Setting up and managing device configurations using Intune
Hello Thishni,
For this requirement, I would separate the solution into application control and Defender file blocking.
1. Recommended approach: AppLocker or WDAC
If the objective is to prevent AnyDesk from running, including portable copies, application-control policies are more appropriate than relying only on a single file hash.
Microsoft specifically notes that file-hash indicators are useful as a stop-gap for individual files, but they aren't the preferred method for blocking an entire application because applications can contain multiple files and different versions have different hashes. Microsoft recommends Windows Defender Application Control (WDAC) or AppLocker for application blocking.
AppLocker supports executable rules and can create rules based on publisher, product name, file name, and version.
For an organization that wants to block AnyDesk while continuing to allow other applications, an AppLocker publisher/path/file rule can therefore be more maintainable than maintaining individual AnyDesk hashes.
2. Defender for Business file indicator
If you need an immediate block for a known AnyDesk executable, Microsoft Defender for Business supports file indicators.
In the Microsoft Defender portal:
Settings → Endpoints → Indicators → File hashes → Add item
Add the SHA-256 hash of the AnyDesk executable and select Block.
Microsoft documents that file indicators can prevent a PE file (.exe/.dll) from being read, written, or executed. Defender for Business supports this capability.
However, this is hash-based. A new AnyDesk version with a different hash would require another indicator. Therefore, I would not use this alone if the requirement is to continuously block AnyDesk.
3. Portable AnyDesk
A portable executable is still an executable, so an appropriate AppLocker/WDAC policy can prevent it from running even when the user hasn't installed AnyDesk normally.
This is an important advantage over simply removing the installed AnyDesk application.
4. Be careful with AppLocker enforcement
Don't immediately deploy a restrictive allow-list policy to all production devices.
Microsoft recommends testing AppLocker policies in Audit only first and reviewing the resulting events before switching the required rule collections to Enforce.
Also be careful with broad publisher/path rules. A poorly designed application-control policy can block legitimate software.
5. What I would use in this environment
For your Microsoft 365 Business Premium + Intune + Defender for Business environment:
Long-term control: AppLocker/WDAC → block AnyDesk
Immediate response for known binaries: Defender for Business file indicator → SHA-256 → Block
Download prevention: Use your organization's Defender/SmartScreen/web protection policies as an additional layer rather than relying on the executable block alone.
One important point: a Defender file indicator is not the same thing as an application deny-list. Microsoft explicitly recommends WDAC/AppLocker when the goal is to block an application rather than individual files.
Before deploying the policy broadly, test it on a small Intune device group and verify that AnyDesk's installed and portable executables are blocked while your approved applications continue to run.