Remotely approve application installs when users are not local admins.

Kris Mullenberg 0 Reputation points
2024-08-22T13:16:58.7566667+00:00

I want to remove all users from being part of the local administrator group. This will prevent them from being able to install apps on their own. What we want to do is to have a means of granting permission for applications to be installed remotely and have a system of record (like an RMM tool or third party app if applicable) to remember this approval and allow other users in the same domain to do that install if required / requested. Does anyone know of an application / tool that will allow such a thing?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,484 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,926 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,850 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
430 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Aleksandr Kolesnikov 636 Reputation points
    2024-08-23T07:00:16.8233333+00:00

    Hi @Kris Mullenberg

    With Local user group membership policies in Endpoint Protection (Intune) you can manage the users of the built-in local groups on devices that run Windows 10 20H2 and later, and Windows 11 devices.

    create-profile

    As for applications you'd like to allow to be installed I think adding them as Available to the Company portal should cover your requirements.

    https://learn.microsoft.com/en-us/mem/intune/apps/apps-deploy#assign-an-app

    Screenshot of the available shortcuts in the Windows Company Portal

    Best regards,

    Aleksandr


    If the response is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.