How to Prevent Executables/Programs from Running from Unapproved File Paths


I wasn't clear enough. You have two problems
1) You don't want people to modify the system / install programs - Guest account solves this part
2) You want to restrict execution of specific programs - Need Applocker for this
I now have Windows 11 Pro (thank you, @antspants). How would I use AppLocker to restrict programs? Like I said in my original post, the guest should be able to run programs from "C:\Program Files", but I don't want them running programs from, for example, "C:\Users\Guest\Downloads".

Thank you all for your help.
 

My Computer

System One

  • OS
    Windows 11 Pro (used to be Home)
    Computer type
    Laptop
An updte to the StackSocial Windows 11 Pro License

I contacted StackSocial and put it to them that the only way the results of trying to use their key showed that it didn’t work, was that they are selling Volume Licensing Keys.

They replied:

We understand what you mean.

We are sorry things did not work out with your order. We have been authorized to issue you a refund for the full amount of the purchase price.

We understand what you mean” is a little ambiguous. In relation to the questions I posed, that’s obviously the closest thing one will get to “Yes we sell volume licensing keys”

So I have a refund pending and regardless of the first attempt, bought another key from them the next day. This time the new key worked.

I believe @win11homeuser still needs help?


How would I use AppLocker to restrict programs?
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5039
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Yes, I do. I've been searching online on tutorials of how to use AppLocker (as suggested by @neemobeer and @garlin), but the results didn't help.
Not to toot my own horn but I have what I think is a pretty comprehensive tutorial on setting up AppLocker:


If you already came across it and decided that it was too complicated, I actually think for your desired purposes, simply the default automatically generated executable rules (shown at 9:02) would do exactly what you want as-is:
  • Allows only running programs from Program Files or Windows Directory
  • Allows admins to run from anywhere
You'd want to enable the default rules for all the categories including DLLs, I show all that in the video. For "Windows Installer Rules" I would delete the "All digitally signed windows installer files" Allow rule and in the "Packaged App Rules" category you might actually want to just make your own instead of the default, to only allow those within program files, but that's really the only manually created one you'd have to do.

If you want you can also right click and go to the properties of each rule and select which users specifically they apply to, but assuming you're using an admin account for yourself the defaults should be fine since they have that rule to allow anything for admin accounts anyway.

I'd also recommend at least watching the entire thing even if you don't end up using it beyond enabling the default rules so you at least know how things work or how to fine tune it further. The rest isn't all that relevant in your case because you're using it to protect users who are just running at standard user level permissions anyway.

I also talk about how AppLocker doesn't 100% protect from powershell scripts and there are other ways to deal with that.
 
Last edited:

My Computer

System One

  • OS
    Windows 11
::cough cough::: AaronLocker ::cough::
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears

Latest Support Threads

Back
Top Bottom