What you need to know
Could enabling the managed installer unexpectedly turn an empty AppLocker collection into enforcement?
Potentially affected
Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.
DSE recommendation
Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured.
Source facts
Enabling Intune managed installer merges an AppLocker policy containing a dummy rule into the device’s existing policy. An empty collection marked NotConfigured can consequently contain that rule and become enforced. Microsoft warns that this can block application startup, Windows sign-in, or boot. Its mitigation is to remove such empty NotConfigured collections from the existing policy before the merge. Microsoft Learn.
Applicability
Use this review before enabling managed installer on Windows devices with an existing AppLocker configuration. Include policy owners for local and centrally delivered rules; do not assume an apparently inactive collection is harmless.
DSE recommendation
Export and inspect the actual policy structure on representative devices, looking specifically for the combination of an empty rule set and NotConfigured. Have the application-control owner approve a narrowly scoped correction where needed. Prepare a tested recovery route before the pilot and avoid a broad policy-cleanup script as a substitute for understanding the affected collection.
Verification
Test on a recoverable device that represents the existing policy combination. Compare the collection state before and after enabling managed installer, then exercise sign-in and the required applications. Include a controlled restart only within the approved test plan. Stop expansion if the merged result differs from the reviewed design, and retain the policy evidence with the recovery and application-test outcomes.
Official references
Review the official source
Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune - Microsoft Intune | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE