Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The organization requires that users are prevented from installing apps from the public App Store to ensure only approved applications are used. Which Intune configuration profile setting should the administrator use to achieve this?

  1. AUnder 'Device restrictions', set 'Require iTunes Store password' to 'Yes'.
  2. BUnder 'App protection policies', configure 'Require PIN for app access'.
  3. CUnder 'Device features', enable 'Managed Home Screen'.
  4. DUnder 'Device restrictions', set 'App Store, Doc, Music, TV, News, and Books' to 'Block'.
Show answer & explanation

Correct answer: D. Under 'Device restrictions', set 'App Store, Doc, Music, TV, News, and Books' to 'Block'.

To prevent users from installing apps from the public App Store on iOS devices, the 'App Store, Doc, Music, TV, News, and Books' setting within a device restrictions profile should be blocked. This effectively disables access to the App Store.

Why the other options are wrong

  • A. Requiring an iTunes Store password does not prevent app installations; it only adds a security layer to purchases.
  • B. App protection policies control data within apps and app access, not the ability to install new apps from the App Store.
  • C. Managed Home Screen is for dedicated devices (kiosk mode) and replaces the entire home screen, which is not the primary goal here.

iOS App Store Restriction

An Intune device restriction setting for iOS/iPadOS that blocks access to the App Store, preventing users from installing new applications.

  • Located within a 'Device restrictions' configuration profile.
  • Also restricts access to other Apple content services.
  • Used to enforce a curated app environment on corporate devices.

Memory trick: To block the App Store, think of a 'red light' for the shopping cart.

More Manage devices and apps (55-60%) questions