Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A Microsoft 365 Endpoint Administrator wants to prevent users on corporate-owned macOS devices from installing applications from outside the App Store or identified developers. The goal is to enhance security by restricting software sources. Which Intune configuration profile setting should be used?
- ASystem security > Require an alphanumeric password
- BGeneral > Block screen capture
- CApp Store, Doc viewing, Gaming, and Media content > Require a password for all purchases
- DRestrictions > Allow installing apps from identified developers only
Show answer & explanationAnswer & explanation
Correct answer: D. Restrictions > Allow installing apps from identified developers only
To restrict app installations on macOS to only those from the App Store and identified developers, the 'Allow installing apps from identified developers only' setting within a device restrictions profile is the correct choice. This directly addresses the security requirement.
Why the other options are wrong
- A. Requiring an alphanumeric password is a device security setting for user authentication, not app source restriction.
- B. Blocking screen capture is a security measure but unrelated to app installation sources.
- C. This setting controls purchase behavior within the App Store, not the source of app installations.
Intune macOS App Source Restriction
Using an Intune device restrictions profile to control which sources macOS devices can install applications from, such as limiting to the App Store and identified developers.
- Enhances security by preventing unauthorized software installations.
- Configured within a device restriction profile for macOS.
- Options typically include 'App Store', 'App Store and identified developers', or 'Anywhere'.
Memory trick: Restrict 'Sources' for security.