CiTool.exe --remove-policy "{[PII removed]}" returns 0x80070002

UguuDoki 20 Reputation points
2026-10-05T20:19:56.5366667+00:00

Windows 11 25H2

July 2026 or later cumulative update installed.

Windows Driver Policy = Evaluation mode.

Audit policy {[PII removed]} is Active.

Enforcement policy {[PII removed]} physically exists under CiPolicies\Reserved.

CiTool -lp does not enumerate {[PII removed]}.

Microsoft's documented command: CiTool.exe --remove-policy "{[PII removed]}" returns 0x80070002.

No EFI copies of either policy exist.

Have not manually modified/deleted the policy files.

As CiTool returns ERROR_FILE_NOT_FOUND when the corresponding .cip exists in Reserved, is CiTool --remove-policy not expected to remove an enforcement policy that is in CiPolicies\Reserved while the device is still in evaluation mode? If yes, will command CiTool.exe --remove-policy "{[PII removed]}" be a workable alternative?

Windows for home | Windows 11 | Devices and drivers
0 comments No comments

Answer accepted by question author
Kai-H 28,235 Reputation points Microsoft External Staff Moderator
2026-10-06T09:23:26.35+00:00

(Please note that our forum is a public platform, and we will modify your question to hide your personal information in the description. Kindly ensure that you hide any personal or organizational information the next time you post an error or other details to protect personal data.)

Hi, UguuDoki

Thanks for providing the exact policy IDs and locations. I couldn’t verify that 0x80070002 is expected for an enforcement policy in Reserved, and the documented removal procedure does not confirm audit-policy removal as an alternative.

Here are some suggestions you can try:

For now, I would leave both policy files untouched rather than delete or move the Reserved file, or substitute the audit GUID. The documented command targets {8F9CXXXXXXXXX}, even on devices with the July 2026 update or later.

Since you already meet that update requirement, I recommend reporting this specific mismatch through Feedback Hub. Press Win + F, select Security and Privacy > App Control, and include your Windows build, installed cumulative update, CiTool -lp -json output, file location, and exact error. That category is provided for feedback on this feature.

Evaluation mode audits drivers without blocking them. However, that does not establish that removing the audit policy would permanently prevent enforcement, so I wouldn’t present that command as a confirmed fix.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.