How can I block AnyDesk completely using Microsoft Intune / Microsoft 365 Admin Center?

Thishni Perera 75 Reputation points
2026-09-28T04:33:32.7666667+00:00

Hi Microsoft Community,

I am managing devices through Microsoft Intune and would like to completely prevent users from using AnyDesk on company-managed Windows devices.

The requirement is to:

  • Block AnyDesk if it is already installed.
  • Prevent users from launching the AnyDesk executable.
  • Prevent users from using the portable/standalone version of AnyDesk without installation.
  • Prevent AnyDesk from being downloaded and executed where possible.
  • Ensure that other legitimate applications are not affected.
  • Ideally manage this centrally through Microsoft Intune / Microsoft Defender for Endpoint.

The devices are managed through Intune, and the organization has Microsoft 365 Business Premium licenses.

I have looked at Microsoft Defender Antivirus policies and Intune configuration profiles, but I would like to know the Microsoft-recommended method for blocking only AnyDesk.

Specifically, I would appreciate guidance on:

  1. Which Intune policy or Microsoft Defender feature should be used?
  2. Can Microsoft Defender for Endpoint block AnyDesk based on its application/file identity?
  3. Can the solution block both the installed and portable versions of AnyDesk?
  4. Is AppLocker, Windows Defender Application Control (WDAC), Attack Surface Reduction (ASR), or Defender Indicators the recommended approach?
  5. Is this capability available with Microsoft 365 Business Premium, or is an additional license required?

Any Microsoft documentation or recommended configuration steps would be greatly appreciated. If Possible can someone guide me step by step to configure this?

Environment:

  • Windows 10/11
  • Microsoft Intune
  • Microsoft 365 Business Premium
  • Microsoft Defender for Business

Thank you.

Microsoft Security | Intune | Configuration

1 answer

Sort by: Most helpful
  1. Abinesh Magudeeswaran 230 Reputation points Student Ambassador
    2026-09-28T15:09:07.36+00:00

    Hello Thishni,

    For this requirement, I would separate the solution into application control and Defender file blocking.

    If the objective is to prevent AnyDesk from running, including portable copies, application-control policies are more appropriate than relying only on a single file hash.

    Microsoft specifically notes that file-hash indicators are useful as a stop-gap for individual files, but they aren't the preferred method for blocking an entire application because applications can contain multiple files and different versions have different hashes. Microsoft recommends Windows Defender Application Control (WDAC) or AppLocker for application blocking.

    AppLocker supports executable rules and can create rules based on publisher, product name, file name, and version.

    For an organization that wants to block AnyDesk while continuing to allow other applications, an AppLocker publisher/path/file rule can therefore be more maintainable than maintaining individual AnyDesk hashes.

    2. Defender for Business file indicator

    If you need an immediate block for a known AnyDesk executable, Microsoft Defender for Business supports file indicators.

    In the Microsoft Defender portal:

    Settings → Endpoints → Indicators → File hashes → Add item

    Add the SHA-256 hash of the AnyDesk executable and select Block.

    Microsoft documents that file indicators can prevent a PE file (.exe/.dll) from being read, written, or executed. Defender for Business supports this capability.

    However, this is hash-based. A new AnyDesk version with a different hash would require another indicator. Therefore, I would not use this alone if the requirement is to continuously block AnyDesk.

    3. Portable AnyDesk

    A portable executable is still an executable, so an appropriate AppLocker/WDAC policy can prevent it from running even when the user hasn't installed AnyDesk normally.

    This is an important advantage over simply removing the installed AnyDesk application.

    4. Be careful with AppLocker enforcement

    Don't immediately deploy a restrictive allow-list policy to all production devices.

    Microsoft recommends testing AppLocker policies in Audit only first and reviewing the resulting events before switching the required rule collections to Enforce.

    Also be careful with broad publisher/path rules. A poorly designed application-control policy can block legitimate software.

    5. What I would use in this environment

    For your Microsoft 365 Business Premium + Intune + Defender for Business environment:

    Long-term control: AppLocker/WDAC → block AnyDesk

    Immediate response for known binaries: Defender for Business file indicator → SHA-256 → Block

    Download prevention: Use your organization's Defender/SmartScreen/web protection policies as an additional layer rather than relying on the executable block alone.

    One important point: a Defender file indicator is not the same thing as an application deny-list. Microsoft explicitly recommends WDAC/AppLocker when the goal is to block an application rather than individual files.

    Before deploying the policy broadly, test it on a small Intune device group and verify that AnyDesk's installed and portable executables are blocked while your approved applications continue to run.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.