logo
search
Security Policy Errors

Fix Configuration Manager Applications Blocked by WDAC Managed Installer

Maira MehtabMaira Mehtab Sep 21, 2026 869 views

Question details

Users in a co-managed environment need to resolve an issue where applications installed via Configuration Manager are blocked by Windows Defender Application Control (WDAC).

Product
Windows Defender Application Control (WDAC)
Device & OS
Windows
Scenario
Deploying enterprise applications using Configuration Manager in an Intune co-managed environment with WDAC policies enforced.
Observed behavior
Configuration Manager applications are blocked by WDAC during installation, even though the agent was reinstalled with the ManagedInstaller=1 parameter and Managed Installer is enabled.
Before you start

Ensure you have collected the latest WDAC policy XML file, deployment configurations, and relevant Windows Event Logs (specifically AppLocker or CodeIntegrity logs) to analyze the block events before requesting support.

Solution 1Recommended

Request Specialized Deployment Assistance via Microsoft Q&A

Because WDAC and Intune co-management involves complex enterprise security policies, consulting Microsoft deployment specialists is the most effective path to resolve intricate blocking issues.

In complex co-managed environments, application blocking by WDAC can stem from policy misconfigurations, timing issues with agent registration, or missing trust rules for the Managed Installer.

Since this requires deep analysis of deployment policies, reaching out to Microsoft's dedicated Q&A community is recommended.

1
Gather required diagnostic logs

Collect your current WDAC policy, Intune deployment configuration details, and relevant CodeIntegrity or AppLocker event logs showing the blocked executions.

2
Navigate to Microsoft Q&A

Open your web browser and navigate to the official Microsoft Q&A platform (learn.microsoft.com/en-us/answers).

3
Post in the WDAC tag

Create a new detailed question under the 'Windows Defender Application Control' topic. Include your installation details (e.g., ManagedInstaller=1) and the gathered logs so deployment specialists can investigate the root cause.

Free Microsoft Office alternative

Deploy WPS Office as Your Lightweight, Secure Office Suite

While troubleshooting enterprise application deployments and WDAC blocks, consider providing your users with a highly compatible, easy-to-deploy alternative to heavy Office installations. WPS Office is lightweight, fully compatible with Microsoft formats, and straightforward to deploy across enterprise environments.

  1. 1. Download the enterprise installer: Obtain the official WPS Office installation package suitable for enterprise deployment from the official website.
  2. 2. Configure deployment parameters: Set up silent installation flags or configure the package within your preferred endpoint management tool.
  3. 3. Distribute to endpoints: Deploy WPS Office to user devices securely, ensuring it aligns with your standard application control policies.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation package reduces deployment complexity and potential policy conflicts.Familiar user interface minimizes training time for enterprise users transitioning from other suites.Easier policy management with a unified, all-in-one office suite architecture.
microsoft office alternative - wps office

Frequently Asked Questions

Why does WDAC block Configuration Manager applications even with Managed Installer enabled?

This can occur if the AppLocker services are not running correctly, the WDAC policy lacks the specific rule to trust the Managed Installer, or the Configuration Manager client did not successfully register its installation paths as trusted.

How do I verify if Managed Installer is active for Configuration Manager?

You can check the local AppLocker event logs (Microsoft-Windows-AppLocker/EXE and DLL) to see if files dropped by the Configuration Manager client (ccmexec.exe) are being correctly tagged with the Managed Installer extended attribute.

Which logs should I analyze for WDAC blocked applications?

Analyze the CodeIntegrity operational logs (Event ID 3077 for blocks) and AppLocker EXE/DLL logs in the Windows Event Viewer to determine exactly which executable or script was blocked and why.