As some of you may know, I muti-boot using native boot vhdx, mostly various Insider builds. but I also have vhdx for Win10 and RTM Win11. I have three machine set up for this, my (unsupported) System Two with 24H2 as its conventional OS, System Four (unsupported) with Windows 10, and my supported System Five on 23H2 (see My Computers > Other Info for the last two). All of them got their respective cumulative updates on Patch Tuesday. Two out of the three work normally after the updates. My 23H2 system has major issues when booting to a vhdx after the update to 22631.4602.
When booted to any one of the available vhdx I have no keyboard, no touchpad, and no sound. The only way I can interact with Windows is through the touchscreen. That on its own is a major inconvenience, but not insurmountable. What is worse is that I am locked out of using anything but the built in Microsoft apps, nor am I allowed to open Windows Security. This is the case regardless of which OS I choose to boot. The only one that works normally is the conventional install of 23H2.
Attempting to open a non-Microsoft app like Firefox, or to open Windows Security is greeted with the statement that "Your organisation used App Control for Business to block this app". I repeat, this applies whichever vhdx I boot.

That is apparently part of Intune. As I only ever use a local account I cannot see how it possibly applies to me.
I must emphasise, none of this is in any way a problem in any of the vhdx OS's, they are all affected the same way. It is the main Windows 11 23H2 22631.4602 that seems to be applying the policies to any and all of the vhdx when it boots them. To confirm that I have restored a system image of its previous 22631.4460 (KB5046633) and all the vhdx are back to working normally again. In fact, I'm typing this in Firefox on the Canary build vhdx, passing the time while it installs the 27764.1000 feature update. Windows update says it's 95% installed, so I'll have to stop typing and reboot shortly....
When booted to any one of the available vhdx I have no keyboard, no touchpad, and no sound. The only way I can interact with Windows is through the touchscreen. That on its own is a major inconvenience, but not insurmountable. What is worse is that I am locked out of using anything but the built in Microsoft apps, nor am I allowed to open Windows Security. This is the case regardless of which OS I choose to boot. The only one that works normally is the conventional install of 23H2.
Attempting to open a non-Microsoft app like Firefox, or to open Windows Security is greeted with the statement that "Your organisation used App Control for Business to block this app". I repeat, this applies whichever vhdx I boot.

That is apparently part of Intune. As I only ever use a local account I cannot see how it possibly applies to me.
Intune's App Control for Business policies are part of endpoint security and use the Windows ApplicationControl CSP to manage allowed apps on Windows devices.
Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune - Microsoft Intune
Use App Control for Business policies and a managed installer to manage which apps are approved to run on Windows devices that you manage with Microsoft Intune.
learn.microsoft.com
I must emphasise, none of this is in any way a problem in any of the vhdx OS's, they are all affected the same way. It is the main Windows 11 23H2 22631.4602 that seems to be applying the policies to any and all of the vhdx when it boots them. To confirm that I have restored a system image of its previous 22631.4460 (KB5046633) and all the vhdx are back to working normally again. In fact, I'm typing this in Firefox on the Canary build vhdx, passing the time while it installs the 27764.1000 feature update. Windows update says it's 95% installed, so I'll have to stop typing and reboot shortly....
My Computers
-
At a glance
Windows 11 HomeAMD Athlon Silver 3050U8GBRadeon Graphics- OS
- Windows 11 Home
- Computer type
- Laptop
- Manufacturer/Model
- Acer Aspire 3 A315-23-R9VY
- CPU
- AMD Athlon Silver 3050U
- Memory
- 8GB
- Graphics Card(s)
- Radeon Graphics
- Monitor(s) Displays
- laptop screen
- Screen Resolution
- 1366x768 native resolution, up to 2560x1440 with Radeon Virtual Super Resolution
- Hard Drives
- 1TB Samsung EVO 870 SSD (from April 2026: 250GB EVO 850)
- Internet Speed
- 150 Mbps
- Browser
- Edge, Firefox
- Antivirus
- Defender
- Other Info
- UPDATE - 11 April 2026: due to lid hinges starting to break up this laptop has been retired from active duty. The OS with all software and files has been migrated to my System Seven in 'Other systems' to carry on as my general purpose 'main machine'.
I've now clean installed 25H2 and used Garlin's scripts to update Secure Boot to CA 2023 and revoke the PCA 2011 certificates. It's new role is to test secure boot issues.
Info for 2021-2026:
fully 'Windows 11 ready' laptop. Windows 10 C: partition migrated from my old unsupported 'main machine' then upgraded to 11. A test migration ran Insider builds for 2 months. When 11 was released on 5th October 2021 it was re-imaged back to 10 and was offered the upgrade in Windows Update on 20th October. Windows Update offered the 22H2 Feature Update on 20th September 2022. It got the 23H2 Feature Update on 4th November 2023 through Windows Update, 24H2 on 3rd October 2024 through Windows Update by setting the Target Release Version for 24H2, and 25H2 on 30th September 2025 through Windows Update by setting the Target Release Version for 25H2.
-
At a glance
Windows 11 ProIntel® Core™ i5-520M8GB(integrated graphics) Intel HD Graphics- Operating System
- Windows 11 Pro
- Computer type
- Laptop
- Manufacturer/Model
- Dell Latitude E4310
- CPU
- Intel® Core™ i5-520M
- Motherboard
- 0T6M8G
- Memory
- 8GB
- Graphics card(s)
- (integrated graphics) Intel HD Graphics
- Screen Resolution
- 1366x768
- Hard Drives
- 500GB Crucial MX500 SSD
- Browser
- Firefox, Edge
- Antivirus
- Defender
- Other Info
- unsupported machine: Legacy bios, MBR, TPM 1.2, upgraded from W10 to W11 using W10/W11 hybrid install media workaround.
In-place upgrade to 22H2 using ISO and a workaround.
Feature Update to 23H2 by manually installing the Enablement Package.
In-place upgrade to 24H2 using hybrid 23H2/24H2 install media.
Upgraded to 25H2 by Enablement Package.
Also running Insider Experimental 263xx and 29xxx builds and Windows 10 as native boot .vhdx.
-
My SYSTEM THREE is a Dell Latitude 5410, i7-10610U, 32GB RAM, 512GB NVMe ssd, supported device running Windows 11 Pro.
My SYSTEM FOUR was a 2-in-1 convertible Lenovo Yoga 11e (1st gen) type 20DA, Celeron N2930, 8GB RAM, 256GB ssd. Unsupported device. This has now been sold. It has been replaced by my System Eight.
My SYSTEM FIVE is a Dell Latitude 3190 2-in-1, Pentium Silver N5030, 8GB RAM, 1TB NVMe ssd, supported device running Windows 11 Pro, plus Insider Beta, Experimental 263xx and 29xxx builds (and a few others) as a native boot .vhdx.
My SYSTEM SIX is a Dell Latitude 5550, Core Ultra 7 165H, 64GB RAM, 1TB NVMe SSD, supported device, Windows 11 Pro, Hyper-V host machine. Updated to 25H2 on 30th September 2025.
My SYSTEM SEVEN is a Lenovo Thinkpad T580, 1920x1080 touchscreen, Intel Core i7-8650U, 16GB RAM, 512GB NVMe SSD + 2nd 512GB NVMe SSD, a supported device for Windows 11. This is my current general purpose 'main machine'. The installed Windows 11 Home from my System One has been migrated to this machine. As its new home has an existing digital licence for Pro I've been able to upgrade the migrated OS from Home to Pro.
My SYSTEM EIGHT is a 2-in-1 convertible Lenovo Yoga 11e (5th gen) type 20LN, Celeron N4120, 8GB RAM, 512GB NVMe ssd, a supported device for Windows 11. Currently running Windows 11 Pro, plus Insider Beta, Experimental 263xx and 29xxx builds as native boot vhdx.






