Restrict which programs can be run

  • Section(s): Security
  • Published on Jun 28, 2006.
  • Last Modified on Jun 28, 2006.
  • Last Modified by Mitch Tulloch.
  • Rated 3.9 out of 5 based on 16 votes.
How to restrict which programs are allowed to run on a computer

A common question is how can I restrict which programs can be run on Windows? With Group Policy (or Local Group Policy on a standalone machine) you can do this, though it takes a bit of work. Here's how it works:

In a domain, open the GPO linked to the container holding the user accounts you want to restrict (or on a standalone computer use Start --> Run --> type gpedit.msc to open the Local GPO).

Expand User Configuration \ Administrative Templates \ System Open the policy named Run Only Allowed Windows Applications Enable the policy and click Show

Click Add and type the executable name for each program you want to *allow* the user to run

Once the policy is applied, the user will only be able to run the programs you specified and no others. Unless you have allowed them access to the command prompt cmd however, in which case they can run pretty much anything if they can find it.

Cheers, Mitch Tulloch, MVP

About Mitch Tulloch

Mitch Tulloch was lead author for the Windows Vista Resource Kit from Microsoft Press, which is the book for IT pros who want to deploy, maintain and support Windows Vista in mid- and large-sized network environments. Mitch was also the author of Introducing Windows Server 2008 and technical project lead for the Microsoft Office Communications Server 2007 Resource Kit, both books also from Microsoft Press. For more information on these and other books by Mitch, see www.mtit.com .

Share this article


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred Network Inventory solution?