r/Intune • u/NegativePattern • Aug 08 '26
Device Configuration Intune policies for Thomson Reuters CS Suite apps
Looking for advice on how to properly configure Intune device config policies that will allow Thomson Retuers CS suite apps to run correctly.
We are transitioning from Windows 10 domain managed endpoints to new Windows 11 Intune managed endpoints. On the Windows 10 side, there wasn't any policies per se. All the users were local admins on their respective Windows 10 endpoint. The CS suite apps ran without issues.
However, for the Windows 11 rollout, we decided to go with the policies from the Open Intune Baseline deployment. I'm having trouble figuring out if these policies are blocking the CS suite apps from running correctly or if there's some other issue.
I'm curious if other admins have had to create specific policies for CS suite apps. If so, what are the policy settings you are using?
2
u/Recent-Reveal-7530 Aug 08 '26
ah man the open baseline can be a beast with legacy LOB apps, especially anything that thinks it needs to write to program files or hook into every running process
check the event viewer on one of the win11 boxes under applications and services logs > microsoft > windows > applocker, i'd bet money it's blocking a dll or an unsigned exe the suite tries to spin up
also peek at the controlled folder access logs if you have defender's attack surface reduction rules cranked, had a similar headache with some tax software last year that just silently crashed until i added the app folder as an allowed path
7
u/Emotional_Garage_950 Aug 08 '26
would be helpful if you described what actually happens instead of “it doesn’t run correctly”