55.4 (L1) Ensure 'Block Non Admin User Install' is set to 'Allow'

Information

This setting manages non-Administrator users' ability to install Windows app packages.

The recommended state for this setting is: Allow

Warning: If the

Self Service Password Reset (SSPR)

feature is used in Microsoft Entra ID, an exception to this recommendation is needed as it's known to interfere with SSPR.

In a corporate managed environment, application installations should be managed centrally by IT staff, not by end users.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Allow

Microsoft App Store\Block Non Admin User Install

Impact:

Non-Administrator users will not be able to install Microsoft Store app packages, unless they are explicitly permitted by other policies. If a Microsoft Store app is required for legitimate use, an Administrator will need to perform the installation from an Administrator context.

This setting can prevent standard users (without Administrator access) from launching Office 365 (O365) applications, displaying the error:

'Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.'

See Also

https://workbench.cisecurity.org/benchmarks/21767

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), 800-53|CM-10, CSCv7|4.3

Plugin: Windows

Control ID: 61a5d6526a34aece931c78ca6b861539f2812b31ed82614109f4b6fe574916f1