diff --git a/Files/PolicyDefinitions/en-GB/DesktopAppInstaller.adml b/Files/PolicyDefinitions/en-GB/DesktopAppInstaller.adml
index 969295a9..38ed1d30 100644
--- a/Files/PolicyDefinitions/en-GB/DesktopAppInstaller.adml
+++ b/Files/PolicyDefinitions/en-GB/DesktopAppInstaller.adml
@@ -10,55 +10,71 @@
Enable App Installer
This policy controls whether the Windows Package Manager can be used by users.
-If you enable or do not configure this setting, users will be able to use the Windows Package Manager.
+If you enable or do not configure this policy, users will be able to use the Windows Package Manager.
-If you disable this setting, users will not be able to use the Windows Package Manager.
+If you disable this policy, users will not be able to use the Windows Package Manager.
Enable App Installer Settings
This policy controls whether users can change their settings.
-If you enable or do not configure this setting, users will be able to change settings for the Windows Package Manager.
+If you enable or do not configure this policy, users will be able to change settings for the Windows Package Manager.
-If you disable this setting, users will not be able to change settings for the Windows Package Manager.
+If you disable this policy, users will not be able to change settings for the Windows Package Manager.
Enable App Installer Experimental Features
This policy controls whether users can enable experimental features in the Windows Package Manager.
-If you enable or do not configure this setting, users will be able to enable experimental features for the Windows Package Manager.
+If you enable or do not configure this policy, users will be able to enable experimental features for the Windows Package Manager.
-If you disable this setting, users will not be able to enable experimental features for the Windows Package Manager.
+If you disable this policy, users will not be able to enable experimental features for the Windows Package Manager.
Enable App Installer Local Manifest Files
This policy controls whether users can install packages with local manifest files.
-If you enable or do not configure this setting, users will be able to install packages with local manifests using the Windows Package Manager.
+If you enable or do not configure this policy, users will be able to install packages with local manifests using the Windows Package Manager.
-If you disable this setting, users will not be able to install packages with local manifests using the Windows Package Manager.
+If you disable this policy, users will not be able to install packages with local manifests using the Windows Package Manager.
+ Enable App Installer Microsoft Store Source Certificate Validation Bypass
+ This policy controls whether the Windows Package Manager will validate the Microsoft Store certificate hash matches to a known Microsoft Store certificate when initiating a connection to the Microsoft Store Source.
+
+If you enable this policy, the Windows Package Manager will bypass the Microsoft Store certificate validation.
+
+If you disable this policy, the Windows Package Manager will validate the Microsoft Store certificate used is valid and belongs to the Microsoft Store before communicating with the Microsoft Store source.
+
+If you do not configure this policy, the Windows Package Manager administrator settings will be adhered to.
Enable App Installer Hash Override
This policy controls whether or not the Windows Package Manager can be configured to enable the ability override the SHA256 security validation in settings.
If you enable or do not configure this policy, users will be able to enable the ability override the SHA256 security validation in the Windows Package Manager settings.
If you disable this policy, users will not be able to enable the ability override the SHA256 security validation in the Windows Package Manager settings.
+ Enable App Installer Local Archive Malware Scan Override
+ This policy controls the ability to override malware vulnerability scans when installing an archive file using a local manifest using the command line arguments.
+
+If you enable this policy, users can override the malware scan when performing a local manifest install of an archive file.
+
+If you disable this policy, users will be unable to override the malware scan of an archive file when installing using a local manifest.
+
+If you do not configure this policy, the Windows Package Manager administrator settings will be adhered to.
Enable App Installer Default Source
This policy controls the default source included with the Windows Package Manager.
-If you do not configure this setting, the default source for the Windows Package Manager will be available and can be removed.
+If you do not configure this policy, the default source for the Windows Package Manager will be available and can be removed.
-If you enable this setting, the default source for the Windows Package Manager will be available and cannot be removed.
+If you enable this policy, the default source for the Windows Package Manager will be available and cannot be removed.
-If you disable this setting the default source for the Windows Package Manager will not be available.
+If you disable this policy the default source for the Windows Package Manager will not be available.
Enable App Installer Microsoft Store Source
This policy controls the Microsoft Store source included with the Windows Package Manager.
-If you do not configure this setting, the Microsoft Store source for the Windows Package manager will be available and can be removed.
+If you do not configure this policy, the Microsoft Store source for the Windows Package manager will be available and can be removed.
-If you enable this setting, the Microsoft Store source for the Windows Package Manager will be available and cannot be removed.
+If you enable this policy, the Microsoft Store source for the Windows Package Manager will be available and cannot be removed.
-If you disable this setting the Microsoft Store source for the Windows Package Manager will not be available.
- Set App Installer Source Auto Update Interval In Minutes
- This policy controls the auto update interval for package-based sources.
+If you disable this policy the Microsoft Store source for the Windows Package Manager will not be available.
+ Set App Installer Source Auto Update Interval
+ This policy controls the auto update interval for package-based sources.
-If you disable or do not configure this setting, the default interval or the value specified in settings will be used by the Windows Package Manager.
+If you disable or do not configure this policy, the default interval or the value specified in settings will be used by the Windows Package Manager.
-If you enable this setting, the number of minutes specified will be used by the Windows Package Manager.
+If you enable this policy, the number of minutes specified will be used by the Windows Package Manager.
Enable App Installer Additional Sources
This policy controls additional sources provided by the enterprise IT administrator.
@@ -75,10 +91,30 @@ If you do not configure this policy, users will be able to add or remove additio
If you enable this policy, only the sources specified can be added or removed from the Windows Package Manager. The representation for each allowed source can be obtained from installed sources using 'winget source export'.
If you disable this policy, no additional sources can be configured for the Windows Package Manager.
+ Enable App Installer ms-appinstaller protocol
+ This policy controls whether users can install packages from a website that is using the ms-appinstaller protocol.
+
+If you enable this policy, users will be able to install packages from websites that use this protocol.
+
+If you disable or do not configure this policy, users will not be able to install packages from websites that use this protocol.
+ Enable Windows Package Manager command line interfaces
+ This policy determines if a user can perform an action using the Windows Package Manager through a command line interface (WinGet CLI, or WinGet PowerShell).
+
+If you disable this policy, users will not be able execute the Windows Package Manager CLI, and PowerShell cmdlets.
+
+If you enable, or do not configure this policy, users will be able to execute the Windows Package Manager CLI commands, and PowerShell cmdlets. (Provided “Enable App Installer” policy is not disabled).
+
+This policy does not override the “Enable App Installer” policy.
+ Enable Windows Package Manager Configuration
+ This policy controls whether the Windows Package Manager configuration feature can be used by users.
+
+If you enable or do not configure this policy, users will be able to use the Windows Package Manager configuration feature.
+
+If you disable this policy, users will not be able to use the Windows Package Manager configuration feature.
-
- Source Auto Update Interval In Minutes
+
+ Source Auto Update Interval
Additional Sources: