{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
        "slug": "dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/"
        },
        "title": "Separate Store app access restrictions from automatic UWP updates",
        "summary": "Can Store browsing be restricted while managed UWP apps keep updating?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:37+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Review this as a UWP Store policy decision, not a universal application-execution boundary. Record the exact effective Store settings and the managed apps whose update path must remain available.",
        "dse_recommendation": "State separately whether the goal is limiting user browsing, limiting app acquisition, or controlling execution.",
        "primary_source": {
            "name": "Add Microsoft Store Apps to Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents separate controls for opening the Store app and for automatic UWP updates. Blocking the Store application does not stop Intune’s Store-app installation or automatic UWP updating when the automatic-update policy permits it. That Store-app restriction does not affect the winget command-line tool. UWP apps can keep updating after installation even without an Intune assignment. <a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review this as a UWP Store policy decision, not a universal application-execution boundary. Record the exact effective Store settings and the managed apps whose update path must remain available.</p>\n<h2>DSE recommendation</h2>\n<p>State separately whether the goal is limiting user browsing, limiting app acquisition, or controlling execution. Preserve the automatic-update path required by the approved apps while testing the intended user-facing restriction. Have the endpoint security owner review other installation routes rather than treating one Store setting as comprehensive application control. Keep any additional restrictions under their own tested policy.</p>\n<h2>Verification</h2>\n<p>On a representative pilot, verify the intended Store user experience and an authorized Intune deployment. Observe an applicable UWP update and confirm the installed version afterward. Test relevant alternative acquisition paths separately and record their actual behavior. If the browsing restriction works but updates stop, reconcile the automatic-update policy before broadening the block. Retain both effective settings and workload results so acceptance covers maintenance as well as the visible Store interface.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Add Microsoft Store Apps to Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nMicrosoft documents separate controls for opening the Store app and for automatic UWP updates. Blocking the Store application does not stop Intune’s Store-app installation or automatic UWP updating when the automatic-update policy permits it. That Store-app restriction does not affect the winget command-line tool. UWP apps can keep updating after installation even without an Intune assignment. Microsoft Learn.\nApplicability\nReview this as a UWP Store policy decision, not a universal application-execution boundary. Record the exact effective Store settings and the managed apps whose update path must remain available.\nDSE recommendation\nState separately whether the goal is limiting user browsing, limiting app acquisition, or controlling execution. Preserve the automatic-update path required by the approved apps while testing the intended user-facing restriction. Have the endpoint security owner review other installation routes rather than treating one Store setting as comprehensive application control. Keep any additional restrictions under their own tested policy.\nVerification\nOn a representative pilot, verify the intended Store user experience and an authorized Intune deployment. Observe an applicable UWP update and confirm the installed version afterward. Test relevant alternative acquisition paths separately and record their actual behavior. If the browsing restriction works but updates stop, reconcile the automatic-update policy before broadening the block. Retain both effective settings and workload results so acceptance covers maintenance as well as the visible Store interface.\nOfficial references\nMicrosoft Learn: Add Microsoft Store Apps to Microsoft Intune.",
        "content_markdown": "## Source facts\n\nMicrosoft documents separate controls for opening the Store app and for automatic UWP updates. Blocking the Store application does not stop Intune’s Store-app installation or automatic UWP updating when the automatic-update policy permits it. That Store-app restriction does not affect the winget command-line tool. UWP apps can keep updating after installation even without an Intune assignment. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store).\n\n## Applicability\n\nReview this as a UWP Store policy decision, not a universal application-execution boundary. Record the exact effective Store settings and the managed apps whose update path must remain available.\n\n## DSE recommendation\n\nState separately whether the goal is limiting user browsing, limiting app acquisition, or controlling execution. Preserve the automatic-update path required by the approved apps while testing the intended user-facing restriction. Have the endpoint security owner review other installation routes rather than treating one Store setting as comprehensive application control. Keep any additional restrictions under their own tested policy.\n\n## Verification\n\nOn a representative pilot, verify the intended Store user experience and an authorized Intune deployment. Observe an applicable UWP update and confirm the installed version afterward. Test relevant alternative acquisition paths separately and record their actual behavior. If the browsing restriction works but updates stop, reconcile the automatic-update policy before broadening the block. Retain both effective settings and workload results so acceptance covers maintenance as well as the visible Store interface.\n\n## Official references\n\n[Microsoft Learn: Add Microsoft Store Apps to Microsoft Intune](https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Store app access restrictions from automatic UWP updates",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/",
                "headline": "Separate Store app access restrictions from automatic UWP updates",
                "description": "Can Store browsing be restricted while managed UWP apps keep updating?",
                "abstract": "Can Store browsing be restricted while managed UWP apps keep updating?",
                "articleBody": "Source facts\nMicrosoft documents separate controls for opening the Store app and for automatic UWP updates. Blocking the Store application does not stop Intune’s Store-app installation or automatic UWP updating when the automatic-update policy permits it. That Store-app restriction does not affect the winget command-line tool. UWP apps can keep updating after installation even without an Intune assignment. Microsoft Learn.\nApplicability\nReview this as a UWP Store policy decision, not a universal application-execution boundary. Record the exact effective Store settings and the managed apps whose update path must remain available.\nDSE recommendation\nState separately whether the goal is limiting user browsing, limiting app acquisition, or controlling execution. Preserve the automatic-update path required by the approved apps while testing the intended user-facing restriction. Have the endpoint security owner review other installation routes rather than treating one Store setting as comprehensive application control. Keep any additional restrictions under their own tested policy.\nVerification\nOn a representative pilot, verify the intended Store user experience and an authorized Intune deployment. Observe an applicable UWP update and confirm the installed version afterward. Test relevant alternative acquisition paths separately and record their actual behavior. If the browsing restriction works but updates stop, reconcile the automatic-update policy before broadening the block. Retain both effective settings and workload results so acceptance covers maintenance as well as the visible Store interface.\nOfficial references\nMicrosoft Learn: Add Microsoft Store Apps to Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:37+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-439-separate-store-app-access-restrictions-from-automatic-uwp-updates/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Store app access restrictions from automatic UWP updates"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Add Microsoft Store Apps to Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/app-management/deployment/add-microsoft-store"
                }
            }
        ]
    }
}