Manage approved apps for Windows devices with App Control for Business policy and Managed Installers for Microsoft Intune

Every day new malicious files and apps appear in the wild. When run on devices in your organization they present a risk, which can be hard to manage or prevent. To help prevent undesired apps from running on your managed Windows devices, you can use Microsoft Intune App Control for Business policies.

Intune's App Control for Business policies are part of endpoint security and use the Windows ApplicationControl CSP to manage allowed apps on Windows devices.

Also available through App Control for Business policy, you can use a managed installer policy to add the Intune management extension to your Tenant as a managed installer. With this extension as a managed installer, the apps you deploy through Intune are automatically tagged by the installer. Tagged apps can be identified by your App Control for Business policies as safe apps that can be allowed to run on your devices.

The information in this article can help you:

For related information, see Windows Defender Application Control in the Windows Security documentation.

App Control for Business policy vs Application control profiles: Intune App Control for Business policies use the ApplicationControl CSP. Intune's Attack surface reduction policies use the AppLocker CSP for their Application control profiles. Windows introduced the ApplicationControl CSP to replace the AppLocker CSP. Windows continues to support the AppLocker CSP but no longer adds new features to it. Instead, development continues through the ApplicationControl CSP.

Prerequisites

Devices

The following devices are supported for App Control for Business policies when they are enrolled with Intune: