Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to prevent users on corporate-owned macOS devices from installing applications from sources other than the Apple App Store. Which Intune device restriction setting should be configured?

  1. ABlock app installation from identified developers
  2. BDisable Gatekeeper
  3. CRequire signed apps
  4. DAllow installing apps from App Store only
Show answer & explanation

Correct answer: D. Allow installing apps from App Store only

To restrict macOS app installations solely to the Apple App Store, the 'Allow installing apps from App Store only' setting within a macOS device restrictions profile is the direct and correct configuration.

Why the other options are wrong

  • A. This blocks specific developers but doesn't restrict to the App Store exclusively.
  • B. Disabling Gatekeeper would reduce security and allow installations from any source, which is the opposite of the requirement.
  • C. Requiring signed apps still allows installations from identified developers or enterprise distribution, not just the App Store.

Intune macOS App Source Restriction

A device restriction setting in Intune for macOS that controls which sources users are allowed to install applications from.

  • Can enforce installation only from the Apple App Store.
  • Leverages macOS Gatekeeper settings.
  • Enhances security by limiting software origins.

Memory trick: App Store Only: The Apple-approved gatekeeper.

More Manage devices and apps (55-60%) questions