That all seems very reasonable. Apps downloaded from other sources are much more dangerous than apps downloaded from Google Play.
Whether you prevent ex-app-store distribution through fiat or through engineering, the result is the same. So I don't think the distinction is important.