Information
This setting manages non-Administrator users' ability to install Windows app packages.
The recommended state for this setting is: Enabled
Warning: If the
Self Service Password Reset (SSPR)
feature is used in Microsoft Entra ID, an exception to this recommendation is needed as it's known to interfere with SSPR.
In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.
Solution
To establish the recommended configuration, set the following Custom Configuration Policy to 1 :
Name: <Enter name>
Description: <Enter Description>
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/BlockNonAdminUserInstall
Data type: Integer
Value: 1
Impact:
Non-Administrator users will not be able to install Microsoft Store app packages, unless they are explicitly permitted by other policies. If a Microsoft Store app is required for legitimate use, an Administrator will need to perform the installation from an Administrator context.
This setting can prevent standard users (without Administrator access) from launching Office 365 (O365) applications, displaying the error:
'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.'