploy alternative to heavy Office installations. WPS Office is lightweight, fully compatible with Microsoft formats, and straightforward to deploy across enterprise environments.
- 1. Download the enterprise installer: Obtain the official WPS Office installation package suitable for enterprise deployment from the official website.
- 2. Configure deployment parameters: Set up silent installation flags or configure the package within your preferred endpoint management tool.
- 3. Distribute to endpoints: Deploy WPS Office to user devices securely, ensuring it aligns with your standard application control policies.

Frequently Asked Questions
Why does WDAC block Configuration Manager applications even with Managed Installer enabled?
This can occur if the AppLocker services are not running correctly, the WDAC policy lacks the specific rule to trust the Managed Installer, or the Configuration Manager client did not successfully register its installation paths as trusted.
How do I verify if Managed Installer is active for Configuration Manager?
You can check the local AppLocker event logs (Microsoft-Windows-AppLocker/EXE and DLL) to see if files dropped by the Configuration Manager client (ccmexec.exe) are being correctly tagged with the Managed Installer extended attribute.
Which logs should I analyze for WDAC blocked applications?
Analyze the CodeIntegrity operational logs (Event ID 3077 for blocks) and AppLocker EXE/DLL logs in the Windows Event Viewer to determine exactly which executable or script was blocked and why.




