How to block all the (.MSC) commands/windows in Windows devices via Intune?

Vinod Survase 4,736 Reputation points
2023-11-06T14:26:41.88+00:00

How to block all the (.MSC) commands/windows in Windows devices via Intune?

For example: lusrmgr.msc this command/window

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
412 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,885 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,351 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,988 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Crystal-MSFT 48,081 Reputation points Microsoft Vendor
    2023-11-07T07:55:42.6066667+00:00

    @Vinod Survase, Thanks for posting in Q&A. Based on my researching, I find we can configure "Restrict Users to the explicitly permitted list of snap-ins" and "Restricted/Permitted snap-ins" to restrict the .msc access. Here is a link with more details:

    https://www.itprotoday.com/windows-78/how-can-i-restrict-access-mmc-snap-ins

    https://admx.help/?Category=Windows_11_2022&Policy=Microsoft.Policies.ManagementConsole::MMC_Restrict_To_Permitted_Snapins

    Note: Non-Microsoft link, just for the reference.

    In Intune, the policy settings are also available in Setting Catalog, you can configure there:

    User's image

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Crystal-MSFT 48,081 Reputation points Microsoft Vendor
    2023-11-08T03:09:14.1233333+00:00

    @Vinod Survase, Thanks for the reply. Based on my test, when I configure the policy as below:

    User's image

    After the policy is applied, I get the following error when I enter lusrmgr.msc in run

    User's image

    And is unable to access as below:

    User's image

    From your description, I know you also get error. Is it the same as the one I get? Which snap ins you are testing? If it is a different one, please let me know the name to let me test.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.