Block applications through Intune (ex regedit/cmd)
A way to block students from running certain applications like reg edit and command prompt. In a school setting this is a necessity.
You can do this with OMA-URI via applocker. When you apply the toggle switches in intune edu it applies a config profile with applocker and a deny exe. in the back end.
This function was added to the intune for education portal. Under applications you can restrict access to administrative apps this will allow you to block regedit, powershell, and command prompt.
In Enterprise environments this is one of the standards for a better security. Please develop those CSP/OMA-URIs a.s.a.p.!
Absolutely agree, in an enterprise environment there is no way to lockdown cmd prompt, its a pain as you can run powershell through this even in kiosk mode.
There is no CSP as yet that I can see, and a google search provides nothing, why would MS release such an immature product??
Can we get a more specific place for how this was implemented? I'm not seeing the option in Device Restrictions and can't find anything online to tell me where to look.
Remi van Tienhoven commented
This function is since a few months implemented ;-)