Microsoft Security | Intune | Application management
Managing apps and software deployment through Microsoft Intune
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi MS Team,
I want to know how we can control winget in a corporate environment where at current anyone within environment can install an application using winget. We want to control it so that either only allowed apps are able to download or apps which are microsoft signed than everything at current. Whats the way to achieve it?
Managing apps and software deployment through Microsoft Intune
AI answer
Use a combination of WinGet Group Policy, centralized source control, and application control.
DesktopAppInstallerPolicies.zip package from the WinGet GitHub releases, extract it, copy the .admx and matching .adml files into C:\Windows\PolicyDefinitions and the language folder such as C:\Windows\PolicyDefinitions\en-US, then configure the policies in Group Policy Management Console (GPMC). On a domain controller, these templates can be stored in the Central Store.BypassCertificatePinningForMicrosoftStore, but enabling the bypass reduces protection against man-in-the-middle risks. Leave it Not configured unless there is a specific enterprise need, such as SSL inspection causing Microsoft Store source connection errors.winget --info on a client to view detailed WinGet information, including configured group policies.Practical approach for the scenario: