From cebafe486fcadeb77b9041055d476c7eb7be48e2 Mon Sep 17 00:00:00 2001 From: AmirMS <104940545+AmelBawa-msft@users.noreply.github.com> Date: Thu, 8 Dec 2022 15:15:13 -0800 Subject: [PATCH] Update DesktopAppInstaller.adml (#2759) --- doc/admx/en-US/DesktopAppInstaller.adml | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/doc/admx/en-US/DesktopAppInstaller.adml b/doc/admx/en-US/DesktopAppInstaller.adml index c0b73f12c2..664f87a652 100644 --- a/doc/admx/en-US/DesktopAppInstaller.adml +++ b/doc/admx/en-US/DesktopAppInstaller.adml @@ -31,12 +31,13 @@ If you disable this setting, users will not be able to enable experimental featu If you enable or do not configure this setting, users will be able to install packages with local manifests using the Windows Package Manager. If you disable this setting, users will not be able to install packages with local manifests using the Windows Package Manager. - Enable App Installer Microsoft Store Source Pinned Certificate Bypass - This policy controls whether the Windows Package Manager can be configured to disable the requirement to use a pinned certificate for the Microsoft Store source. + Enable App Installer Microsoft Store Source Certificate Validation Bypass + This policy controls whether the Windows Package Manager will validate the Microsoft Store certificate hash matches to a known Microsoft Store certificate when initiating a connection to the Microsoft Store Source. +If you enable this policy, the Windows Package Manager will bypass the Microsoft Store certificate validation. -If you enable or do not configure this setting, users will be able to bypass the pinned certificate used to validate the Microsoft Store source. +If you disable this policy, the Windows Package Manager will validate the Microsoft Store certificate used is valid and belongs to the Microsoft Store before communicating with the Microsoft Store source. -If you disable this setting, users will not be able to bypass the pinned certificate used to validate the Microsoft Store source. +If you do not configure this policy, the Windows Package Manager administrator settings will be adhered to. Enable App Installer Hash Override This policy controls whether or not the Windows Package Manager can be configured to enable the ability override the SHA256 security validation in settings.