Repository navigation
Azure CLI 2.89.1 installed by az upgrade is blocked by Azure Local WDAC policy #33919
Description
Activity
- addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on Aug 18, 2026 azure-client-tools-bot-prd commented
on Aug 18, 2026 More actionsHi Jackie & Leon & Jack (@Leonschnucki),
2.85.0 is not the latest Azure CLI(2.89.1).
If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.
- addedcustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.Auto-AssignAuto assign by botAuto assign by botUpgradeaz upgradeaz upgradeAzure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Aug 18, 2026 Thank you for opening this issue, we will look into it.
x-engineering-agent commented
on Aug 18, 2026 ContributorMore actionsBug Analysis
Reported issue: On an Azure Local (Azure Stack HCI) cluster node with an enforced Device Guard / WDAC policy,
az upgrade --yesdownloads and installs the official Microsoft-signed Azure CLI 2.89.1 MSI. After installation, the bundledpython.exeunder
C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\python.exe
is blocked by the node's enforced WDAC policy (Windows Code Integrity Event IDs 3033/3077 — "did not meet the Enterprise signing level requirements / violated code integrity policy"). This renders the CLI completely unusable until the node is rolled back to 2.85.0.Expected behavior:
az upgradeshould not silently complete an MSI installation that leaves the CLI non-functional. At minimum,az upgrade(implemented inazure-cli-core's self-update / upgrade command flow) should be hardened so that:- The upgrade path fails loudly / rolls back automatically if the newly installed CLI cannot be invoked afterward (e.g. verify
az versionsucceeds post-install before declaring success), and/or - On Windows, if the MSI install or the post-install verification step raises an OS-level "blocked by your organization's policy" style error (e.g. WinError 225 / ERROR_VIRUS_INFECTED, or WDAC/Device Guard-specific failures),
az upgradeshould surface a clear, actionable error message rather than leaving a broken installation in place.
Where to look: the self-update / MSI-invocation logic in
src/azure-cli-core/azure/cli/core/_session.py,src/azure-cli-core/azure/cli/core/util.py, and theaz upgradecommand implementation (likelysrc/azure-cli-core/azure/cli/core/commands/upgrade.pyor similar — search for where the MSI is downloaded/executed and where post-install verification, if any, happens).Suggested fix approach:
- After the MSI install step completes, run a lightweight post-install check (e.g. invoke the newly installed
python.exe/CLI with a trivial command) and detect failure. - If the post-install check fails, keep/restore the previous working installation if feasible, and print a clear error explaining that the new build could not be verified (mentioning WDAC/Device Guard/AppLocker-style policy blocks as a possible cause), directing the user to
https://learn.microsoft.com/cli/azure/update-azure-clifor manual recovery. - Add regression coverage (unit test) around the upgrade success/failure detection path.
Use this EXACT PR title:
[Core] Fix #33919:az upgrade: Skip self-upgrading to a build whose bundled python.exe fails WDAC/Device Guard validationPR title & description format (required)
This repo enforces a PR format (guide). Please author the PR exactly as follows or CI's Check the Format of Pull Request Title and Content will fail.
Use this EXACT PR title (copy verbatim, do not reword):
[Core] Fix #33919: `az upgrade`: Skip self-upgrading to a build whose bundled python.exe fails WDAC/Device Guard validationKeep the backticks around the command and the
Fix #33919:prefix. You may only adjust the wording after the command (the final summary) if the fix changes; the[Core]prefix, issue link, and backticked command must stay.Description — follow the PR template and fill in:
- Link the issue — start the Description with a closing keyword so the PR auto-links and closes it:
Fixes #33919. - Related command — the
az ...command this affects. - Description (mandatory) — why the bug happens, what you changed, and the resulting behavior.
- Testing Guide — example command(s) showing the fix works.
- History Notes — leave the title to drive the history note, or add extra lines in the same format (component in brackets + the command in backticks), e.g.
[Core] `az <command>`: <note>. - Keep the template checklist and tick the items you've satisfied.
Posted by agent-assist (autonomous bug-fix pipeline).
- The upgrade path fails loudly / rolls back automatically if the newly installed CLI cannot be invoked afterward (e.g. verify
- linked a pull request that will close this issue[Util] Fix #33919: `az upgrade`: Warn about Device Guard / WDAC blocking after MSI install #33920
on Aug 18, 2026 Leonschnucki commented
on Aug 18, 2026 AuthorMore actionsHi Leon & Jack (@Leonschnucki),
2.85.0 is not the latest Azure CLI(2.89.1).
If you haven't already attempted to do so, please upgrade to the latest Azure CLI version by following https://learn.microsoft.com/en-us/cli/azure/update-azure-cli.
**The suggestion to upgrade to Azure CLI 2.89.1 is exactly the issue being reported.
Azure CLI 2.85.0 is shown in the environment summary because 2.89.1 had to be rolled back after the upgrade made Azure CLI unusable.
The reported reproduction is:
2.85.0 working →az upgrade --yesinstalls 2.89.1 → Azure Local WDAC blocks the bundledpython.exe→ Azure CLI no longer starts → rollback to 2.85.0 restores functionality.Therefore it is not possible to provide
az versionoutput from 2.89.1 after the upgrade, because WDAC prevents Azure CLI itself from starting.**- removedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.
on Aug 18, 2026 - addedbugThis issue requires a change to an existing behavior in the product in order to be resolved.This issue requires a change to an existing behavior in the product in order to be resolved.and removedquestionThe issue doesn't require a change to the product in order to be resolved. Most issues start as thatThe issue doesn't require a change to the product in order to be resolved. Most issues start as that
on Aug 18, 2026 microsoft-github-policy-service commented
on Aug 18, 2026 ContributorMore actions🔔 Routing this issue to @Azure/act-platform-engineering-squad.
Describe the bug
On an Azure Local cluster node,
az upgrade --yesoffers and installs Azure CLI 2.89.1 using the official Microsoft MSI.Before the upgrade, Azure CLI 2.85.0 works normally on the node.
After the MSI upgrade completes, Azure CLI can no longer be started because the bundled:
C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\python.exeis blocked by the Azure Local node's enforced Device Guard / WDAC policy.
Windows Code Integrity logs Event IDs 3033 and 3077 stating that the new
python.exedoes not meet the Enterprise signing level requirements / violates the active code integrity policy.Rolling Azure CLI back from 2.89.1 to the Microsoft-signed 2.85.0 MSI immediately restores Azure CLI functionality without making any WDAC policy changes.
Environment before upgrade:
C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\C:\CloudContent\AzCliExtensions\Reproduction:
az version.az upgrade.az upgrade --yes.az version.python.exeand Azure CLI is unusable.Expected behavior:
az upgradeshould not offer and install an Azure CLI version that cannot execute under the enforced WDAC policy of an Azure Local node.Either:
az upgradeshould detect this environment and refuse/avoid an incompatible upgrade, orActual behavior:
The Microsoft-provided self-upgrade successfully installs Azure CLI 2.89.1, but the resulting Azure CLI is unusable because its bundled
python.exeis blocked by WDAC.Rollback test:
Azure CLI 2.89.1 was uninstalled and the Microsoft-signed Azure CLI 2.85.0 MSI was reinstalled.
az versionworked again immediately with no WDAC policy changes.Other Azure Local nodes were intentionally not upgraded after reproducing the problem on the first node.
Related command
az upgradeaz upgrade --yesaz versionErrors
After upgrading from Azure CLI 2.85.0 to 2.89.1:
'C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\python.exe' was blocked by your organization's Device Guard policy.
Contact your support person for more info.
Windows Code Integrity Event ID 3077:
Code Integrity determined that a process
(\Device\HarddiskVolume4\Windows\System32\cmd.exe)
attempted to load
\Device\HarddiskVolume4\Program Files (x86)\Microsoft SDKs\Azure\CLI2\python.exe
that did not meet the Enterprise signing level requirements or violated code integrity policy.
Windows Code Integrity Event ID 3033:
Code Integrity determined that a process
(\Device\HarddiskVolume4\Windows\System32\cmd.exe)
attempted to load
\Device\HarddiskVolume4\Program Files (x86)\Microsoft SDKs\Azure\CLI2\python.exe
that did not meet the Enterprise signing level requirements.
The same node works again immediately after rolling Azure CLI back to 2.85.0.
Issue script & Debug output
Reproduction script: