Block ALL (ANY) downloads with extensions EXE and MSI applicable to a specific folder like Desktop or Downloads

Anielka Oliveros 115 Reputation points
2025-03-17T18:59:38.9633333+00:00

After a deep search and test policies like APP Locker and APP Control for Business for Intune, on how to block extension files from downloads on any browser, we couldn't find a solution. Can someone please point us in the right direction? We need to block ANY downloads with extensions EXE and MSI applicable to a specific folder like Desktop or Downloads for a specific group. Not by Hash, path or publisher.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
488 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
    2025-03-17T22:26:50.78+00:00

    The best I could find from Settings Catalog are these, but not exactly what you want.

    User's image

    With policies or rules I don't think you can archive what you want by specifying only few folders. If you want to be extra secure what you users do, Applocker is still a good technology and can be implemented in Intune with xml rules, and same time keeping Users being users and not admins, you'll be fine :)


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.