# Inspect empty AppLocker collections before enabling Intune managed installer

> Could enabling the managed installer unexpectedly turn an empty AppLocker collection into enforcement?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-264-inspect-empty-applocker-collections-before-enabling-intune-managed-installer/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:32+00:00
- Modified: 2026-09-10T01:23:48+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Could enabling the managed installer unexpectedly turn an empty AppLocker collection into enforcement?

## Potentially affected

Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.

## DSE recommendation

Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured.

## Article

## Source facts

Enabling Intune managed installer merges an AppLocker policy containing a dummy rule into the device’s existing policy. An empty collection marked NotConfigured can consequently contain that rule and become enforced. Microsoft warns that this can block application startup, Windows sign-in, or boot. Its mitigation is to remove such empty NotConfigured collections from the existing policy before the merge. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/manage-app-control).

## Applicability

Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.

## DSE recommendation

Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured. Have the application-control owner approve a narrowly scoped correction where needed. Prepare a tested recovery route before the pilot and avoid a broad policy-cleanup script as a substitute for understanding the affected collection.

## Verification

Test on a recoverable device that represents the existing policy combination. Compare the collection state before and after enabling managed installer, then exercise sign-in and the required applications. Include a controlled restart only within the approved test plan. Stop expansion if the merged result differs from the reviewed design, and retain the policy evidence with the recovery and application-test outcomes.

## Official references

[Microsoft Learn: Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/manage-app-control).

## Primary reference

- Name: Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/manage-app-control
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Inspect empty AppLocker collections before enabling Intune managed installer,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-264-inspect-empty-applocker-collections-before-enabling-intune-managed-installer/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
