18.10.65.2 (L1) Ensure 'Only display the private store within the Microsoft Store' is set to 'Enabled'

Information

This policy setting denies access to the retail catalog in the Microsoft Store, but displays the private store.

The recommended state for this setting is: Enabled

Allowing the private store will allow an organization to control the apps that users have access to add to a system. This will help ensure that unapproved malicious apps are not running on a system.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Store\Only display the private store within the Microsoft Store

Note: This Group Policy path is provided by the Group Policy template WindowsStore.admx/adml that is included with the Microsoft Windows 10 Release 1607 Administrative Templates (or newer).

Note #2: In older Microsoft Windows Administrative Templates, this setting was initially named

Only display the private store within the Windows Store app

, but it was renamed starting with the Windows 10 Release 1803 Administrative Templates.

Impact:

Users will not be able to view the retail catalog in the Microsoft Store, but they will be able to view apps in the private store.

See Also

https://workbench.cisecurity.org/benchmarks/16515

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|9.2

Plugin: Windows

Control ID: da437c2a10a58018301bb65d8be6c069fbf087363a2d486a6157abe242593de2