Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A company uses Microsoft Intune to manage its corporate-owned iOS devices. Due to security concerns, the IT department wants to prevent users from installing applications from any source other than the Apple App Store. Which Intune device restriction setting should be configured?

  1. ABlock installing apps from App Store
  2. BBlock untrusted app developers
  3. CBlock enterprise app trust
  4. DRequire iTunes Store password for all purchases
Show answer & explanation

Correct answer: B. Block untrusted app developers

The 'Block untrusted app developers' setting specifically prevents users from installing and launching apps that are not from the Apple App Store, including those signed with enterprise certificates or downloaded from the web, ensuring only App Store apps can be used.

Why the other options are wrong

  • A. This setting would prevent users from installing *any* apps from the App Store, which is the opposite of the requirement.
  • C. Blocking enterprise app trust is a related concept but 'Block untrusted app developers' is the direct setting that prevents installation of apps from non-App Store sources.
  • D. This setting only controls password prompts for purchases, not the source of app installation.

Intune iOS App Source Restriction

An Intune device restriction setting for iOS that controls whether users can install applications from sources other than the official Apple App Store.

  • Enhances device security.
  • Prevents sideloading of apps.
  • Ensures apps are vetted by Apple.

Memory trick: Only trusted developers can build in my walled App Garden.

More Manage devices and apps (55-60%) questions