@JBreeze, Thanks for posting in Q&A.
Based on my research, we configure manage approved apps for Windows devices with App Control for Business policy and Managed Installers for Microsoft Intune. When you enable a managed installer, all subsequent applications you deploy to Windows devices through Intune are marked with the managed installer tag.
Here is a link you can refer.
https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-app-control-policy
Hope it will help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.