(Please note that our forum is a public platform, and we will modify your question to hide your personal information in the description. Kindly ensure that you hide any personal or organizational information the next time you post an error or other details to protect personal data.)
Hi, UguuDoki
Thanks for providing the exact policy IDs and locations. I couldn’t verify that 0x80070002 is expected for an enforcement policy in Reserved, and the documented removal procedure does not confirm audit-policy removal as an alternative.
Here are some suggestions you can try:
For now, I would leave both policy files untouched rather than delete or move the Reserved file, or substitute the audit GUID. The documented command targets {8F9CXXXXXXXXX}, even on devices with the July 2026 update or later.
Since you already meet that update requirement, I recommend reporting this specific mismatch through Feedback Hub. Press Win + F, select Security and Privacy > App Control, and include your Windows build, installed cumulative update, CiTool -lp -json output, file location, and exact error. That category is provided for feedback on this feature.
Evaluation mode audits drivers without blocking them. However, that does not establish that removing the audit policy would permanently prevent enforcement, so I wouldn’t present that command as a confirmed fix.