GuideInformationBusiness ContinuityIT

Inspect empty AppLocker collections before enabling Intune managed installer

Could enabling the managed installer unexpectedly turn an empty AppLocker collection into enforcement?

Governed cloud identity system with connected service and lifecycle nodes.
DSE visual intelligenceIdentity & cloudGuide · 2 min read
Executive summary

What you need to know

Could enabling the managed installer unexpectedly turn an empty AppLocker collection into enforcement?

Potentially affected

Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.

DSE recommendation

Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured.

Source facts

Enabling Intune managed installer merges an AppLocker policy containing a dummy rule into the device’s existing policy. An empty collection marked NotConfigured can consequently contain that rule and become enforced. Microsoft warns that this can block application startup, Windows sign-in, or boot. Its mitigation is to remove such empty NotConfigured collections from the existing policy before the merge. Microsoft Learn.

Applicability

Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.

DSE recommendation

Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured. Have the application-control owner approve a narrowly scoped correction where needed. Prepare a tested recovery route before the pilot and avoid a broad policy-cleanup script as a substitute for understanding the affected collection.

Verification

Test on a recoverable device that represents the existing policy combination. Compare the collection state before and after enabling managed installer, then exercise sign-in and the required applications. Include a controlled restart only within the approved test plan. Stop expansion if the merged result differs from the reviewed design, and retain the policy evidence with the recovery and application-test outcomes.

Official references

Microsoft Learn: Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune.

Primary reference

Review the official source

Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE