Support Request: Application control policy block on client

Description

Dear Michael,

Unfortunately we are experiencing the same issue again today on client Abri (DESKTOP-A5L8704, project BTNStad). This is now the latest in a series of occurrences showing exactly the same pattern.

Current report
Time: October 1, 2026, 08:54:20
Error: Watchdog SiteKiosk.Runtime.exe, Unable to start process, This file is blocked by an application control policy
As a result, the Runtime ends up in a restart loop and the client no longer displays any content.

Device details
Client: Abri, project BTNStad
Computer name: DESKTOP-A5L8704
Operating system: Windows 11 Professional N 10.0.26200.0
SiteKiosk version: 1.10.341.0

What we have already ruled out
After the first occurrence we manually disabled Smart App Control, after which the device worked again
On September 26 we found that Smart App Control had switched back to On, without us having changed it, so we disabled it again
We verified through gpresult that this device is not a member of a domain and is not managed by Intune or any other MDM, so there is no external policy that could be enforcing this
Windows Update is fully disabled through local policy, so a Windows update cannot have reset the setting

Despite all of this, the block keeps recurring after some time, now for the fourth time.

Question
Since this looks to us like a structural issue rather than a one time configuration mistake, we would like to know whether SiteKiosk.Runtime.exe and the files deployed by the AutoUpdater have been submitted to Microsoft's ISG reputation program. That would permanently prevent this type of Smart App Control block, regardless of local security settings. Is this already the case, and if not, is this something you can arrange?

Best regards,
Thimo Arling

Answer: (1)

Re: Application control policy block on client 10/1/2026 1:15 PM
Hello,

the main SiteKiosk Online Client components, including SiteKiosk.Runtime.exe, are digitally signed. According to Microsoft's documentation, Smart App Control uses both Microsoft's cloud-based reputation services and code-signing information when deciding whether an application is trusted.

Recent Windows versions apparently also allow Smart App Control to be enabled from the Windows Security application without requiring a clean Windows installation. It is therefore possible that the Smart App Control state changed again as part of a Windows update or another Windows-side change.

Microsoft also acknowledges that Smart App Control may not be suitable for all usage scenarios and may interfere with legitimate tasks. In the Smart App Control FAQ under “Why is Smart App Control on?”, Microsoft states:
"However, there are some legitimate tasks that corporate users, developers, or others may do regularly that may not be a great experience with Smart App Control running. If we detect that you're one of those users, we'll automatically turn Smart App Control off so you can work with fewer interruptions."
See: https://support.microsoft.com/en-us/windows/security/threat-malware-protection/smart-app-control-frequently-asked-questions
For a dedicated kiosk system where reliable and uninterrupted operation is required, we therefore recommend disabling Smart App Control if it repeatedly blocks required SiteKiosk components.

As an alternative way to disable Smart App Control again (remotely), you can use PowerShell through the SiteKiosk Online Recovery Shell.
In your SiteKiosk Online team, please navigate to:
Monitoring > [Client] > Administration > Recovery Shell
First, check the current Smart App Control state:

Get-MpComputerStatus | Select-Object SmartAppControlState

If Smart App Control is enabled, you can disable it with:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\CI\Policy" -Name "VerifiedAndReputablePolicyState" -Type DWord -Value 0

Then restart the system:
Restart-Computer -Force


Please also check whether optional diagnostic data is enabled in Windows and consider disabling this setting.
According to Microsoft's Smart App Control FAQ, Smart App Control requires optional diagnostic data to be enabled. If optional diagnostic data is disabled, Smart App Control is also turned off.

If Smart App Control nevertheless becomes enabled again after optional diagnostic data has been disabled, you could consider using a startup script or scheduled task that checks the Smart App Control setting at system startup and deactivates it if necessary.
Please note that this would be a Windows-side workaround rather than a SiteKiosk setting.

Regards,
Michael
My Account
Login
Language (Tickets):