The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To hide App and browser control in Windows Security, set Hide the App and browser control area in the Windows Security app to Yes in an Intune Antivirus policy. Microsoft identifies the setting’s configuration service provider (CSP) as DisableAppBrowserUI. This hides the section and suppresses its related notifications; it is a visibility control, not a documented way to turn off SmartScreen or other protections.
Configure the setting in Intune
-
In the Intune admin center, go to Endpoint security > Antivirus, then create or edit an Antivirus policy for Windows.
-
Open the policy’s Windows Security experience settings and find Hide the App and browser control area in the Windows Security app.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchSpecial offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Set the value to Yes, then assign and save the policy according to your organization’s device-management process.
Microsoft’s Intune Antivirus policy settings reference describes the values as follows:
| Setting value | Documented behavior |
|---|---|
| Yes | Hides the App and browser control area and suppresses related notifications. |
| No | Behaves like Not configured. |
| Not configured | Default; allows user access to the area and its notifications. |
What hiding the area does—and does not do
The setting controls whether users can see and access the App and browser control area in the Windows Security app. Microsoft describes that area as containing information and settings for Windows Defender SmartScreen. On Windows 10 version 1709 and later, it also includes Exploit protection options. Hiding the interface should not be described as disabling those underlying protections. See Microsoft’s App & browser control in Windows Security documentation for the section’s contents.
Rank #2
Check platform and policy conflicts
Use a profile available in your tenant
Microsoft says the original Windows 10 and later platform was replaced by the Windows platform beginning April 5, 2022. New instances of the original profile can no longer be created, although existing profiles may still be edited and used. Choose the current Windows platform and profile offered in your tenant, and confirm that the setting is available there.
Look for another policy setting the same control
Endpoint security policies, device configuration policies, and security baselines can conflict when they configure the same setting to different values. If the section remains visible or the policy does not appear to take effect, review assignments and device-specific policy reports. Microsoft’s guidance on managing endpoint security policies explains policy conflicts and reporting.
Rank #3
Distinguish the section from the Windows Security icon
Hiding App and browser control is not the same as hiding the Windows Security icon in the notification area. The icon has a separate Intune setting. Microsoft notes that a sign-out and sign-in or a reboot is required for an icon change to take effect. See the Intune Endpoint Protection settings reference for the separate control.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Use Group Policy instead of Intune when appropriate
For devices managed through Group Policy, Microsoft documents a related control: Hide the App and browser protection area. In Group Policy Editor, go to Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Security > App and browser protection, then enable the setting. Microsoft lists Windows 10 version 1709 or later as the prerequisite for the corresponding ADMX/ADML settings. This GPO hides the section on the Windows Security home page and removes its navigation icon.
Rank #4
Intune and Group Policy are different management planes. The appropriate option depends on how your organization manages and assigns policy to its devices, whether the setting is available in the relevant tenant profile or ADMX/ADML templates, and how you handle overlapping policies.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

