Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator is configuring a new set of corporate-owned iOS devices. The company policy requires that all applications installed on these devices must be reviewed and approved by IT. Users should not be able to install apps from the public Apple App Store directly. Which Intune policy setting should be configured?
- AAllow installing apps from the App Store
- BBlock unmanaged app installation
- CRestrict app usage based on content rating
- DRequire managed apps
Show answer & explanationAnswer & explanation
Correct answer: A. Allow installing apps from the App Store
To prevent users from installing apps from the public Apple App Store, the 'Allow installing apps from the App Store' setting in an iOS/iPadOS device restriction profile should be set to 'Block'. This ensures only IT-approved apps (deployed via Intune) can be installed.
Why the other options are wrong
- B. There is no direct setting named 'Block unmanaged app installation' that specifically targets the App Store as the source; the 'Allow installing apps from the App Store' setting is the direct control.
- C. Content rating restrictions limit app visibility based on age ratings, not the source of installation.
- D. 'Require managed apps' is related to managing existing apps, not preventing installation from the App Store.
iOS App Store Restriction
Intune device restriction to prevent users from installing applications directly from the public Apple App Store on corporate-owned iOS devices.
- Configured in iOS/iPadOS device restriction profiles
- Setting is 'Allow installing apps from the App Store'
- Set to 'Block' to prevent public App Store installations
Memory trick: Keep Apps in Line, Block the Public Store Sign.