Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator needs to prevent users on corporate-owned macOS devices from installing applications from sources other than the Apple App Store. Which Intune device restriction setting should be configured?
- ABlock app installation from identified developers
- BDisable Gatekeeper
- CRequire signed apps
- DAllow installing apps from App Store only
Show answer & explanationAnswer & explanation
Correct answer: D. Allow installing apps from App Store only
To restrict macOS app installations solely to the Apple App Store, the 'Allow installing apps from App Store only' setting within a macOS device restrictions profile is the direct and correct configuration.
Why the other options are wrong
- A. This blocks specific developers but doesn't restrict to the App Store exclusively.
- B. Disabling Gatekeeper would reduce security and allow installations from any source, which is the opposite of the requirement.
- C. Requiring signed apps still allows installations from identified developers or enterprise distribution, not just the App Store.
Intune macOS App Source Restriction
A device restriction setting in Intune for macOS that controls which sources users are allowed to install applications from.
- Can enforce installation only from the Apple App Store.
- Leverages macOS Gatekeeper settings.
- Enhances security by limiting software origins.
Memory trick: App Store Only: The Apple-approved gatekeeper.