During a regular admin audit of our instance, I found that 2 users were able to install apps on our instance. Neither of them have product admin access, and only one is an admin on the project in which they have access. The other only has the service desk team role assigned.
How do I ensure that only org admins are able to install Marketplace apps?