question

David-B avatar image
0 Votes"
David-B asked LuDaiMSFT-0289 commented

Impossible to open .hta file after activating the Control Application (ARS / Intunes)

Hi,

After activating the "Application Control" of ARS in Intunes, I can no longer run files with the .hta extension. I have no error messages or alerts in Defender.

199686-capture.png


I deleted the strategy to go back, the blockage persists.


mem-intune-generalmem-intune-device-configurations
capture.png (67.6 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered

@David-B Thanks for your update.

If you want to configure this setting to "Not configured", it seems a workaround that try to find the registry key of this setting and then change the registry key to remove the setting.

If you want to make it via intune, it is needed to do the following actions:
1.Please remove the group in assignment of the Control Application policy.
2.Create a Powershell Script that can change the registry key of the target setting.
3.Deploy this script via intune.
https://docs.microsoft.com/en-us/mem/intune/apps/intune-management-extension

Hope it will give you some ideas.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered

@David-B Thanks for posting in our Q&A. From your description, did you mean that you have removed the group in assignment, but this policy still worked? If there is anything unclear, please correct me.

For this issue, it seems that this policy is tattooed. Intune deploys policies based on the windows CSPs. The tattoo is an issue or limitation from Windows CSPs. For more details, please refer to the following link:
https://www.anoopcnair.com/intune-policy-tattooed-not-tattooed-windows-csp/
Note: Non-Microsoft link, just for the reference.

Thanks for your understanding.


If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

David-B avatar image
0 Votes"
David-B answered

Hi,

thank you for your feedback

Yes, we have removed the group in assignment

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

David-B avatar image
0 Votes"
David-B answered LuDaiMSFT-0289 commented

1.png (36.7 KiB)
2.png (37.6 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@David-B Thanks for your kindess to share other suggestions. It will give someone else who has the similar issue more choice.

Thanks again and have a nice day. : )

0 Votes 0 ·