Intune: Allow Store Apps To Update (If Store Enabled)
π 2025-10-30
β’
β±οΈ 2 minuten lezen
β’
π’ Should-Have
πΌ Management Samenvatting
Allow Store apps to update = enable automatic updates for Microsoft Store apps (IF Store is enabled - security patches).
Aanbeveling
N/A (if Store disabled)
Risico zonder
N/A
Risk Score
10/10
Implementatie
0u
Van toepassing op:
β Windows 10 β Windows 11
Store app updates = security patches: Store apps: UWP apps from Microsoft Store (if Store enabled), Security updates: App vulnerabilities patched (automatic updates), Blocking updates: Outdated apps = vulnerable (exploits). IF Store disabled (recommended): This policy = N/A (no Store apps installed), IF Store enabled: Allow updates = security patches applied. Recommendation: Disable Store entirely (previous controls) β this policy becomes irrelevant.
PowerShell Modules Vereist
Primary API: Microsoft Graph API Connection:Connect-MgGraph Required Modules: Microsoft.Graph.DeviceManagement
Implementatie
Allow Store updates: Policy: Turn off Automatic Download and Install of updates: Not configured (allow updates), Effect: Store apps auto-update (security patches), Use case: IF Store is enabled (not recommended for enterprise). Best practice: Disable Store β N/A.
Vereisten
Windows 10/11
Microsoft Store ENABLED (not recommended)
Intune subscription
Implementatie
IF Store enabled: Intune Settings Catalog β Store β Turn off Automatic Download and Install of updates: Not configured (allow updates). RECOMMENDATION: Disable Store instead β this policy = N/A.
Compliance
BIO 12.06 (Patch management).
Monitoring
Gebruik PowerShell-script allow-apps-from-the-microsoft-app-store-to-update-is-set-to-allowed.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script allow-apps-from-the-microsoft-app-store-to-update-is-set-to-allowed.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
BIO: 12.06.01 -
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).
N/A: N/A - Recommendation: Disable Store (previous controls).
Management Samenvatting
Store app updates = N/A if Store disabled (recommended). IF Store enabled: Allow updates (security patches). BEST: Disable Store. Implementatie: 0 uur (N/A).