user installed apps that didnt require local admin

crib bar 846 Reputation points
2024-01-30T13:24:22.7466667+00:00

Are there any common windows apps that you come across when inventorying the software on your workstations that users have managed to install as the apps don’t actually require local admin rights? Are there any other ‘safeguards’ that can be put in place in a work environment to prevent installation of apps that don’t require local admin, as currently relying solely on not giving end users local admin on their workstations to stop them installing unapproved apps – only seems to be part of the puzzle with a growing number of apps for newer versions of windows that will install or run just fine without local admin rights. I was just intrigued if there were any common themes in such apps or categories of apps you find have crept onto your workstation estate. Do you have any specific tips on how to identify when such no-local-admin-required apps get installed on your workstations? Any specific tools or other methods that can help?

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-01-30T13:58:13.7933333+00:00

    Hi @crib bar

    You can use Applocker to control the list of applications and programs can be used and installed on each workstiation.

    Administer AppLocker Configure access to Microsoft Store


    Please don't forget to accept helpful answer

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Anonymous
    2024-02-02T02:03:38.6733333+00:00

    Hello crib bar, Thank you for posting in Q&A forum.

    To block applications to run, you can try the methods below:

    You can try the following gpo setting:

    1. Launch gpedit.msc through local group policy on this machine or gpmc.msc on Domain Controller.
    2. Expand user configuration > policies > Administrative templates > system
    3. Double click on don’t run specified windows applications
    4. Click enable
    5. Click the SHOW button
    6. Type in the app file name you want to block You can also try Software Restriction Policies here. https://learn.microsoft.com/en-us/windows-server/identity/software-restriction-policies/administer-software-restriction-policies If possible, you can block run PS command and CMD command on the machines. I hope the information above is helpful. If you have any question or concern, please feel free to let us know. Best Regards, Daisy Zhou

    ---If the Answer is helpful, please click "Accept Answer" and upvote it.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.