Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Easy
A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune to manage corporate-owned Android Enterprise devices. The administrator needs to ensure that users are prevented from installing apps from unknown sources, but still allows app installation from the Google Play Store. Which Intune device restriction setting should be configured?
- ABlock apps from unknown sources
- BAllow untrusted apps
- CRequire Google Play Protect
- DDisable app sideloading
Show answer & explanationAnswer & explanation
Correct answer: A. Block apps from unknown sources
Blocking apps from unknown sources prevents installation from non-Play Store sources while allowing the Play Store. The other options either permit untrusted apps or are related to general security/sideloading, but not specifically the 'unknown sources' setting that allows Play Store.
Why the other options are wrong
- B. This setting would permit app installation from unknown sources, which is the opposite of the requirement.
- C. This setting ensures Google Play Protect is active for security but doesn't directly control unknown sources.
- D. While related, 'Disable app sideloading' is a broader term; 'Block apps from unknown sources' is the specific Intune setting for this scenario.
Android Enterprise Unknown Sources Restriction
A Microsoft Intune device restriction setting for Android Enterprise that controls whether users can install applications from sources other than official app stores.
- Prevents installation of apps from non-Google Play Store sources.
- Does not restrict app installation from the Google Play Store.
- Enhances device security by limiting potentially malicious app installations.
Memory trick: Guard the gate, but let the official store deliver.