Skip to main content

πŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Microsoft Store Allowed

What this group is for​

This is a static assigned device group that carves an exception out of the fleet-wide Microsoft Store block.

It works only as a pair with:

Both assignments are required. The Store block writes to HKLM\Software\Policies\Microsoft\WindowsStore and that value survives exclusion, so a device that is only excluded still has no Store.

πŸ› οΈ Group Configuration​

SettingValue
Group nameπŸ›‘οΈπŸͺŸπŸ’»πŸ‘ˆπŸ”“βš™οΈGroup - Microsoft Store Allowed
Group descriptionDevices explicitly allowed to use the Microsoft Store, overriding the default block. Membership requires a named application, documented approval and a review date.
Group typeSecurity
Membership typeAssigned (Device Group)

⚠️ Governance​

Membership means a device sits outside the app governance story, not just that it gained one extra application. The bar reflects that:

  • A named application that is genuinely published only through the Store.
  • Written customer approval, recorded against the device.
  • A quarterly review confirming the vendor still ships Store-only and the device still exists.

Good reason: a hardware utility for audio, display or stylus features that the manufacturer distributes exclusively as a Store app. Bad reason: "the user liked having it." If the application is available as an MSI, MSIX or winget package, deploy it through Intune and leave the device on the baseline.


One device, one named application, one review date. An exception group full of laptops is just the block switched off with extra steps. πŸ”“