Software deployed through a nominated distribution tool, Intune or Configuration Manager for instance, is trusted automatically under this App Control for Business feature, tracked via an AppLocker rule collection. Earlier installs are not tagged retrospectively.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Managed installer in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Microsoft Configuration Manager
Microsoft's endpoint management product run on-premises, used to roll out software, settings and updates to devices. A server with its client installed is not thereby onboarded to Defender for Cloud.
- App Control for Business
Previously known as Windows Defender Application Control. On Windows it blocks any driver or app that its policy does not permit, and Microsoft suggests choosing it over AppLocker.
- AppLocker
Microsoft now steers customers to App Control for Business, since this legacy feature gets no new capabilities. It controls which executables, scripts, installers, DLLs and packaged apps may run through Group Policy rules.
- Rule collection
A set of security admin rules, aimed at one or more network groups, held inside a security admin configuration of Azure Virtual Network Manager.
- EARLIER
Within nested DAX row contexts, lets an inner calculation read a column as it stood in an outer pass; EARLIEST jumps to the outermost. Most people now use variables, which read more clearly.