By: Michael Dineen - Sr. Product Manager | Microsoft Intune
This blog was written to provide guidance to Microsoft Intune admins that need to block or remove apps on their managed endpoints. This includes blocking the DeepSeek – AI Assistant app in accordance with government and company guidelines across the world (e.g. the Australian Government’s Department of Home Affairs Protective Policy Framework (PSPF) Direction 001-2025, Italy, South Korea). Guidance provided in this blog uses the DeepSeek – AI Assistant and associated website as an example, but you can use the provided guidance for other apps and websites as well.
The information provided in this guidance is supplemental to previously provided guidance which is more exhaustive in the steps administrators need to take to identify, report on, and block prohibited apps across their managed and unmanaged mobile devices: Support tip: Removing and preventing the use of applications on iOS/iPadOS and Android devices.
iOS/iPadOS devices
For ease of reference, the below information is required to block the DeepSeek – AI Assistant app:
- App name: DeepSeek – AI Assistant
- Bundle ID: com.deepseek.chat
- Link to Apple app store page: DeepSeek – AI Assistant
- Publisher: 杭州深度求索人工智能基础技术研究有限公司
Corporate devices (Supervised)
Hide and prevent the launch of the DeepSeek – AI Assistant app
The most effective way to block an app on supervised iOS/iPadOS devices is to block the app from being shown or being launchable.
- Create a new device configuration profile and select Settings Catalog for the profile type. (Devices > iOS/iPadOS > Configuration profiles).
- On the Configuration settings tab, select Add settings and search for Blocked App Bundle IDs.
- Select the Restrictionscategory and then select the checkbox next to the Blocked App Bundle IDs setting.
- Enter the Bundle ID: com.deepseek.chat
- Assign the policy to either a device or user group.
Note: The ability to hide and prevent the launch of specific apps is only available on supervised iOS/iPadOS devices. Unsupervised devices, including personal devices, can’t use this option.
Uninstall the DeepSeek – AI Assistant app
If a user has already installed the app via the Apple App Store, even though they will be unable to launch it when the previously described policy is configured, it’ll persist on the device. Use the steps below to automatically uninstall the app on devices that have it installed. This policy will also uninstall the app if it somehow gets installed at any point in the future, while the policy remains assigned.
- Navigate to Apps > iOS/iPadOS apps.
- Select + Add and choose iOS store app from the list.
- Search for DeepSeek – AI Assistant and Select.
- Accept the default settings, then Next.
- Modify the Scope tags as required.
- On the Assignments tab, under the Uninstall section, select + Add group or select + Add all users or + Add all devices, depending on your organization’s needs.
- Click the Create button on the Review + create tab to complete the setup.
Monitor the status of the uninstall by navigating to Apps > iOS/iPadOS, selecting the app, and then selecting Device install status or User install status. The status will change to Not installed.
Personal Devices – Bring your own device (BYOD)
Admins have fewer options to manage settings and apps on personal devices. Apple provides no facility on unsupervised (including personal) iOS/iPadOS devices to hide or block access to specified apps.
Instead, admins have the following options:
- Use an Intune compliance policy to prevent access to corporate data via Microsoft Entra Conditional Access (simplest and quickest to implement).
- Use a report to identify personal devices with specific apps installed.
- Takeover the app with the user’s consent.
- Uninstall the app.
This guide will focus on option 1. For further guidance on the other options refer to: Support tip: Removing and preventing the use of applications on iOS/iPadOS and Android devices.
Identify personal devices that have DeepSeek – AI Assistant installed and prevent access to corporate resources
You can use compliance policies in Intune to mark a device as either “compliant” or “not compliant” based on several properties, such as whether a specific app is installed. Combined with Conditional Access, you can now prevent the user from accessing protected company resources when using a non-compliant device.
- Create an iOS/iPadOS compliance policy, by navigating to Devices > iOS/iPadOS > Compliance policies > Create policy.
- On the Compliance settings tab, under System Security > Restricted apps, enter the name and app Bundle ID and select Next.
- Name: DeepSeek – AI Assistant
- Bundle ID: com.deepseek.chat
- Under Actions for noncompliance, leave the default action Mark device noncompliant configured to Immediately and then select Next.
- Assign any Scope tags as required and select Next.
- Assign the policy to a user or device group and select Next.
- Review the policy and select Create.
Devices that have the DeepSeek – AI Assistant app installed are shown in the Monitor section of the compliance policy.
- Navigate to the compliance policy and select Device status, under Monitor > View report.
- Devices that have the restricted app installed are shown in the report and marked as “Not compliant”.
When combined with the Require device to be marked as compliant grant control, Conditional Access blocks access to protected corporate resources on devices that have the specified app installed.
Android devices
Android Enterprise corporate owned, fully managed devices
Admins can optionally choose to allow only designated apps to be installed on corporate owned fully managed devices by configuring Allow access to all apps in Google Play store in a device restrictions policy.
If this setting has been configured as Block or Not configured (the default), no additional configuration is required as users are only able to install apps allowed by the administrator.
Uninstall DeepSeek
To uninstall the app, and prevent it from being installed via the Google Play Store perform the following steps:
- Add a Managed Google Play app in the Microsoft Intune admin center by navigating to Apps > Android > Add, then select Managed Google Play app from the drop-down menu.
- r DeepSeek – AI Assistant in the Search bar, select the app in the results and click Select and then Sync.
- Navigate to Apps > Android and select DeepSeek – AI Assistant > Properties > Edit next to Assignments.
- Under the Uninstall section, add a user or device group and select Review + save and then Save.
- After the next sync, Google Play will uninstall the app, and the user will receive a notification on their managed device that the app was “deleted by your admin”:
The Google Play Store will no longer display the app. If the user attempts to install or access the app directly via a link, the example error below is displayed on the user’s managed device:
Android Enterprise personally owned devices with work profile
For Android Enterprise personally owned devices with a work profile, use the same settings as described in the Android Enterprise corporate owned, fully managed devices section to uninstall and prevent the installation of restricted apps in the work profile.
Note: Apps installed outside of the work profile can’t be managed by design.
Windows devices
You can block users from accessing the DeepSeek website on Windows devices that are enrolled into Microsoft Defender for Endpoint. Blocking users’ access to the website will also prevent them from adding DeepSeek as a progressive web app (PWA).
This guidance assumes that devices are already enrolled into Microsoft Defender for Endpoint.
Using Microsoft Defender for Endpoint to block access to websites in Microsoft Edge
First, Custom Network Indicators needs to be enabled.
Note: After configuring this setting, it may take up to 48 hours after a policy is created for a URL or IP Address to be blocked on a device.
- Access the Microsoft Defender admin center and navigate to Settings > Endpoints > Advanced features and enable Custom Network Indicators by selecting the corresponding radio button.
- Select Save preferences.
Next, create a Custom Network Indicator.
- Navigate to Settings > Endpoints > Indicators and select URLs/Domains and click Add Item.
- Enter the following, and then click Next:
- URL/Domain: https://deepseek.com
- Title: DeepSeek
- Description: Block network access to DeepSeek
- Expires on (UTC): Never
- You can optionally generate an alert when a website is blocked by network protection by configuring the following and click Next:
- Generate alert: Ticked
- Severity: Informational
- Category: Unwanted software
Note: Change the above settings according to your organization’s requirements.
- Select Block execution as the Action and click Next, review the Organizational scope and click Next.
- Review the summary and click Submit.
Note: After configuring the Custom Network Indicator, it can take up to 48 hours for the URL to be blocked on a device.
Once the Custom Network Indicator becomes active, the user will experience the following when attempting to access the DeepSeek website via Microsoft Edge:
Using Defender for Endpoint to block websites in other browsers
After configuring the above steps to block access to DeepSeek in Microsoft Edge, admins can leverage Network Protection to block access to DeepSeek in other browsers.
- Create a new Settings Catalog policy by navigating to Devices > Windows > Configuration > + Create > New Policy and selecting the following then click Create:
- Platform: Windows 10 and later
- Profile type: Settings Catalog
- Enter a name and description and click Next.
- Click + Add settings and in the search field, type Network Protection and click Search.
- Select the Defender category and select the checkbox next to Enable Network Protection.
- Close the settings picker and change the drop-down selection to Enabled (block mode) and click Next.
- Assign Scope Tags as required and click Next.
- Assign the policy to a user or device group and click Next.
- Review the policy and click Create.
When users attempt to access the website in other browsers, they will experience an error that the content is blocked by their admin.
macOS
macOS devices that are onboarded to Defender for Endpoint and have Network Protection enabled are also unable to access the DeepSeek website in any browser as the same Custom Network Indicator works across both Windows and macOS. Ensure that you have configured the Custom Network Indicator as described earlier in the guidance.
Enable Network Protection
Enable Network Protection on macOS devices by performing the following in the Microsoft Intune admin center:
- Create a new configuration profile by navigating to Devices > macOS > Configuration > + Create > New Policy > Settings Catalog and select Create.
- Enter an appropriate name and description and select Next.
- Click + Add settings and in the search bar, enter Network Protection and select Search.
- Select the Microsoft Defender Network protection category and select the checkbox next to Enforcement Level and close the Settings Picker window.
- In the dropdown menu next to Enforcement Level, select Block and select Next.
- Add Scope Tags as required and select Next.
- Assign the policy to a user or devices group and select Next.
- Review the policy and select Create.
The user when attempting to access the website will experience the following:
Conclusion
This blog serves as a quick guide for admins needing to block and remove specific applications on their Intune managed endpoints in regulated organizations.
Additional guidance for other mobile device enrollment methods can be found here: Support tip: Removing and preventing the use of applications on iOS/iPadOS and Android devices.
Additional resources
For further control and management of user access to unapproved DeepSeek services, consider utilizing the following resources. This article provides insights into monitoring and gaining visibility into DeepSeek usage within your organization using Microsoft Defender XDR.
Additionally, our Microsoft Purview guide offers valuable information on managing AI services and ensuring compliance with organizational policies. These resources can help enhance your security posture and ensure that only approved applications are accessible to users.
Let us know if you have any questions by leaving a comment on this post or reaching out on X @IntuneSuppTeam.
Updated Feb 19, 2025
Version 3.0Intune_Support_Team
Microsoft
Joined October 11, 2018
Intune Customer Success
Follow this blog board to get notified when there's new activity