Authorized Applications should be deployed to managed devices
PreviousWindows Hello for Business should be configured where applicableNextDevice Use Shall be restricted until required applications are installed
Last updated
An authorized application inventory should be kept for corporate approved applications. These applications should be packaged and deployed in Microsoft Intune from the applications section of the Intune Admin Center. The application lifecycle should be maintained through Intune, including the patch cycle.
Authorized Applications should be deployed to managed devices
• Any tenant with Intune licensing can access this setting.
https://learn.microsoft.com/en-us/mem/intune/apps/apps-win32-prepare
Add Microsoft Store apps to Microsoft Intune | Microsoft Learn

Level: Low
This will vary depending on the applications you are pushing out. The installation package you define will determine if the application will install automatically or provide the option to the user to install the application.
Tips
• Leverage packaging tools like Winget and Chocolatey to help automate the app packaging and deployment.
https://github.com/Romanitho/Winget-Install
https://github.com/Romanitho/Winget-AutoUpdate
https://github.com/o-l-a-v/winget-intune-win32
Last updated