π‘οΈπͺπ»ππβοΈGroup - Microsoft Store Allowed
What this group is forβ
This is a static assigned device group that carves an exception out of the fleet-wide Microsoft Store block.
It works only as a pair with:
- βοΈπͺπ»CP - Security - Microsoft Store: the baseline this group is excluded from.
- βοΈπͺπ»πCP - Security - Microsoft Store - Allow: the inverse policy assigned to this group, which writes the tattooed registry value back and actually returns the Store.
Both assignments are required. The Store block writes to HKLM\Software\Policies\Microsoft\WindowsStore and that value survives exclusion, so a device that is only excluded still has no Store.
π οΈ Group Configurationβ
| Setting | Value |
|---|---|
| Group name | π‘οΈπͺπ»ππβοΈGroup - Microsoft Store Allowed |
| Group description | Devices explicitly allowed to use the Microsoft Store, overriding the default block. Membership requires a named application, documented approval and a review date. |
| Group type | Security |
| Membership type | Assigned (Device Group) |
β οΈ Governanceβ
Membership means a device sits outside the app governance story, not just that it gained one extra application. The bar reflects that:
- A named application that is genuinely published only through the Store.
- Written customer approval, recorded against the device.
- A quarterly review confirming the vendor still ships Store-only and the device still exists.
Good reason: a hardware utility for audio, display or stylus features that the manufacturer distributes exclusively as a Store app. Bad reason: "the user liked having it." If the application is available as an MSI, MSIX or winget package, deploy it through Intune and leave the device on the baseline.
π Relatedβ
- βοΈπͺπ»CP - Security - Microsoft Store
- βοΈπͺπ»πCP - Security - Microsoft Store - Allow
One device, one named application, one review date. An exception group full of laptops is just the block switched off with extra steps. π