Skip to content
Block Android App Installation from Unknown Sources using Intune

Block Android App Installation from Unknown Sources using Intune

Written By Jitesh Kumar
Last Updated August 28, 2023
Posted In Intune
SHARE

This post walks you through how to block Android App Installation from Unknown Sources using Intune. By creating a device profile within Intune, admins can enforce policies that prevent users from installing apps from sources other than the Managed Google Play Store.

The Intune device restriction policy setting blocks app installation from unknown sources. This will prevent users from installing apps from sources other than the Managed Google Play Store.

This proactive approach significantly reduces the risk of malware or unauthorized software to installed in corporate devices, enhancing overall data protection. Once the policy is defined and applied to specific user groups, Intune ensures that only trusted apps from the Play Store can be installed.

Line of Business apps are the apps that are specific to an organization and are used for internal use. These apps are either developed internally or by Private Apps for your Organization. These apps are designed to meet the specific needs of each company, and they are not available publicly in the Google Play Store for use.

Patch My PC

Intune supports various types of Android apps for multiple types of enrolment, An IT admin can add these LOB apps to the managed Google Play Store and deploy them to enrolled users, For more details Deploy Private LOB Apps To Android Devices Using Intune.

Block Android App Installation from Unknown Sources using Intune

Blocking Android app installations from unknown sources using Intune is a crucial security measure for organizations. Let’s check the steps, to understand which policies can be applied to block or allow Android App Installation from Unknown Sources.

  • Sign in to Microsoft Intune Admin Center https://intune.microsoft.com/
  • Click on Devices > Android > Configuration Policies. I selected the existing configuration profile (Device Restriction) for modification.

You can check more details, you wanted to create device restriction policies from scratch, Enforcing Screen Lock For Android Devices In Intune

Block Android App Installation from Unknown Sources using Intune Fig.1
Block Android App Installation from Unknown Sources using Intune Fig.1

You can see the different categories of applied configuration in the configuration settings for Android Enterprise personally owned devices with a work profile (BYOD). The System security allows you to configure the policy to control the app scan and installation from unknown sources.

Block Android App Installation from Unknown Sources using Intune Fig.2
Block Android App Installation from Unknown Sources using Intune Fig.2

Here you can review the available restriction settings under System security. You can select and customize them as per our requirements. I will be toggling to Switch to Block for Allow installation from unknown sources where you will apply the policy.

SettingsDescription
Allow installation from unknown sourcesAllow lets users turn on Unknown sources. This setting allows apps to install from unknown sources, including sources other than the Google Play Store. When set to Not configured (default), Intune doesn’t change or update this setting. By default, the OS might prevent users from turning on Unknown sources.
Table 1 – Block Android App Installation from Unknown Sources using Intune
Block Android App Installation from Unknown Sources using Intune Fig.3
Block Android App Installation from Unknown Sources using Intune Fig.3

The next step is to review the setup policy and Save. A notification prompt will appear when you save the profile, Profile “HTMD Android Device Restriction Policy” saved successfully.

Block Android App Installation from Unknown Sources using Intune Fig.4
Block Android App Installation from Unknown Sources using Intune Fig.4

Monitor the devices to ensure that the restriction is successfully enforced. Let’s test the devices to confirm that users are unable to install APKs from unknown sources on the mobile device.

Once the configuration is applied to the device, Staging app progress will appear as soon as you attempt to install the app on the managed mobile device.

The user cannot install the APKs. Here you can see the message appears “Action not allowed” You do not have permission to perform this action. Contact your organization’s IT administrator for more information.

Block Android App Installation from Unknown Sources using Intune Fig.5
Block Android App Installation from Unknown Sources using Intune Fig.5

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read