Apps Allow or Block Windows Installer Files with AppLocker in Windows 11


AppLocker_header.webp

This tutorial will show you how to use AppLocker to create a rule to allow or block Windows Installer (.msi, .msp, and .mst) files to run for all or specific users and groups in Windows 10 and Windows 11.

AppLocker is included in Local Security Policy (secpol.msc) to configure Application Control Policies in the Pro, Enterprise, and Education editions of Windows 10 and Windows 11. Local Security Policy is not available in the Home edition.

AppLocker defines Windows Installer rules to include only the .msi, .msp, and .mst file formats.

The purpose of this rule collection is to allow you to control the installation of files on client computers and servers through Group Policy or the Local Security Policy snap-in. The following table lists the default rules that are available for the Windows Installer rule collection.

Any Windows Installer file not allowed by the default rules below will automatically be blocked by default unless you create a new rule to allow it for a user or group.

If you want to block a Windows Installer file allowed by the default rules below, you will need to create a new rule to block (deny) it for a user or group.

Purpose​
Name​
User​
Rule condition type​
Allow members of the local Administrators group to run all Windows Installer files(Default Rule) All Windows Installer filesBUILTIN\AdministratorsPath: *
Allow all users to run Windows Installer files that are digitally signed(Default Rule) All digitally signed Windows Installer filesEveryonePublisher: * (all signed files)
Allow all users to run Windows Installer files that are located in the Windows Installer folder(Default Rule) All Windows Installer files in %systemdrive%\Windows\InstallerEveryonePath: %windir%\Installer*

References:

You must be signed in as an administrator to use AppLocker.


AppLocker Windows Installer Rules are saved to the registry key below.

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SrpV2\Msi



EXAMPLE: "This installation package could not be opened. Contact the application vendor to verify that this is a valid Windows Installer package." message when open a blocked Windows Installer file

AppLocker_blocked_Windows_Installer_file.webp




Here's How:

1 Open Local Security Policy (secpol.msc).

2 Expand open Application Control Policies in the left pane of the Local Security Policy window, click/tap on AppLocker, and click/tap on the Configure rule enforcement link on the right side. (see screenshot below)

AppLocker_Windows_Installer_Rules-1.webp

3 In the Enforcement tab under Windows Installer rules, check Configured to Enforce rules, and click/tap on OK. (see screenshot below)

This setting is what enforces any "Windows Installer rules" you create.


AppLocker_Windows_Installer_Rules-2.webp

4 Perform the steps below to add default rules for "Script Rules": (see screenshots below)

If this step is not done, AppLocker can block all Windows Installer files from running.

If you already have all the Windows Installer default rules like in the right screenshot below, then you can skip this step and go to step 5 instead.

  1. Expand open AppLocker.
  2. Right click on Windows Installer Rules.
  3. Click/tap on Create Default Rules.
AppLocker_Windows_Installer_Rules-3.webp
AppLocker_Windows_Installer_Rules-4.webp

5 Right click on Windows Installer Rules, and click/tap on Create New Rule. (see screenshot below)

AppLocker_Windows_Installer_Rules-5.webp

6 Click/tap on Next. (see screenshot below)

AppLocker_Windows_Installer_Rules-6.webp

7 Under Action, select (dot) Allow or Deny (block) for how you want this rule applied. (see screenshot below)

AppLocker_Windows_Installer_Rules-7.webp

8 If you want to select a specific User or group instead of the default Everyone to apply this rule to, then follow the steps below:

If you want to allow or block script file(s) for the default Everyone, then go to step 9 instead.


A) Click/tap on Select. (see screenshot below)​

AppLocker_Windows_Installer_Rules-8.webp

B) Click/tap on the Advanced button. (see screenshot below)​

AppLocker_Windows_Installer_Rules-9.webp

C) Click/tap on the Find Now button. (see screenshot below)​

AppLocker_Windows_Installer_Rules-10.webp

D) Select a user or group you want to allow or block script file(s) for, and click/tap on OK. (see screenshot below)​

AppLocker_Windows_Installer_Rules-11.webp

E) Click/tap on OK. (see screenshot below)​

AppLocker_Windows_Installer_Rules-12.webp

9 Click/tap on Next. (see screenshot below)

AppLocker_Windows_Installer_Rules-13.webp

10 Select (dot) Path, and click/tap on Next. (see screenshot below)

AppLocker_Windows_Installer_Rules-14.webp

11 Do step 12 (file) or step 13 (folder/drive) below for the file or folder path you want to specify to allow or block script files.

12 Allow or Block Specific Windows Installer File

A) Click/tap on the Browse Files button. (see screenshot below)​

AppLocker_Windows_Installer_Rules-15.webp

B) Select the .msi, .msp, or .mst file type you want in the drop menu, navigate to and select the .msi, .msp, or .mst Windows Installer file, and click/tap on Open. (see screenshot below)​

AppLocker_Windows_Installer_Rules-16.webp

C) Click/tap on Create, and go to step 14. (see screenshot below)​

AppLocker_Windows_Installer_Rules-17.webp

13 Allow or Block All Windows Installer Files in a Specific Folder or Drive

A) Click/tap on the Browse Folders button. (see screenshot below)​

AppLocker_Windows_Installer_Rules-19.webp

B) Navigate to and select the folder or drive you want, and click/tap on OK. (see screenshot below)​

AppLocker_Windows_Installer_Rules-20.webp

C) Click/tap on Create, and go to step 14. (see screenshot below)​

AppLocker_Windows_Installer_Rules-21.webp

14 This new rule will now be added for "Windows Installer Rules". (see screenshots below)

AppLocker_Windows_Installer_Rules-18.webp
AppLocker_Windows_Installer_Rules-22.webp

To undo and remove this rule, you can right click on the rule, click/tap on Delete, and click/tap on Yes to confirm.

AppLocker_Windows_Installer_Rules-23.webp



That's it,
Shawn Brink


 
Last edited:
Thank you Shawn, will this also work in window 10?
 

My Computer

System One

  • OS
    Win 10 Pro 19045.6937 Win 11 25H2 VM
    Computer type
    Laptop
    Manufacturer/Model
    Dell Precicion 15 Workstation
    CPU
    Xeon W-10885M
    Motherboard
    Dell
    Memory
    64GB ECC DDR4 128GB max
    Graphics Card(s)
    Intel 1080p + Quadro RTX 5000 Max-Q 16GB 4K
    Sound Card
    onboard Realtec
    Monitor(s) Displays
    NA
    Screen Resolution
    1080p to 4k
    Hard Drives
    1 TB Samsung 9100 M2 SSD main
    2 TB Samsung 9100 M2 SSD storage
    500 GB Corsair T500 storage M2 SSD (6 TB max)
    PSU
    NA
    Case
    NA
    Cooling
    NA
    Keyboard
    backlit
    Mouse
    Logitec M720 Bluetooth Free scroll
    Internet Speed
    slow
    Browser
    Pale Moon 33.9.x.x - x64 AVX2 build
    Antivirus
    Windows Defender

My Computers

System One System Two

  • OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    TerraMaster F8 SSD Plus NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Amazon Basics Wired Full Keyboard MD005
    Mouse
    Logitech MX Master 4
    Internet Speed
    2 Gbps Download and 100 Mbps Upload
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
Cool,
 

My Computer

System One

  • OS
    Win 10 Pro 19045.6937 Win 11 25H2 VM
    Computer type
    Laptop
    Manufacturer/Model
    Dell Precicion 15 Workstation
    CPU
    Xeon W-10885M
    Motherboard
    Dell
    Memory
    64GB ECC DDR4 128GB max
    Graphics Card(s)
    Intel 1080p + Quadro RTX 5000 Max-Q 16GB 4K
    Sound Card
    onboard Realtec
    Monitor(s) Displays
    NA
    Screen Resolution
    1080p to 4k
    Hard Drives
    1 TB Samsung 9100 M2 SSD main
    2 TB Samsung 9100 M2 SSD storage
    500 GB Corsair T500 storage M2 SSD (6 TB max)
    PSU
    NA
    Case
    NA
    Cooling
    NA
    Keyboard
    backlit
    Mouse
    Logitec M720 Bluetooth Free scroll
    Internet Speed
    slow
    Browser
    Pale Moon 33.9.x.x - x64 AVX2 build
    Antivirus
    Windows Defender

Latest Support Threads

Back
Top Bottom