Hello Jamie,
Thank you for posting your question on Microsoft Windows Forum!
Thank you for the detailed investigation. Based on the information you've provided, you've already ruled out many of the common causes, and I agree that this does not appear to be a standard Intune policy issue.
What stands out is that:
- The issue only occurs on managed devices.
- Re-imaging temporarily resolves the problem.
- The issue affects the Windows common Save As dialog across multiple applications.
- No Intune-delivered configuration appears to be enforcing the behavior.
- The problem started around the same timeframe across managed devices.
Given those findings, I would focus on identifying what changes in the Windows security posture after enrollment, rather than looking for a specific Intune configuration profile.
Recommended Next Steps
Step 1: Test with a clean managed device
If possible, enroll a freshly installed test device into Intune without deploying any business applications.
Immediate test:
Notepad → Save As
Word → Save As
File Explorer → Browse
If the issue appears before any applications are installed, this helps isolate the problem to the Windows management/security stack.
Step 2: Compare WDAC and Code Integrity status
On both a working personal device and an affected managed device, run:
Get-CimInstance -ClassName Win32_DeviceGuard
and
Get-SystemDriver -NoFlighting
Review whether Device Guard, Code Integrity, Smart App Control, or WDAC-related settings differ between the two devices.
Step 3: Collect Code Integrity logs
Open:
Event Viewer
- Applications and Services Logs
- Microsoft
- Windows
- CodeIntegrity
- Operational
Look for any warnings or errors that occur when reproducing the Save As hang.
Even if Explorer does not crash, Code Integrity may log blocked or delayed operations.
Step 4: Capture a process dump during the hang
Since the application freezes rather than crashes, a dump may reveal where the thread is waiting.
Using Process Explorer or Task Manager:
Explorer.exe
- Create Dump File
while the Save As dialog is hung.
This is often one of the most useful artifacts for identifying shell extension, driver, or Code Integrity interactions.
Step 5: Check shell extensions and file system filter drivers
The fact that the issue occurs during Save As operations suggests that Explorer may be waiting on:
- File system filter drivers
- Security products
- DLP solutions
- Classification/tagging agents
- Third-party shell extensions
Run:
fltmc
and compare the filter drivers loaded on:
- A working unmanaged device
- An affected managed device
This frequently exposes security components interacting with file operations.
My Observation
Since you've already determined that Intune itself is not deploying the policy and Microsoft Support has suggested escalation to the Windows team, the most likely path forward is still a Windows platform investigation, particularly around:
Code Integrity
WDAC
Smart App Control
File Dialog / Explorer
Filter Drivers
The dump analysis and Code Integrity logs would probably provide the strongest evidence for the Windows Desktop and Shell Experience team.
Additional Information
Could you share:
- Whether fltmc shows any additional filter drivers on affected devices?
- Whether a Process Dump has been collected during the hang?
- Are Defender for Endpoint, DLP, or third-party endpoint/security products installed?
For additional reference:
Hope the response provided some helpful insight. If you find this answer useful, please feel free to click on Accept Answer and consider upvoting it so I know it addressed your concern.