18.10.17.1 (L1) Ensure 'Enable App Installer' is set to 'Disabled'

Information

This policy setting controls whether standard users have access to the Windows Package Manager. Windows Package Manager is a package manager solution that consists of a command line tool and set of services for installing applications on Microsoft Windows 10 and 11.

The recommended state for this setting is: Disabled

Windows Package Manager is a command line tool can be used to discover, install, upgrade, remove and configure applications, and it can be used as a distribution channel for software packages containing tools and applications. Users should not have access to these types of development tools.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Desktop App Installer\Enable App Installer

Note: This Group Policy path is provided by the Group Policy template DesktopAppInstaller.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates v1.0 (or newer).

Impact:

Users will not have access to the command line tool, winget to discover, install, upgrade, remove, configure, or distribute applications.

See Also

https://workbench.cisecurity.org/benchmarks/16514

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 11bbab3aae00730d6cc2e383052bbffc5a89dd642e5dbee347ec1448b02c20f2