BlockNonAdminUserInstall
Control whether nonadministrators can initiate app installations that require elevation.
OMA-URI
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/BlockNonAdminUserInstall
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/BlockNonAdminUserInstall
Deployment playbook
Assign it, sync it, prove it
A correct OMA-URI can still fail because of scope, format, applicability, targeting, conflict, or device state.
Likely causes
- The path, device scope, integer format, or configured value does not match this CSP record.
- The setting is not applicable to the device edition, Windows build, management mode, or hardware.
- Assignment filters, exclusions, stale check-in, or another policy source changed the effective configuration.
Recommended fix
- Test approved deployment channels such as Intune Company Portal.
- Coordinate with Windows Installer and App Installer policies.
- Avoid blocking required self-service workflows without an alternative.
Verify
- Trigger a device sync, then wait for a new check-in rather than reading the previous report state.
- Review the per-setting status and compare the profile, assignment, filter evaluation, and conflict details.
- On Windows, correlate the fresh sync with DMEDP/Admin events and the MDM diagnostic report.
- Verify the operating-system effect directly; a successful policy report is not always proof of the desired outcome.
Escalate when
- The current Microsoft CSP documentation lists the path/value as applicable but a freshly synced supported device still rejects it.
- Multiple devices fail with the same event or SyncML status after targeting and conflicts are eliminated.
- You can provide the policy JSON, assignments/filters, device build/edition, UTC sync time, per-setting status, and redacted diagnostics.
Copy this OMA-URI
./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/BlockNonAdminUserInstallUse scope Device, format Integer, and a value allowed by the current Microsoft documentation.
Read recent Windows MDM events
Get-WinEvent -LogName 'Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin' -MaxEvents 50 | Select-Object TimeCreated,Id,LevelDisplayName,MessageRead-only. Run on the affected Windows device and correlate the output with the latest sync time.
Collect an MDM diagnostic archive
mdmdiagnosticstool.exe -area "DeviceEnrollment;DeviceProvisioning;Autopilot" -zip "C:\Users\Public\Documents\MDMDiagReport.zip"Creates a local archive. Redact tenant, user, device, certificate, and network identifiers before sharing.
Deployment values
- Scope
- Device
- Format
- Integer
- Values
- 0 allows the default behavior; 1 blocks nonadministrator installs where supported.
Operational checks
- Test approved deployment channels such as Intune Company Portal.
- Coordinate with Windows Installer and App Installer policies.
- Avoid blocking required self-service workflows without an alternative.
Advertisement
