Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy

A company uses Microsoft Intune to manage its Windows 11 devices. You need to ensure that all corporate-owned devices can only install applications from the Microsoft Store and other approved sources, preventing users from installing unapproved software. Which Intune configuration profile setting should you configure?

  1. ADelivery Optimization settings
  2. BWindows Update Rings
  3. CDevice restrictions for Windows
  4. DApplication Control policies
Show answer & explanation

Correct answer: C. Device restrictions for Windows

To restrict application installation sources on Windows 11 devices managed by Intune, you should configure Device restrictions for Windows. This profile allows you to control various aspects of the device, including app installations.

Why the other options are wrong

  • A. Delivery Optimization settings manage how updates and apps are downloaded and distributed, not where apps can be installed from.
  • B. Windows Update Rings manage when and how Windows updates are deployed, not application installation sources.
  • D. Application Control policies, like Windows Defender Application Control (WDAC), are more granular for defining what apps can run, but 'Device restrictions' directly controls installation sources.

Intune Device Restrictions (Windows)

A configuration profile in Microsoft Intune used to control various settings and features on Windows devices, including restricting application installation sources.

  • Manages device features and user experiences.
  • Can restrict app store access and installation of unapproved apps.
  • Applied to groups of users or devices.

Memory trick: Device restrictions lock down your app options.

More Manage devices and apps (55-60%) questions