Block Command Prompt (CMD) Using Intune

Please follow below steps to block CMD on user devices.

1. Go to Microsoft Endpoint Manager admin center.  Click All Groups > + New group


2. Enter the info for group creation. After that click Create
3. Go to Devices > Configuration profiles > +create profile

4. Choose the Platform, Profile type, Template name and click Create

5. Enter the Name > click Next































6. Click Add
































7. Enter below info and click Save





























8. Click Next


















9. Click Next





















10. Click Add groups






























11. Choose the Group that you want to push block CMD and click Select





















12. Click Next
































13. Make sure rule configured as below depends on the platform choose, then click Next
































14. Click Create































15. Check the device status, wait for a while for it to take changes











16. On user device, try open CMD























17. User will see the CMD have been block


Popular posts from this blog

DMARC Checker

Warning "Windows can't find target" when open Outlook App

Push Apps to Android Devices via Intune