{"id":12835,"date":"2018-09-18T07:32:26","date_gmt":"2018-09-18T07:32:26","guid":{"rendered":"https:\/\/www.top-password.com\/blog\/?p=12835"},"modified":"2018-09-18T07:32:26","modified_gmt":"2018-09-18T07:32:26","slug":"disable-powershell-with-software-restriction-policies-gpo","status":"publish","type":"post","link":"https:\/\/www.top-password.com\/blog\/disable-powershell-with-software-restriction-policies-gpo\/","title":{"rendered":"How to Disable PowerShell with Software Restriction Policies GPO"},"content":{"rendered":"<p>Is there a way to block PowerShell from running through group policy? Windows PowerShell comes pre-installed in Windows 10 and it&#8217;s a command-line shell designed especially for programmers and IT professionals. If you&#8217;re a standard Windows user, you may want to get rid of it. In this tutorial we&#8217;ll show you how to disable PowerShell for all user accounts in Windows 10, using Software Restriction Policies GPO.<\/p>\n<p><strong>Part 1: Find the PowerShell Executable Program<\/strong><\/p>\n<ol>\n<li>After launching <a href=\"https:\/\/www.top-password.com\/blog\/5-ways-to-run-powershell-as-administrator-in-windows-10\/\" rel=\"noopener\" target=\"_blank\">Windows PowerShell<\/a>, press the Ctrl + Shift + Esc keys simultaneously to bring up the <a href=\"https:\/\/www.top-password.com\/blog\/5-quick-ways-to-open-task-manager-in-windows-10-8\/\" rel=\"noopener\" target=\"_blank\">Task Manager<\/a> window. Go to the <strong>Details<\/strong> tab, scroll down to find the process called <em>powershell.exe<\/em>. Right-click on it and select &#8220;<strong>Open file location<\/strong>&#8220;.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/open-file-location-from-task-manager.png\" alt=\"\" width=\"550\" height=\"404\" class=\"alignnone size-full wp-image-12843\" \/>\n<\/li>\n<li>Windows Explorer will open the folder where the <em>powershell.exe<\/em> file is located. Note down the full path as we&#8217;ll need it later.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/powershell-executable.png\" alt=\"\" width=\"572\" height=\"240\" class=\"alignnone size-full wp-image-12844\" \/>\n<\/li>\n<\/ol>\n<p><strong>Part 2: Disable PowerShell with Software Restriction Policies<\/strong><\/p>\n<ol>\n<li><a href=\"https:\/\/www.top-password.com\/blog\/open-local-group-policy-editor-in-windows-10\/\" rel=\"noopener\" target=\"_blank\">Open the Local Group Policy Editor<\/a> and navigate to:<br \/>\n<code>Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Software Restriction Policies<\/code><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/new-software-restriction-policies.png\" alt=\"\" width=\"594\" height=\"384\" class=\"alignnone size-full wp-image-12845\" \/><\/p>\n<p> \tRight-click on <strong>Software Restriction Policies<\/strong> on the left console tree, and then select <strong>New Software Restriction Policies<\/strong>.<\/li>\n<li>Select the newly-created &#8220;<strong>Additional Rules<\/strong>&#8221; node. Right-click any empty space in the right pane and choose &#8220;<strong>New Hash Rule<\/strong>&#8220;.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/new-hash-rule.png\" alt=\"\" width=\"587\" height=\"436\" class=\"alignnone size-full wp-image-12846\" \/>\n<\/li>\n<li>Click the <strong>Browse<\/strong> button to select the <em>powershell.exe<\/em> file we&#8217;ve located previously, and set the <strong>Security level<\/strong> to <strong>Disallowed<\/strong>. Click <strong>OK<\/strong>.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/disable-powershell.png\" alt=\"\" width=\"400\" height=\"455\" class=\"alignnone size-full wp-image-12847\" \/>\n<\/li>\n<li>If you also want to block the Windows PowerShell ISE from running, just repeat the above steps to add a new rule to block <em>powershell_ise.exe<\/em>.<\/li>\n<li>Reboot your computer for the policies to take effect. When you try to run PowerShell you should receive the following error message &#8220;<em>This app has been blocked by your system administrator<\/em>&#8220;.\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.top-password.com\/blog\/wp-content\/uploads\/2018\/09\/app-blocked-by-system-admin.png\" alt=\"\" width=\"550\" height=\"160\" class=\"alignnone size-full wp-image-12848\" \/><\/p>\n<p> \tRenaming the PowerShell executable file couldn&#8217;t bypass the above message as well.<\/li>\n<\/ol>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>Is there a way to block PowerShell from running through group policy? Windows PowerShell comes pre-installed in Windows 10 and it&#8217;s a command-line shell designed especially for programmers and IT professionals. If you&#8217;re a standard Windows user, you may want to get rid of it. In this tutorial we&#8217;ll show you how to disable PowerShell [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,10,1894],"tags":[3972,3971,3970],"class_list":["post-12835","post","type-post","status-publish","format-standard","hentry","category-others","category-tips-tricks","category-windows-10","tag-block-powershell-gpo","tag-disable-powershell-group-policy","tag-disable-powershell-windows-10"],"_links":{"self":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/12835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/comments?post=12835"}],"version-history":[{"count":13,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/12835\/revisions"}],"predecessor-version":[{"id":12854,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/posts\/12835\/revisions\/12854"}],"wp:attachment":[{"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/media?parent=12835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/categories?post=12835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.top-password.com\/blog\/wp-json\/wp\/v2\/tags?post=12835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}