Jump to content

Recommended Posts

Posted (edited)

We're rolling out Windows 10 to a few machines and someone spotted a seriously annoying feature in Edge.

 

It seems that normal users, even with access to the store blocked, can install apps via Edge. Opening Edge and scrolling around under "My feed" will eventually get you to this:

 

fail1.png

 

You also get the same thing under "Top sites" on a new tab in Edge:

 

fail2.png

Daily Mail are you serious Microsoft?!?

 

 

 

Anyhow, notice how it lets you "Install app".. clicking this then just, well, installs it on the machine without any route through the store it seems and I have no idea how to turn it off. You can click the link to see more apps to download and it takes you to the MS Store page - here, you can see loads more apps, but you can't install them, since it tries to open them in the Store app (which I have blocked).

 

However, it seems as though the GPO to block the Store simply stops you opening the app, but doesn't disable functionality to install apps. And, even if you enable the GPO to disable all Store apps, it doesn't stop you installing them as above (which means you can install this crudware, but you can't open it. Failington Failford.)

 

Has anyone found a solution for this? We don't really want people randomly being able to install apps, but we need apps to work because Microsoft decided that the Calculator app should be the One And Only way to add two numbers together on a computer. Maybe block all apps and make an exception for Calculator?

Edited by Trevelyan
Posted

There is only 1 way, Applocker.

Had this myself a while back and ignored it hoping kids wouldn't notice, they did...

 

You will need to implement Applocker (really easy, don't read the MS docs just google a guide) and then lock down Edge through the Apps section along.

 

You could block the apps in that list but it changes so I block Edge and also monitor which apps show on my office pc and once a month install any new ones to my machine and block them from there.

 

Piece of advice - Setup group policy management on either your office pc or a test client pc don't do it from the server as these apps don't show on the server.

  • Thanks 1
  • 3 weeks later...
Posted
What would happen if you blocked write access to the C:\Program Files\WindowsApps folder? If you could just do on that folder without any inheritance then it shouldn't effect currently installed apps, right?
  • Thanks 1
Posted

A bit dirty but a good idea - removing TrustedInstaller worked and now it hangs at 0% in the browser. You also get a notification saying that it had troubles installing it but it'll try again later. Will see how that works out..

 

I tried to block everything else in Applocker that *wasnt* Edge, but it didn't stop it. Edge just seems to have diplomatic immunity from any system policies for things like, you know, app installation..

Posted (edited)

1703 and no, I can't - but it seems to just be the intial start page for Edge. If you follow the links to get to the store on the web, those will always try to access the store app.

 

I'm wondering if this perhaps wasn't intentional; it sort of bypasses everything else and just allows installation of an App without having to go through the store (well, I have the Store blocked by end users so it clearly isn't using the store).

Edited by Trevelyan
Posted

It is possible to stop Edge going to this Start page for any user - that may mitigate the issue. You'll need the 1703 GP templates.

 

Computer Configuration/Administrative Templates/Windows Components/Microsoft Edge/Configure Start Pages and Prevent the First Run webpage from opening on Microsoft Edge

  • Thanks 1
Posted
The process used on the front page is called direct linking. There are ways in which you can direct link any app from the store for a browser URL hence blocking edge is the only solution.
  • Thanks 1
Posted

I just read your thread from November on it.. insanity. You can't Applocker the store or anything else to counter it, but I asked about this on Technet too and someone acknowledged it there.

 

It looks like the suggestion is to disable the AppXSvc but I haven't figured out how to do that. Even via GPO that service doesn't want to be disabled.

 

If I can't fix this by our mass rollout date then yeah, it'll have to be blockerised.

Posted
I can't say exactly how, but with a combination of Smoothwall blocking parts of the Store, the Store Applocker'd and the GPOs in 1703 I have got it so that users cannot install the extensions into Edge - clicking on the buttons does nothing. Haven't seen any quirks from these policies - though some do say that using Applocker on the Store will mean it's impossible to open back up for users (not tested that myself).
  • Thanks 1
Posted

Right, solution within Windows (without externally blocking anything) is to disable (set to 4) the Appxsvc in HKEY_LOCAL_MACHINE \System \CurrentControlSet \Services\Appsvc

 

Any apps already installed then cannot be uninstalled, however, but combined with blocking the store, it then blocks Edge's ability to install stuff itself. Seems like a really messy and horrible fix but it really does but a definitive spanner in these works for app installation.

 

(I think It's also worth changing the homepage in Edge and making new tabs have a blank screen. But that has to be done through a machine GPO for some bizarre reason)

Posted

Alternatively install Chrome, block Edge and let the users choose between IE and Chrome.

Edge is horrific and even after a good 2 years it's not really improved .

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...