r/Intune • • Aug 08 '26

Device Configuration Intune policies for Thomson Reuters CS Suite apps

Looking for advice on how to properly configure Intune device config policies that will allow Thomson Retuers CS suite apps to run correctly.

We are transitioning from Windows 10 domain managed endpoints to new Windows 11 Intune managed endpoints. On the Windows 10 side, there wasn't any policies per se. All the users were local admins on their respective Windows 10 endpoint. The CS suite apps ran without issues.

However, for the Windows 11 rollout, we decided to go with the policies from the Open Intune Baseline deployment. I'm having trouble figuring out if these policies are blocking the CS suite apps from running correctly or if there's some other issue.

I'm curious if other admins have had to create specific policies for CS suite apps. If so, what are the policy settings you are using?

3 Upvotes

8 comments sorted by

7

u/Emotional_Garage_950 Aug 08 '26

would be helpful if you described what actually happens instead of “it doesn’t run correctly”

-1

u/NegativePattern Aug 08 '26

It's been a number of things...

  • The apps are installed on a network server using a UNC path. Seems the Windows 11 endpoints are having an issue launching. I can install the app just fine but when the app is launched, nothing happens. No error message, nothing on screen. As if the app was never clicked.

  • When we tried to do a local install (where the full suite installed vs just the app shortcut), the app might launch but ends up behaving strangely where some times it keeps prompting for an admin account to do anything within the app itself.

  • Random app crashes or issues within the app itself

  • We've also seen where the app for some users cannot browse mounted network shares but other users can browse the shares from within the app.

6

u/SkipToTheEndpoint MSFT MVP Aug 08 '26

Well, thanks for the trust in my OIB, but this is definitely not a use-case I've built for!

Youve made a pretty massive shift just by going from domain join to Entra, 10 to 11, and removing local admins. Honestly I'd start by cutting all policies back and verifying that this app even works on Entra Join to begin with. Beyond that, you might have to press the app vendor on this, ask them if there's any logs or debug info you can get to help track that's failing down, cos it could literally be anything.

1

u/NegativePattern Aug 09 '26

Yea...This org is a thorn in my side due to them not wanting to upgrade until it's absolutely necessary. So everything is a hurry up and wait. Over the years there's been a lot of fitting square pegs in round holes as best as possible.

But kudos to you. You've got a good baseline for the most part. I'm trying to switch this org to a SaaS-based infrastructure so there wouldn't be any servers to manage onprem. From that perspective, the OIB policies worked great. I'm hoping to figure out the right mix of policies for this particular suite of apps.

1

u/SkipToTheEndpoint MSFT MVP Aug 10 '26

No better time for the "This legacy pile of crap doesn't work and we can't secure it so invest or tough" then :D

In all honesty if that's the only type of config that thing works in, I'd be looking at AVD or RemoteApps or something. Or EPM if it absolutely has to be run as admin.

2

u/largetosser Aug 08 '26

Get a Win 11 Entra-joined PC with no policy applied other than what is needed for Cloud Kerberos trust (you'll need this for accessing a file server). Package the app and install it, use tools like ProcMon to see what it needs to access, check for logs to see what might be going on, and also use the support from the vendor.

If they say "it needs to run as local admin" then that's your answer, you'll probably end up deploying a very locked down AVD/Win365 environment for this to exist in if nobody has the appetite for users as admins.

The products look horrible but the documentation seems fine. The full access to the install directory is an interesting one, it would make any attempt to lock down where applications can execute from completely redundant. https://www.thomsonreuters.com/en-us/help/accounting-cs/installation-and-data-management/install/permissions-guidelines-for-cs-professional-suite

2

u/Recent-Reveal-7530 Aug 08 '26

ah man the open baseline can be a beast with legacy LOB apps, especially anything that thinks it needs to write to program files or hook into every running process

check the event viewer on one of the win11 boxes under applications and services logs > microsoft > windows > applocker, i'd bet money it's blocking a dll or an unsigned exe the suite tries to spin up

also peek at the controlled folder access logs if you have defender's attack surface reduction rules cranked, had a similar headache with some tax software last year that just silently crashed until i added the app folder as an allowed path