Home

How to block installation of Dropbox / Google Drive etc.

%3CLINGO-SUB%20id%3D%22lingo-sub-267359%22%20slang%3D%22en-US%22%3EHow%20to%20block%20installation%20of%20Dropbox%20%2F%20Google%20Drive%20etc.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267359%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20there%20a%20possibility%20to%20block%20the%20installation%20from%20apps%20like%20Dropbox%3F%20A%20regular%20user%20can%20now%20(although%20not%20admin)%20install%20the%20Dropbox%20application.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-267359%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268386%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20block%20installation%20of%20Dropbox%20%2F%20Google%20Drive%20etc.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268386%22%20slang%3D%22en-US%22%3E%3CP%3EThanx%20Oliver%20for%20your%20answer%20in%20details.%20I%20found%20the%20solution%20for%20installing%20only%20Store%20apps%20for%20the%20user.%20Thats%20secure%20enough%20for%20us.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268172%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20block%20installation%20of%20Dropbox%20%2F%20Google%20Drive%20etc.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268172%22%20slang%3D%22en-US%22%3E%3CP%3EIs%20this%20a%20statement%2C%20answer%20or%20question%20%3A-)%2C%20I'm%20not%20sure%20if%20I%20understand%20your%20sentence%20correct.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20will%20answer%20to%20clarify%20my%20statement%20a%20bit%20anyway%20%3A)%3C%2Fimg%3E%3C%2FP%3E%0A%3CP%3EAppLocker%20can%20control%20store%20apps%2C%20executables%20etc.%20you%20can%20build%20a%20rule%20set%20to%20allow%20some%20executables%20or%20block%20some%20executables%20and%20this%20is%20even%20possible%20for%20store%20apps.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20like%20to%20prevent%20all%20executables%20you%20could%20go%20for%20S-Mode%20to%20only%20allow%20store%20apps%20which%20is%20a%20great%20level%20of%20security%20in%20the%20end.%3C%2FP%3E%0A%3CP%3EIf%20you%20like%20to%20allow%20the%20user%20to%20install%20only%20store%20apps%20but%20you%20like%20to%20deploy%20executables%20by%20a%20management%20solution%20like%20Intune%20or%20ConfigMgr%20you%20should%20go%20for%20AppLocker%20and%20build%20a%20rule%20set%20to%20block%20everything%20except%20the%20deployed%20apps%20from%20your%20management%20software%20(and%20of%20course%20the%20system%20apps).%20This%20approach%20needs%20quite%20a%20bit%20of%20work%20and%20operational%20effort%20as%20every%20new%20app%20must%20be%20whitelisted.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20find%20an%20Intune%20AppLocker%20rule%20set%20example%20with%20focus%20on%20security%20published%20in%20the%20Windows%2010%20managed%20with%20Intune%20guide%20from%20the%20UK%20National%20Cyber%20Security%20Centre%20here%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.ncsc.gov.uk%2Fguidance%2Feud-guidance-windows-10-1803-mobile-device-management%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.ncsc.gov.uk%2Fguidance%2Feud-guidance-windows-10-1803-mobile-device-management%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-268170%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20block%20installation%20of%20Dropbox%20%2F%20Google%20Drive%20etc.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-268170%22%20slang%3D%22en-US%22%3EHi%20Oliver%2C%20the%20solution%20is%20to%20give%20the%20standard%20user%20only%20rights%20to%20install%20apps%20from%20the%20Windows%20Store%20by%20the%20restriction%20policy%20in%20Intune.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-267984%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20block%20installation%20of%20Dropbox%20%2F%20Google%20Drive%20etc.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267984%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Harry%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20assume%20you%20are%20talking%20about%20Windows%2010%20managed%20by%20MDM%20enrolled%20with%20Autopilot%20as%20Standard%20User.%20Dropbox%20is%20available%20as%20user%20mode%20install%20and%20therefor%20can%20be%20installed%20by%20a%20standard%20user.%20To%20control%20execution%20and%20install%20behavior%20of%20a%20Windows%2010%20device%20you%20could%20leverage%20AppLocker%2C%20which%20can%20be%20configured%20with%20MDM%20also.%20There%20you%20could%20go%20for%20a%20whitelist%20or%20blacklist%20approach.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Esee%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fapplocker-csp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fclient-management%2Fmdm%2Fapplocker-csp%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Harry Dubois
Contributor

Is there a possibility to block the installation from apps like Dropbox? A regular user can now (although not admin) install the Dropbox application.

4 Replies

Hi Harry,

 

I assume you are talking about Windows 10 managed by MDM enrolled with Autopilot as Standard User. Dropbox is available as user mode install and therefor can be installed by a standard user. To control execution and install behavior of a Windows 10 device you could leverage AppLocker, which can be configured with MDM also. There you could go for a whitelist or blacklist approach.

 

see here: https://docs.microsoft.com/en-us/windows/client-management/mdm/applocker-csp

 

best,

Oliver

Hi Oliver, the solution is to give the standard user only rights to install apps from the Windows Store by the restriction policy in Intune.

Is this a statement, answer or question :-), I'm not sure if I understand your sentence correct.

 

I will answer to clarify my statement a bit anyway :)

AppLocker can control store apps, executables etc. you can build a rule set to allow some executables or block some executables and this is even possible for store apps. 

If you like to prevent all executables you could go for S-Mode to only allow store apps which is a great level of security in the end.

If you like to allow the user to install only store apps but you like to deploy executables by a management solution like Intune or ConfigMgr you should go for AppLocker and build a rule set to block everything except the deployed apps from your management software (and of course the system apps). This approach needs quite a bit of work and operational effort as every new app must be whitelisted. 

You can find an Intune AppLocker rule set example with focus on security published in the Windows 10 managed with Intune guide from the UK National Cyber Security Centre here: 

https://www.ncsc.gov.uk/guidance/eud-guidance-windows-10-1803-mobile-device-management

 

best,

Oliver

Thanx Oliver for your answer in details. I found the solution for installing only Store apps for the user. Thats secure enough for us. 

Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies