18.10.3.2 (L1) Ensure 'Prevent non-admin users from installing packaged Windows apps' is set to 'Enabled'

Information

This setting manages non-Administrator users' ability to install Windows app packages.

The recommended state for this setting is: Enabled

In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Prevent non-admin users from installing packaged Windows apps

Note: This Group Policy path is provided by the Group Policy template AppxPackageManager.admx/adml that is included with the Microsoft Windows 10 Release 2004 Administrative Templates (or newer).

Impact:

Non-Administrator users will not be able to install Microsoft Store app packages, unless they are explicitly permitted by other policies. If a Microsoft Store app is required for legitimate use, an Administrator will need to perform the installation from an Administrator context.

This setting can prevent standard users (without Administrator access) from launching Office 365 (O365) applications, displaying the error:

'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.'

See Also

https://workbench.cisecurity.org/benchmarks/17610

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|4.3

Plugin: Windows

Control ID: 9b77240eeb1aa1dfff5cf7cbe07a4f48c81a48a4ef17016d91a847f4fb878294