Information
This setting manages a user's ability to install unsigned Windows App packages.
The recommended state for this setting is: Enabled
Note: Unsigned Windows App packages will require an explicit allow per install if this setting is disabled.
In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.
Solution
To establish the recommended configuration via GP, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Not allow per-user unsigned packages to install by default (requires explicitly allow per install)
Note: This Group Policy path is provided by the Group Policy template AppxPackageManager.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).
Impact:
Standard users will not be able to install unsigned packaged Microsoft Store Apps, unless they are explicitly permitted by other policies.