Hello,
Based on your description, this does not sound like SVCHost arbitrarily launching Company Portal. What I would investigate first is whether the September 2026 update coincided with a change in Intune enrollment, Company Portal package servicing, or MSIX app update behavior.
Company Portal is delivered as an MSIX/UWP application. Windows can automatically trigger package maintenance, registration repair, entitlement checks, and update activities through AppX Deployment Service (AppXSVC), ClipSVC, Windows Store infrastructure, or Intune management agents running under SVCHost. Seeing SVCHost spawn processes related to Company Portal is therefore expected behavior by itself.
The abnormal part is the Company Portal UI becoming visible to users. In most environments, Company Portal should remain backgrounded during update or maintenance operations. When the window opens unexpectedly, it is often caused by an application registration repair, an Intune policy requiring user interaction, a Company Portal update/remediation cycle, or corruption in the user-specific AppX registration.
I would review the Event Viewer logs under:
Plain Text
Applications and Services Logs
└ Microsoft
└ Windows
├ AppXDeploymentServer
├ AppModel-Runtime
├ AAD
└ DeviceManagement-Enterprise-Diagnostics-Provider
and correlate the timestamps with the portal launch. Also inspect:
PowerShell
Get-AppxPackage Microsoft.CompanyPortal -AllUsers
to determine whether all affected devices are running the same Company Portal version.
If the behavior started for multiple users at roughly the same time, and especially if it appeared immediately after a Windows or Company Portal update, that usually points to a servicing or application issue rather than user actions, Scheduled Tasks, or malware. I would also review Intune assignment changes and check whether Company Portal was recently updated through Microsoft Store or the new Store update mechanisms.
To identify the exact trigger, Process Monitor or Process Explorer can be used to capture the process tree and determine which parent process is launching CompanyPortal.exe. The parent is frequently more revealing than SVCHost itself because it can expose whether the launch originated from AppXSVC, Intune Management Extension, Store updates, or another Windows component.
If you can provide the process tree, the exact Company Portal version, Windows build number, and whether the devices are Intune-managed or co-managed, I can help narrow down the specific component responsible for the launches.
I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!
Domic Vo.