18.10.4.2 (L1) Ensure 'Not allow per-user unsigned packages to install by default (requires explicitly allow per install)' is set to 'Enabled'

Information

This setting manages a user's ability to install unsigned Windows App packages.

The recommended state for this setting is: Enabled

Note: Unsigned Windows App packages will require an explicit allow per install if this setting is disabled.

In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\App Package Deployment\Not allow per-user unsigned packages to install by default (requires explicitly allow per install)

Note: This Group Policy path is provided by the Group Policy template AppxPackageManager.admx/adml that is included with the Microsoft Windows 11 Release 24H2 Administrative Templates (or newer).

Impact:

Standard users will not be able to install unsigned packaged Microsoft Store Apps, unless they are explicitly permitted by other policies.

See Also

https://workbench.cisecurity.org/benchmarks/21318

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|4.3

Plugin: Windows

Control ID: 0e3770f390af998f2678cb233e73260ac983351742fa4d80b8ccc8cf00438b17