An extension of Azure for running apps in an on-premises environment and delivering Azure services in a datacenter.
Hello Uniting Country SA,
Greetings! Thanks for raising this question in the Q&A forum.
Excellent documentation of the issue this level of detail makes it much easier to get to the root cause quickly. You have clearly done thorough preliminary work and the remaining issue is specifically isolated to the Test-WdacEnablement check. Let me explain exactly what's happening and walk you through the full remediation.
The error "You cannot call a method on a null-valued expression" in the Test-WdacEnablement step occurs because the AzStackHci.EnvironmentChecker module's WDAC validation logic queries the root\Microsoft\Windows\CI WMI namespace (Code Integrity), not the root\Microsoft\Windows\DeviceGuard namespace you already verified. On your nodes, the root\Microsoft\Windows\CI namespace either doesn't exist, returns a null object, or the CIM class it expects (MSFT_CIRegistryPolicy) is not registered — causing the null reference error in the module's internal script. This is a known behavior gap in certain preview builds of the EnvironmentChecker module and can also occur when the Code Integrity WMI provider is not properly registered on the node.
Here's your step-by-step remediation:
Run the following on each node in an elevated PowerShell session to confirm whether the root\Microsoft\Windows\CI namespace is actually accessible:
Get-CimInstance -Namespace root\Microsoft\Windows\CI -ClassName MSFT_CIRegistryPolicy
If this returns a "namespace not found" or "invalid class" error — that is the confirmed root cause. If it returns results, move to Step 3.
If the CI namespace is missing or the class is not registered, rebuild the Code Integrity WMI provider by running the following on each node:
cd C:\Windows\System32\wbem
.\mofcomp.exe CodeIntegrity.mof
Then restart each node:
Restart-Computer
After the restart, re-run the Get-CimInstance command from Step 1 to confirm the namespace is now accessible before proceeding.
Verify the WDAC/Code Integrity Windows features are installed on each node. Run this on both nodes:
Get-WindowsFeature -Name Windows-Defender-ApplicationControl, DeviceGuard
If either shows as Not Installed, install them:
Install-WindowsFeature -Name Windows-Defender-ApplicationControl, DeviceGuard -IncludeAllSubFeature
Restart-Computer
Update the AzStackHci.EnvironmentChecker module. You are currently on version 10.2509.0.2010 which is a Preview build. Previous versions of the Environment Checker may cause conflicts and null-method errors, and it is recommended to remove any previously installed versions before installing the latest. Run the following on each node:
Remove-Module AzStackHci.EnvironmentChecker -Force
Uninstall-Module AzStackHci.EnvironmentChecker -AllVersions -Force
Install-Module AzStackHci.EnvironmentChecker -Force
Then confirm the installed version:
Get-Module AzStackHci.EnvironmentChecker -ListAvailable | Select Name, Version
Re-run the upgrade validation after completing Steps 1 through 4:
Invoke-AzStackHciUpgradeValidation
The Test-WdacEnablement check should now pass cleanly.
If the null-method error persists after all the above steps, this is likely a confirmed defect in the current module build. In that case, do the following:
Capture the full validation output to a file for support:
Invoke-AzStackHciUpgradeValidation -PassThru | Export-Clixml -Path C:\Logs\ValidationOutput.xml
Then raise a Microsoft Support ticket via the Azure Portal with the following details:
- Module version:
AzStackHci.EnvironmentChecker 10.2509.0.2010(and the version after your update)- Failing test:
Test-WdacEnablement- Error: "You cannot call a method on a null-valued expression"
- Cluster: 2-node Dell physical, Azure Stack HCI 23H2, OS Build 25398
- Attach the exported
ValidationOutput.xmllog- Request a hotfixed EnvironmentChecker build or a waiver to bypass the
Test-WdacEnablementcheck
- Request a hotfixed EnvironmentChecker build or a waiver to bypass the
- Attach the exported
- Cluster: 2-node Dell physical, Azure Stack HCI 23H2, OS Build 25398
- Error: "You cannot call a method on a null-valued expression"
- Failing test:
- Supported upgrade path reminder once validation passes:
- Run
Invoke-AzStackHciUpgradeValidationcleanly — all checks green- Apply the 23H2 → 24H2 OS upgrade via Windows Update, Windows Admin Center, or ISO
- Use CAU (
Invoke-CauScan/Invoke-CauRun) to patch cluster nodes in a rolling fashion- Apply the 24H2 solution update using
Invoke-AzStackHciUpdate
- Apply the 24H2 solution update using
- Use CAU (
- Apply the 23H2 → 24H2 OS upgrade via Windows Update, Windows Admin Center, or ISO
- Run
As a helpful tip while waiting for Microsoft Support to respond if needed, you can check whether any Group Policy or third-party security tools on your nodes are enforcing WDAC policies that might be interfering with the CI namespace registration. Run Get-CIPolicy on each node to confirm whether any Code Integrity policies are currently active and enforced.
If this answer helps you kindly accept the answer which will help others who have similar questions.
Best Regards,
Jerald Felix.