Restricting Software Installation by End Users in M365 – Best Practices

Yuuta Shimamura 0 Reputation points
2025-08-01T18:29:53.9933333+00:00

We would like to restrict end users from installing software on their devices and only allow installation when explicitly approved by an administrator.

One method we are considering is to create two groups on the admin side: a Normal User group and a Local Admin group. End users would be moved to the Normal User group by default, and only temporarily added to the Local Admin group when they request permission to install software.

However, this would require reassigning all users to the Normal User group initially, which could be complex and time-consuming.

Is there any feature in Microsoft 365 or Intune that can help us manage this more efficiently? We would appreciate any recommendations for a better approach.

Thank you in advance.

Microsoft Security | Intune | Configuration
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Jindal 11,076 Reputation points
    2025-08-02T13:58:44.68+00:00

    I will suggest to look at cloud laps. If you still want to elevate permissions for the standard user then consider EPM.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.