Intune Policy to Block Installation of .msi, .exe, and PowerShell Scripts for Standard Users

Ganesh Karki 0 Reputation points
2025-04-11T06:44:38.84+00:00

Dear All,

Greetings!

I am seeking your guidance in creating an Intune policy that restricts the installation of .msi, .exe files, and the execution of PowerShell scripts for standard users, while allowing such actions for users with administrative privileges.

If available, I would appreciate it if you could share the corresponding .xml configuration file or a reference template that can be imported into Intune.

Thank you for your support and cooperation.

Best Regards,

Ganesh Karki

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
1,005 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,806 Reputation points MVP
    2025-04-11T09:39:54.76+00:00

    Have you looked into UAC settings for standard users? Something like this - https://rahuljindalmyit.blogspot.com/2021/03/intune-uac-elevation-prompt-behavior.html

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.