Yes. Smart App Control block details are typically in Event Viewer, not necessarily in Protection History.
Use this path:
- Open Event Viewer.
- Go to Applications and Services Logs > Microsoft > Windows > CodeIntegrity > Operational.
- Look for these event IDs:
- 3077 = Smart App Control blocked a file in enforcement mode.
- 3076 = Smart App Control would have blocked a file in evaluation mode.
That log records which individual files were blocked or audited. For a blocked .dll, this is the main place to check.
Important detail: the Code Integrity log records blocked or audited files, but it does not explain an installer failure at the whole-app level. If the blocked item was part of an installer or app launch, review the 3076/3077 events to identify the exact file that was blocked.
There is also another relevant Event Viewer location for some App Control-related failures:
- Applications and Services Logs > Microsoft > Windows > AppLocker > MSI and Script
That second log is used for MSI installers, scripts, and COM objects. For the .dll case described, start with CodeIntegrity > Operational.
If the goal is only to confirm whether Smart App Control is active and in which mode, check:
- Settings > Windows Security > App and Browser Control
- On = enforcement mode
- Evaluation = evaluation mode
- Off = not running