Potentially Unwanted app blocking - How can I Block Downloads

Roger Hendrikse 246 Reputation points
2021-03-31T09:53:17.057+00:00

We are using Windows 10 (1909 and 20H2) with SCCM 2010 (and a Cloud Management Gateway for remote machines) and are moving to using Defender and managing it with SCCM. We use SCCM Endpoint Protection Policies to deploy Antimalware policy to machines.

In the Antimalware policy, we enable the option to Block potentially unwanted applications. However, the Windows Security icon is showing an exclamation mark, and if we open Windows Security, under App & browser control, we see a warning that "The setting to block unwanted apps is turned off".
83138-image.png

If we click Reputation-based protection settings, we see that Block Apps is enabled, but Block Downloads is not enabled.
83187-image.png

The only way to get the exclamation mark warning to go away is to select Block Downloads or click Dismiss, and doing so means having to provide admin credentials (our users do not have local admin rights on their machines). As we are migrating to Defender on over 4000 machines, it is not practical to login to each machine to remove this warning, especially seeing as 90% of our machines are currently working remotely.

The only way I can think of enabling the Block Downloads option on all machines would be to use a group policy (a group policy isn't really a valid option for me, as most of our machines do not have VPN access so I can't reliably use GPOs at the moment), a registry file, or a powershell command. All my research and testing has shown that making changes to PUA (Potentially unwanted Applications) with registry, GPO or powershell only seems to affect the Block Apps setting. I read that the Block Downloads setting is controlled in Edge settings, so how can I enable this setting machine wide using a registry setting or powershell command ?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,760 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Jörg Yannic Brian 1 Reputation point
    2021-06-15T13:29:05.673+00:00

    How can I change this setting via Intune?


  2. Dom 0 Reputation points
    2023-08-17T15:55:46.4566667+00:00

    If only it were this simple...

    We manage a tenant which seems to turn this ON in Windows:

    User's image

    But it is OFF in Edge on the same device, same user profile:
    User's image

    So these seem to be DIFFERENT settings.

    It gets even stranger. For the life of me, I can't identify the Intune policy that turns "Block downloads" ON. No GPOs here, devices are AAD/Intune managed only. So while someone must've solved it in this tenant some time ago - we can't repro that.

    Which Intune setting controls "Block Downloads" in the Security App?