{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreiduqmya6pvo2p36vi6yvh26zcpivbaycqplkvjdpawpdcjgoobmiu",
"uri": "at://did:plc:ws6dhxzqnqxu5aqxt4kd27oc/app.bsky.feed.post/3mnby4ttnqf32"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreieg3y7do5bzvzgrtpbehhxj74dhwndd3nv7de2qb4me4wdcgg7jim"
},
"mimeType": "image/webp",
"size": 77956
},
"description": "Switch the app install control setting to lock your PC to verified Microsoft Store apps and stop other software from installing.",
"path": "/how-to-keep-windows-11-from-installing-apps-outside-the-microsoft-store/",
"publishedAt": "2026-06-02T06:35:46.000Z",
"site": "https://allthings.how",
"textContent": "Windows 11 has a built-in switch that decides where apps are allowed to come from. Flip it to the strictest setting and the system stops anyone on the PC from installing software that didn't come from the Microsoft Store. No extra utility or registry hack is needed, and the same control exists in Windows 10 under a slightly different name.\n\n✅\n\nQuick answer: Open Settings → Apps → Advanced app settings, then set Choose where to get apps to The Microsoft Store only.\n\n* * *\n\n## Block third-party app installations in Windows 11\n\nThe setting lives inside the Apps section of Windows Settings. Once it's on, any attempt to run an installer from a website or other outside source is refused, and only Store apps go through.\n\n**Step 1:** Press `Win+I` to open Windows Settings. This is the fastest way to land on the main settings page.\n\n**Step 2:** Click the **Apps** tab in the left sidebar. This holds every option related to installed software.\n\n**Step 3:** Open **Advanced app settings**. This screen controls how apps are installed and updated on the device.\n\n**Step 4:** Expand the **Choose where to get apps** drop-down menu and pick **The Microsoft Store only**. From this point on, installers from outside the Store are blocked.\n\nYou'll know it worked when someone tries to launch an outside installer and sees the message **Your PC's settings only let it install verified apps from the Store**. That confirmation is the sign the block is active.\n\n* * *\n\n## What each \"Choose where to get apps\" option does\n\nThe drop-down isn't all-or-nothing. There's a middle setting that still lets you install outside software after a confirmation, which is useful if you want a warning rather than a hard wall.\n\nSetting | What happens\n---|---\nAnywhere (Allow apps from anywhere) | Default. Apps install from any source with no extra prompt.\nWarn me before installing apps from outside the Store | Shows **Get apps from Store** and **Install anyway** buttons each time, so third-party apps still work after you confirm.\nThe Microsoft Store only | Blocks all outside installers and shows the verified-apps-only message.\n\nThe Microsoft Store now carries plenty of regular desktop apps such as Firefox and Opera, not just packaged UWP apps, so locking to the Store doesn't shut out every familiar program.\n\n* * *\n\n## Block third-party app installations in Windows 10\n\nThe same control exists in Windows 10, just under a different label. Head to **Settings → Apps → Apps & features**, then find **Installing apps** on the right. By default it reads **Allow apps from anywhere**.\n\nSwitch it to **Allow apps from the Store only** to stop other users from installing software, or pick **Warn me before installing apps from outside the Store** if you'd rather confirm each install instead of blocking it outright.\n\n⚠️\n\nThis control only triggers when something is being installed. Portable apps that run without an installer aren't affected. On Windows 10 you also need to set this in every account you want protected.\n\n* * *\n\n## Lock the setting so it can't be changed\n\nOn its own, the drop-down can be flipped back by anyone using the PC without needing a password. To stop that, the Group Policy Editor on Pro editions can freeze the choice in place.\n\n**Step 1:** Press `Win+R`, type `gpedit.msc`, and press Enter to open the Group Policy Editor.\n\n**Step 2:** Navigate to the SmartScreen policy folder at the path below.\n\n\n Computer Configuration\\Administrative Templates\\Windows Components\\Windows Defender SmartScreen\\Explorer\n\n**Step 3:** Double-click **Configure App Install Control** and select **Enabled**. This activates the locking behavior.\n\n**Step 4:** In the Options drop-down, choose **Allow Apps from Store Only** , then click **Apply** and **OK**. Restart the PC for the change to take hold.\n\nAfter the restart, return to **Advanced app settings** and the **Choose where to get apps** menu will appear grayed out and unchangeable. To undo it later, set the same policy back to **Not Configured** or **Disabled**.\n\n💡\n\nGroup Policy Editor ships only with Pro, Enterprise, and Education editions. On Windows Home you can still set the Store-only option through Settings, but you won't be able to lock it with this policy.\n\nFor most setups, the Store-only switch alone covers the goal of keeping outside software off a machine used by children, employees, or anyone you don't want installing programs. Add the Group Policy lock when you also need to make sure that switch stays put.",
"title": "How to keep Windows 11 from installing apps outside the Microsoft Store",
"updatedAt": "2026-06-02T06:35:47.914Z"
}