Fixed with 27766 Workaround for “Your organization used App Control for Business to block this app” dialog in the Canary Channel

Anonymous
2024-12-16T16:39:34+00:00

After updating to Build 27764 in the Canary Channel, some Windows Insiders are reporting hitting the issue that previously impacted the Dev Channel where an “Your organization used App Control for Business to block this app” dialog is shown when attempting to use or install certain third-party apps on your PC due to an incorrect policy being enforced. The following steps should mitigate the issue:

  1. Open Command Prompt with administrator privileges.
  2. Type and hit enter: mountvol s: /s
  3. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
  4. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{36D62F7C-AB85-4F61-8724-744294F24023}.cip
  5. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
  6. Then reboot your PC.

If you are dual-booting between the Canary Channel and the Dev Channel or another version of Windows, you will need to do this workaround BEFORE booting to the other OS.

If the above steps do not work, you may need to disable Secure Boot first and follow these steps:

  1. Disable Secure Boot on your PC.
  2. You will be asked to enter your BitLocker recovery key.
  3. Log in to your PC and open Command Prompt with administrator privileges.
  4. Type and hit enter: mountvol s: /s
  5. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip
  6. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{36D62F7C-AB85-4F61-8724-744294F24023}.cip
  7. Type and hit enter: del S:\EFI\Microsoft\Boot\cipolicies\active{66D7D265-7EDD-47DD-86E4-F7C42CD55A8F}.cip
  8. Reboot your PC once with Secure Boot still disabled.
  9. Then reboot again and enable Secure Boot.

In small cases, your PC may not boot into Windows. To get out of this state, you can follow these steps:

  1. Disable Secure Boot on your PC.
  2. Then get into Windows Recovery, choose advanced boot options and disable driver signature enforcement.
  3. Then do the above-mentioned workaround for deleting the policies after logging in.
  4. Alternatively, you can also delete the above-mentioned policies directly from the Windows Recovery console.
Windows Insider program | Windows Insider preview | Install, activate, and Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

91 answers

Sort by: Most helpful
  1. Anonymous
    2025-01-14T06:53:36+00:00

    Thank you for the reply.

    I think the partition for efi is S , but here I don't find the files that everybody talks.

    The workaround that I found but drive me crazy is altering the startup settings every time I start the letter, and disabling driver signature enforcement

    If I run mountvol G: /d , I get the system cannot find the file specified.

    Image

    On saturday I made a rollback ,because after the update I had problems with the Internet too, I was connected to the internet (wi-fi/enthernet/hotspot) and I did not got anything (I got something like access blocked ) , the internet worked just fine on other devices.

    After the rollback I was able to use the internet, and I saw that I did not had the G:\ partition, but yesterday after I tried almost everything I thought , if i will reset the windows maybe I will be able to get rid get rid of the policies thing, and "Your organzation used App Control for Business to block this app". But nothing happened after the reset.

    From what you show above the bad CIPolicies files have already been deleted.

    Any problem you have seems to be unrelated to those files. 🤷‍♂️

    If you have a good system image backup taken before you had these problems, you could just restore a good system.

    Otherwise, you may try an update repair with the repair version. Good luck!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-01-14T06:39:42+00:00

    Thank you for the reply.

    I think the partition for efi is S , but here I don't find the files that everybody talks.

    The workaround that I found but drive me crazy is altering the startup settings every time I start the letter, and disabling driver signature enforcement

    If I run mountvol G: /d , I get the system cannot find the file specified.

    Image

    I tried to create a folder in the G:\ to see what happens there , and I get this error.

    On saturday I made a rollback ,because after the update I had problems with the Internet too, I was connected to the internet (wi-fi/enthernet/hotspot) and I did not got anything (I got something like access blocked ) , the internet worked just fine on other devices.

    After the rollback I was able to use the internet, and I saw that I did not had the G:\ partition, but yesterday after I tried almost everything I thought , if i will reset the windows maybe I will be able to get rid get rid of the policies thing, and "Your organzation used App Control for Business to block this app". But nothing happened after the reset.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-01-13T20:13:25+00:00

    Hello,

    I tried to find the policies but i don't have the policies in S ,

    Coult not find S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip , I even reset the windows, and i still get the error.

    I see that I got a G:\ partition, but I don't have anything there, and this partition weren't there, is out of nowhere this partition right now.

    Some users found that the EFI partition was mounted already with a different letter.

    In that case you should get an error when you try to "mountvol S: /s"

    Perhaps yours is mounted on G: instead of S: 🤷‍♂️

    If that is the case, you can remove G: and mountvol on S: again.

    mountvol G: /d

    mountvol S: /s

    then type the following to check the files in the directory and then delete the ones suggested. 😎

    S:

    S:>cd EFI\Microsoft/boot/cipolicies\active

    dir

    https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mountvol

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-01-13T19:12:55+00:00

    Hello,

    I tried to find the policies but i don't have the policies in S ,

    Coult not find S:\EFI\Microsoft\Boot\cipolicies\active{8E8A94F0-6EB9-42C7-A189-E018C8CF3D10}.cip , I even reset the windows, and i still get the error.

    I see that I got a G:\ partition, but I don't have anything there, and this partition weren't there, is out of nowhere this partition right now.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-01-13T18:30:09+00:00

    Yes, public build is dual boot, on both machines. So, the EFI partition is in common for both. I will try to boot the bad system into the Dev build and see if it still has a problem.

    I just checked my other system on which the last update did run normally, and the numbers are different from the ones shown. Had my other machine not refused to do that update, possibly it would not have had that problem.

    I do not have a Canary build.

    Originally the problem was caused by Dev Build.

    If you deleted the bad CIPolicies files as instructed, you should be fine. 😉

    "After updating to Build 27764 in the Canary Channel, some Windows Insiders are reporting hitting the issue that previously impacted the Dev Channel where an “Your organization used App Control for Business to block this app” dialog is shown when attempting to use or install certain third-party apps on your PC due to an incorrect policy being enforced. The following steps should mitigate the issue:"

    Was this answer helpful?

    0 comments No comments