If you run App Control (WDAC) with a managed installer, you’ll have hit this: during Autopilot Device Preparation, Win32, Microsoft Store and Enterprise App Catalog apps were skipped in the out-of-box experience. Not failed — skipped, deliberately, to avoid install conflicts and provisioning failures. Which meant the apps you most wanted on the device before handover were exactly the ones that didn’t land.
What changed
Intune now applies the managed installer policy during Device Preparation, before those app types install in OOBE. That’s the missing piece: with the managed installer trusted at provisioning time, App Control lets the apps through, and they install cleanly during setup instead of being deferred.
Why it matters if you run App Control
The whole point of a managed installer is that anything it deploys is implicitly trusted, so you don’t have to hand-author allow rules for every app. Extending that trust into the device-prep phase means your App Control story finally holds together end to end — the device comes out of provisioning with its apps present and your control policy intact, rather than you choosing between the two.
If you’re not running App Control, this is a non-event. If you are, it removes a genuinely annoying gap where secure provisioning and complete provisioning were pulling against each other.
Source: Microsoft Learn. Summarised independently — check the source for the latest detail.