Limit Windows 10 sideloading sources

%3CLINGO-SUB%20id%3D%22lingo-sub-1943893%22%20slang%3D%22en-US%22%3ELimit%20Windows%2010%20sideloading%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1943893%22%20slang%3D%22en-US%22%3EHi%20Everyone.%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20develop%20internal%20applications%20in%20.NET%20and%20are%20changing%20over%20to%20APPX%2FMSIX%20installations%20for%20deployment.%20We%20would%20like%20to%20avoid%20using%20any%20kind%20of%20internal%20Store%20by%20using%20sideloading.%20We%20would%20obviously%20have%20to%20allow%20non-admins%20the%20ability%20to%20do%20so%20via%20group%20policy.%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20there%20any%20way%20to%20control%20what%20they%20can%20install%20more%20specifically%3F%20Say%2C%20who%20signed%20the%20application%3F%20Or%20is%20it%20a%20pure%20%22all-or-nothing%22%20setting.%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3CBR%20%2F%3E%3CBR%20%2F%3EErnie%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1943893%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAPPX%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMSIX%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Esideloading%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Estoreapp%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1967999%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Windows%2010%20sideloading%20sources%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1967999%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F698396%22%20target%3D%22_blank%22%3E%40erniesalazar%3C%2FA%3E%2C%26nbsp%3BYou%20can%20use%20the%20WDAC%20Wizard%20to%20create%20policies%26nbsp%3B%20to%20only%20allow%20certain%20application%20to%20be%20installed%20by%20your%20users.%20More%20information%20go%20to%3A%20aka.ms%2FWDAC%20and%2For%20aka.ms%2FWDACWizard%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Visitor
Hi Everyone.

We develop internal applications in .NET and are changing over to APPX/MSIX installations for deployment. We would like to avoid using any kind of internal Store by using sideloading. We would obviously have to allow non-admins the ability to do so via group policy.

Is there any way to control what they can install more specifically? Say, who signed the application? Or is it a pure "all-or-nothing" setting.

Thanks

Ernie
1 Reply

Hi @erniesalazar, You can use the WDAC Wizard to create policies  to only allow certain application to be installed by your users. More information go to: aka.ms/WDAC and/or aka.ms/WDACWizard