@Aran Billen,Thanks for posting in Q&A. From your description, I know that you want to block apps for specific users on a device via Intune.
Based on my researching, I found that there are different configuration profiles for different platforms.
- For IOS, you can create a new configuration profile and select Settings Catalog for the profile type (Devices > iOS/iPadOS > Configuration profiles) to restrict apps.
- For Android, create a new Device restriction profile by navigating to Devices > Android > Configuration profiles, select Create Profile and choose Android Enterprise as the platform. For the Profile type, select “Device restrictions” under Fully Managed, Dedicated, and Corporate-Owned Work Profile.
Here is a link about detailed configuration settings you can refer. https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-removing-and-preventing-the-use-of-applications-on/ba-p/3815452
- For Windows, you can create a new configuration profile and select Settings Catalog for the profile type (Devices > Windows 10 and later > Configuration profiles).
Here is a link about detailed configuration settings you can refer. https://blog.ciaops.com/2023/10/13/block-applications-on-windows-devices-using-intune/#:~:text=In%20the%20search%20field%20type,(User)%20as%20shown%20above. Non-official, just for reference.
When you configure the settings successfully, in Assignment page, add the user group you want to allow to open apps under Included groups, add the user group you do not want to allow to open apps under Excluded groups.
Hope above information can be helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.