Thank you SIR!!!!
Fixed with 27766 Workaround for “Your organization used App Control for Business to block this app” dialog in the Canary Channel
After updating to Build 27764 in the Canary Channel, some Windows Insiders are reporting hitting the issue that previously impacted the Dev Channel where an “Your organization used App Control for Business to block this app” dialog is shown when attempting to use or install certain third-party apps on your PC due to an incorrect policy being enforced. The following steps should mitigate the issue:
- Open Command Prompt with administrator privileges.
- Type and hit enter: mountvol s: /s
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{36D62F7C-AB85-4F61-8724-744294F24023}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
- Then reboot your PC.
If you are dual-booting between the Canary Channel and the Dev Channel or another version of Windows, you will need to do this workaround BEFORE booting to the other OS.
If the above steps do not work, you may need to disable Secure Boot first and follow these steps:
- Disable Secure Boot on your PC.
- You will be asked to enter your BitLocker recovery key.
- Log in to your PC and open Command Prompt with administrator privileges.
- Type and hit enter: mountvol s: /s
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{36D62F7C-AB85-4F61-8724-744294F24023}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
- Reboot your PC once with Secure Boot still disabled.
- Then reboot again and enable Secure Boot.
In small cases, your PC may not boot into Windows. To get out of this state, you can follow these steps:
- Disable Secure Boot on your PC.
- Then get into Windows Recovery, choose advanced boot options and disable driver signature enforcement.
- Then do the above-mentioned workaround for deleting the policies after logging in.
- Alternatively, you can also delete the above-mentioned policies directly from the Windows Recovery console.
Windows Insider program | Windows Insider preview | Install, activate, and Windows update
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
91 answers
Sort by: Oldest
-
Anonymous
2024-12-22T19:27:21+00:00 -
Anonymous
2024-12-23T08:54:29+00:00 I did not "Enter" the script I cut & paste from the original script so don't know why it did not find the S: volume
-
Anonymous
2024-12-23T17:29:56+00:00 I did not "Enter" the script I cut & paste from the original script so don't know why it did not find the S: volume
There is no S: volume till you enter the command "mountvol S: /s" from a command prompt opened as administrator as explained in the 1st post.
-
Anonymous
2024-12-24T08:46:18+00:00 This just showed up on Dec 24, 2024. Dell XPS 8940 Multiboot system, 24H2 R.P. 26100.2605, 23H2 Beta 22635.4655 and Canary Build 27764.1000.
The problem showed up when I booted the 24H2 R.P. Build 26100.2605 system on Dec 24, 2024.
It is strange that the problem didn't show up earlier. I used these 3 systems for several days before Dec 24 without this issue on any of the 3 systems. 🤷♂️
I applied the workaround from Brandon post in page 1, first 6 lines and that eliminated the problem.
The system came up fine after reboot.
Note that there were also other drivers showing a yellow triangle when I check device manager.
It sure affected the NVIDIA drivers including the NVIDIA High-Definition Audio. I could not get any sound on my Monitor speakers.
This worked fine for this specific case.
\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_- Open Command Prompt with administrator privileges.
- Type and hit enter: mountvol s: /s
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{36D62F7C-AB85-4F61-8724-744294F24023}.cip
- Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
- Then reboot your PC. __________________________________________________________________________________________________________________________
Thanks, Brandon. 👍
This is what I see left in the EFI partition after deleting the 3 .cip files suggested in the workaround instructions.
-
Anonymous
2024-12-24T09:33:21+00:00 This is what I see on another Canary 27764.1000 without apply the workaround.
Looks like the problem is caused by the last 3 .cip files which get deleted with the suggested workaround. 😎
So far, only the 2 Dell XPS 8930 and Dell XPS 8940, with Nvidia display driver and multiboot were affected by this bug and needed the workaround.
I have 2 more PCs (GMKTec M2 and K3 with Intel display driver) with Canary 27764.1000 (single boot) that did not exhibit the problem. 🤷♂️
Merry, Christmas!