I manage more than 100 Windows 11 endpoints that are joined to a local domain and registered with Entra ID. They are not hybrid joined or fully Entra joined, and Microsoft Defender for Endpoint is deployed throughout the environment. Users do not have local administrator rights, but they can still install some applications in their own context, especially under AppData, without elevation. I currently use Defender Advanced Hunting and a scheduled custom detection rule that correlates registry, file-system, and process telemetry. The problem is that some installations are missed, while updates, repairs, and version changes can look like new installations because they create files, folders, or registry entries. Ideally, I want new software installations to generate alerts while ordinary updates, repairs, and patches do not. How are others handling this? Are Defender XDR and KQL, Intune, AppLocker, WDAC, or another approach effective for detecting user-context installations and portable applications?
2 Answers
An Intune Detection and Remediation script can periodically inspect the registry, event logs, installed AppX packages, and selected file locations. The script can report its findings back through Intune, after which the results can feed ticketing or automation workflows. This is more suitable for scheduled inventory and reconciliation than for immediate prevention.
Establishing a known-good baseline is important. Compare changes against approved software and maintain separate logic for first-time discoveries versus changes to an existing product. Combining that baseline with Defender process and file telemetry should reduce false positives from upgrades and repairs, although portable applications still require monitoring of user-writable directories.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures