Winget Control in corporate environment

joomla3597 55 Reputation points
2026-09-28T10:35:22.7433333+00:00

Hi MS Team,

I want to know how we can control winget in a corporate environment where at current anyone within environment can install an application using winget. We want to control it so that either only allowed apps are able to download or apps which are microsoft signed than everything at current. Whats the way to achieve it?

Microsoft Security | Intune | Application management
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-28T10:35:41.4733333+00:00

    Use a combination of WinGet Group Policy, centralized source control, and application control.

    1. Control which WinGet sources are allowed WinGet includes Group Policy settings for Source Control, letting IT administrators specify which sources are allowed or blocked. This is the primary way to stop users from pulling packages from any source you do not approve.
    2. Deploy WinGet policy centrally Beginning in Windows 11, WinGet Group Policy templates are included with each release. Download the DesktopAppInstallerPolicies.zip package from the WinGet GitHub releases, extract it, copy the .admx and matching .adml files into C:\Windows\PolicyDefinitions and the language folder such as C:\Windows\PolicyDefinitions\en-US, then configure the policies in Group Policy Management Console (GPMC). On a domain controller, these templates can be stored in the Central Store.
    3. Use an enterprise-controlled repository for approved apps For internal or approved corporate apps, WinGet can be pointed to a private enterprise repository. A documented approach is to use the WinGet REST API reference implementation as an Azure Web App, or host a static pre-indexed package index in Azure Blob Storage. Then distribute that repository configuration centrally using Group Policy or Microsoft Intune.
    4. Restrict execution of non-approved apps, not just download sources If the goal is to allow only approved apps or only Microsoft-signed apps, source restriction alone is not enough. Use App Control for Business policies to define what is allowed to run based on signing identity and file attributes. Code signing lets the system verify files have not been tampered with and ties them to a publisher identity. The guidance recommends requiring app binaries and scripts to be code signed wherever possible.
    5. Be careful with certificate-pinning bypass WinGet supports a policy named BypassCertificatePinningForMicrosoftStore, but enabling the bypass reduces protection against man-in-the-middle risks. Leave it Not configured unless there is a specific enterprise need, such as SSL inspection causing Microsoft Store source connection errors.
    6. Validate current WinGet policy state on clients Run winget --info on a client to view detailed WinGet information, including configured group policies.

    Practical approach for the scenario:

    • Block or limit public sources with WinGet Source Control policy.
    • Publish only approved apps through a private enterprise WinGet repository.
    • Enforce allowed publishers or signed apps with App Control for Business.
    • Use Intune or Group Policy to deploy all of the above consistently across devices.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.