18.9.4.2 Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'

Information

This setting manages non-Administrator users' ability to install Windows app packages.

The recommended state for this setting is: Enabled.

Rationale:

In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.

Impact:

Non-Administrator users will not be able to install Microsoft Store app packages, unless they are explicitly permitted by other policies. If a Microsoft Store app is required for legitimate use, an Administrator will need to perform the installation from an Administrator context.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:

Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Prevent non-admin users from installing packaged Windows apps

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template AppxPackageManager.admx/adml that is included with the Microsoft Windows 10 Release 2004 Administrative Templates (or newer).


Default Value:

Disabled. (All users will be able to initiate installation of Microsoft Store app packages.)

See Also

https://workbench.cisecurity.org/files/2992