Disable Microsoft Windows Public Store with MDM on InTune

MDM are becoming the future of Group Policy Objects (GPO). This allows admins, to deploy company policies to computers all over the world. Without the need to access a network through VPN or by connecting on site for the users.

I wondered how to disable the public windows store with intune, but let the users use the private company store (Windows Business Store).

Here is how.

First, you need to create a new MDM :

  1. Add a name for your MDM
  2. Add a description
  3. Platform : Windows 10 and later
  4. Profile type : Custom
  5. Name : RequireOnlyPrivateStore
  6. Description : Custom OMA-URI to allow only private store
  7. OMA-URI : ./User/Vendor/MSFT/Policy/Config/ApplicationManagement/RequirePrivateStoreOnly
  8. Data Type : Integer
  9. Value : 1
  10. Save and Assign the policy to all user or a selected groups.

For all users, Public store will disappear and let only the private store to be shown. This allows the admins to manage which apps the users can install on they computers.

Information Technology addict since Windows 3.11, I specialised myself on Cloud technologies. I did not forget my development skills in Scripting (Powershell) and Web (PHP,CSS,HTML,Javascript). I love sharing my knowledge and help companies in their cloud journey. Feel free to contact me.

2 Replies to “Disable Microsoft Windows Public Store with MDM on InTune

  1. Good morning, Karl,
    Do you know how to remove the toast notification icon next to the clock? And block user-installed programs like Google Chrome that do not require administrator privileges. And how to enable CTRL+ALT+DEL in the interactive logon. Are there also AMO-URI for this? Thank you for your help.

    1. Hi Guillaume,

      That’s a lot of interesting questions! 🙂
      You can enable interactive logon with OMA-URI ./Vendor/MSFT/Policy/Config/LocalPoliciesSecurityOptions/InteractiveLogon_DoNotRequireCTRLALTDEL
      You can allow trusted apps with the OMA-URI ApplicationManagement/AllowTrustedApps
      You can’t remove toast notification icon because its where the user enable wifi, bluetooth and access some parameters but you can disable notifications tile with Notifications/DisallowTileNotifications

      Hope this helps you.

      Regards,
      Karl

Leave a Reply

Your email address will not be published. Required fields are marked *

twelve + 7 =

*