Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Hard

A Microsoft 365 Endpoint Administrator is managing a fleet of corporate-owned Windows 11 devices. The security team has mandated that no users should be able to uninstall applications from the 'Apps & features' section in Windows Settings. Additionally, access to the command prompt and PowerShell must be blocked. Which Intune configuration profile type and specific settings should be used?

  1. AEndpoint security > Attack surface reduction rules > Block Win32 API calls
  2. BConfiguration profiles > Device features > Control Panel and Settings > Prevent access to 'Apps & features'
  3. CDevices > Compliance policies > Device Health > Require app integrity
  4. DConfiguration profiles > Device restrictions > General > Prevent access to command prompt and Device restrictions > Apps > Prevent app uninstall
Show answer & explanation

Correct answer: D. Configuration profiles > Device restrictions > General > Prevent access to command prompt and Device restrictions > Apps > Prevent app uninstall

Device restrictions profiles are designed to control various aspects of device functionality and user access. The settings 'Prevent access to command prompt' (under General) and 'Prevent app uninstall' (under Apps) are precisely what's needed to meet these security mandates.

Why the other options are wrong

  • A. Attack surface reduction rules are for preventing specific malicious behaviors, not for broadly blocking user access to built-in system tools or app uninstall functionality.
  • B. Device features typically configure things like AirPrint, VPN, Wi-Fi. 'Control Panel and Settings' is a sub-category but 'Prevent access to 'Apps & features'' is not the direct setting for blocking app uninstalls or system tools.
  • C. Compliance policies *report* on device state; they do not *enforce* or *configure* these types of device restrictions.

Intune Windows Device Restrictions

An Intune configuration profile type for Windows devices used to control various device functionalities, security settings, and user access to system features like app uninstallation or command-line tools.

  • Configured via Configuration Profiles > Device restrictions.
  • Manages user access to features like Control Panel, Settings, Command Prompt.
  • Can prevent application uninstallation.
  • Crucial for locking down corporate-owned devices.

Memory trick: Restrictions prevent unauthorized device actions.

More Manage devices and apps (55-60%) questions