How to Block Software Installs on Windows 11 & 10 (Every Method)

Logeshwaran
—

The most effective way to stop someone installing programs on a Windows 11 or 10 PC is to give them a standard user account instead of an administrator account: most desktop programs need an administrator password to install, and a standard user cannot supply one. Add Settings > Apps > Advanced app settings > Choose where to get apps > The Microsoft Store only to block downloaded installers, and, for children, Microsoft Family Safety to require approval for Store apps. On Pro editions, Group Policy can go further. Here is the catch many people miss: some programs install "just for me" without administrator rights, into the user's own folder. A standard account blocks most installs, but not those; the Store-only setting or App Control closes that gap.

Ethan's sister shares the family desktop with her two teenagers, and in one month it gained a game launcher, three "free" video converters, a browser toolbar and a cryptocurrency miner disguised as a game mod. All three of them had administrator accounts, because that was how the PC was set up on day one. At Jake's shop, the fix took twenty minutes and no extra software: one administrator account for Ethan's sister with a password the teenagers do not know, standard accounts for everyone day to day, the Store-only setting for the youngest, and Family Safety approvals for Store apps. Requests for new software now come to her phone, and the PC has stayed clean since. This page covers every layer, from simple to strict.

⚡ Quick Answer

• Most effective → give users standard accounts, keep one administrator. Standard accounts.

• Block downloaded installers → Choose where to get apps: The Microsoft Store only. Store only.

• Children → Family Safety: ask a parent before Store downloads. Family Safety.

• Pro editions → Windows Installer and Explorer policies in gpedit.msc. Group Policy.

Strictest: App Control or AppLocker allow-lists on Pro and Enterprise. App Control.

None of these steps remove programs already installed; they stop new ones arriving. Start with the first layer and add more only if you need them.

Ways to restrict installs, from simple to strict

Method Blocks Editions Effort
Standard user accountMost desktop installers, system changesAllLow
Store onlyRunning installers not from the StoreAllLow
Family Safety approvalsStore apps and purchases without a parent's OKAll (child accounts)Low
Windows Installer policiesMSI installs for usersPro and aboveMedium
Removable storage policiesRunning or reading USB drives and discsPro and aboveMedium
App Control or AppLockerAnything not on an allow listPro/Enterprise (varies)High

For a family or small office, the first three rows solve nearly every problem. The rest are for organizations or for a PC that must be locked down tightly.

Most homes need only the first two or three layers. Offices with more than a handful of PCs usually add the policy layers, because they can be applied once and enforced everywhere.

Use standard accounts (the biggest single step)

  1. Sign in with an administrator account.
  2. Open Settings > Accounts > Other users (and Family for child accounts).
  3. Click each account, choose Change account type, select Standard User, and click OK.
  4. Keep one administrator account, with a strong password the other users do not know.
  5. If you are the main user, consider using a standard account yourself day to day and signing in as administrator only to install things.

Standard users can use every installed app, browse, work and change their own settings. When something needs administrator rights, such as most installers, Windows shows a User Account Control prompt asking for an administrator's password. Without it, the install stops. This alone blocked most of what had appeared on Ethan's sister's PC. Our guide to creating accounts covers setting them up.

When a standard user needs something installed, the administrator can approve it in person: the User Account Control prompt on the user's screen accepts the administrator's password, the program installs, and the user carries on in their own account. Nobody has to switch accounts, and the password is typed once without being shared.

Who should have which account

Person Account type Extra protection
The person who maintains the PCAdministrator (separate from daily use if possible)Strong password, not shared
Other adultsStandardAsk the administrator for installs
TeenagersStandard, child account in Family SafetyStore approvals, content ratings
Young childrenStandard, child accountStore only, Ask a parent, screen time
VisitorsStandard local accountRemove after the visit

The same pattern works in a small office: one person, or an outside IT helper, holds administrator rights, and everyone else works as a standard user.

If you are the only person who knows the administrator password, write it down and keep it somewhere safe outside the PC, such as a password manager on your phone. A locked-out administrator account on a family PC is a far bigger problem than an unwanted app.

What a standard user can still do

Standard accounts are not crippled. A standard user can run every installed program, browse, use email and Office, connect to Wi-Fi, pair Bluetooth devices, change their own wallpaper, Start layout and passwords, and install many Store apps if allowed. They cannot install most desktop programs, change system-wide settings such as Windows Update policies or firewall rules, create other accounts, or read other users' files. For everyday use, most people never notice the difference until they try to install something, which is the point.

That balance matters, because a restriction people hardly notice is one they will not try to get around.

Allow apps only from the Microsoft Store

  1. Open Settings > Apps > Advanced app settings (Windows 10: Settings > Apps > Apps & features).
  2. Under Choose where to get apps, select The Microsoft Store only (recommended).

Now running a downloaded installer shows a message that the app is not Microsoft-verified, with a link to the Store. This catches the "just for me" installers that standard accounts allow, and it applies to administrator accounts too unless they change the setting back. The softer options, Anywhere, but warn me and Anywhere, but let me know if there's a comparable app in the Microsoft Store, are useful middle grounds that nudge people toward the Store without blocking.

Keep in mind that the setting is machine-wide: it applies to every account on the PC, including yours. When you need to install a trusted program from its website, switch to a less strict option, install, and switch back, or install it from an administrator account.

S mode: Store-only by design

Some laptops, especially inexpensive education models, ship with Windows 11 in S mode, which runs only Microsoft Store apps. For a child's laptop or a relative who only needs a browser, email and Office, S mode is an excellent lock that cannot be changed accidentally. It can be switched off for free in Settings > System > Activation, but the switch is one-way: once out of S mode, you cannot go back without reinstalling. Leave it on if every app the person needs is in the Store.

To check whether a PC is in S mode, open Settings > System > About and look at the edition line, which reads "Windows 11 Home in S mode" or similar.

🧭 NEW HERE? READ THESE FIRST

Locking down a shared or family PC? These five pages pair with this one:

📌 Bookmark this; standard accounts plus Store-only stops nearly every unwanted install.

Children: Family Safety approvals

For children's accounts managed through Microsoft Family Safety, turn on Ask a parent for Store downloads and purchases. When a child tries to get an app or game, the parent receives a request in the Family Safety app or by email and can approve or decline it. Content filters can limit apps and games by age rating, and screen time limits apply per app. Combined with a standard account, a child cannot install desktop programs, and Store installs wait for a parent. Our guide to Family Safety and screen time covers the settings.

Approval requests expire if not answered, so check the Family Safety app regularly, and talk with children about why some requests are declined; most families find that a quick conversation works better than silent blocking.

Store age ratings and purchases

Family Safety's Content filters let you set an age limit for apps and games; anything rated above it requires approval. Purchases can require approval too, and you can add money to a child's Microsoft account balance instead of attaching a card, which caps spending. For adults on a shared PC, the Microsoft Store's own settings can require a password for purchases, so nobody buys apps on your account by accident.

Ratings follow the regional rating systems, such as ESRB in the United States, so the limits match what parents already see on game boxes. Review the limit once a year as children grow, rather than approving the same requests one by one.

Game launchers and mods

Games bring their own install routes: launchers such as Steam and Epic install games without Windows administrator prompts once the launcher itself is installed, and game mods are often downloaded from fan sites. If a child has a launcher, use its own family or parental settings, such as Steam Family View, to control what can be installed and played. Teach that mods come only from official mod platforms or well-known sites, since fake mods are a common way malware reaches gaming PCs, exactly as with Ethan's sister's teenager.

Also check the launcher's own startup and auto-update settings, so games do not install large updates or new titles while the child is supposed to be doing homework.

Group Policy options (Pro and above)

Press Windows + R and run gpedit.msc. Useful policies include:

  • Computer Configuration > Administrative Templates > Windows Components > Windows Installer > Turn off Windows Installer: set to Enabled and choose For non-managed applications only or Always to stop MSI-based installs.
  • Prohibit User Installs in the same folder: stops per-user MSI installs.
  • User Configuration > Administrative Templates > Control Panel > Programs: settings such as Hide "Get Programs" page and, on older systems, Hide the "Add a program from CD-ROM or floppy disk" option, which the original version of this page described.
  • Windows Components > Store: on editions that support it, options to turn off the Store app.

Policies apply to everyone on the PC (Computer Configuration) or to all users (User Configuration) unless you use per-user policy files. Test with a standard account after changing them. Many installers are not MSI-based, so Windows Installer policies alone are not a complete block; combine them with standard accounts.

Block programs from USB drives and discs

To stop programs being run or copied from USB sticks, external drives and discs, Pro editions have policies under Computer Configuration > Administrative Templates > System > Removable Storage Access, such as Removable Disks: Deny execute access and All Removable Storage classes: Deny all access. Deny execute access still allows copying documents but blocks running programs straight from the drive. Microsoft Defender also scans removable drives when they are opened. Home editions do not have these policies; standard accounts and the Store-only setting are the practical protection there.

These policies also stop autorun-style tricks where a program on a USB stick starts automatically; Windows already disables autorun for USB drives by default, but the policies add a firm second layer on shared PCs.

The strictest option: App Control and AppLocker

For a PC that must run only approved programs, such as a kiosk, a shop computer or a child's dedicated study PC, Windows offers allow-list technologies. App Control for Business (formerly Windows Defender Application Control) and AppLocker define which programs, publishers or folders may run; everything else is blocked. AppLocker's management console is in Enterprise and Education editions, while App Control policies can be deployed on more editions with the right tools. They are powerful but easy to get wrong: a careless rule can block Windows components or updates. Test in audit mode first, keep an administrator way back in, and document every rule. For homes, they are usually more than needed.

Common mistakes to avoid

  • Giving every family member an administrator account "so they do not have to ask".
  • Saving the administrator password in the browser, where anyone using the PC can see it.
  • Turning off User Account Control to stop prompts.
  • Relying on Group Policy alone without standard accounts.
  • Forgetting Store purchases and game launchers, which bypass desktop install rules.
  • Locking down so tightly that people look for workarounds instead of asking.

Each of these turns a careful setup into one that only looks safe. Avoid them and the simple layers on this page do most of the work.

Teach safe downloading too

Restrictions work best alongside a little education. Show family members the safe sources: the Microsoft Store, official developer sites and well-known game platforms. Explain that "free full version" downloads, search ads for software and unexpected email attachments are the usual traps. Encourage them to ask before installing anything, and to report pop-ups rather than click them. Ethan's sister's teenagers now check with her first, and the PC has had no surprises since.

Children in particular respond better when they understand the reason. A rule that says "ask first because fake downloads can steal your game account" sticks better than a blanket no.

Smart App Control

On Windows 11 PCs where it is available and turned on, Smart App Control blocks apps that are unsigned or unknown to Microsoft's reputation service, which stops many sketchy installers automatically. Check it in Windows Security > App & browser control > Smart App Control. It cannot allow individual apps, which makes it unsuitable for some households, but on PCs used mainly for browsing, school and mainstream apps it adds protection with no effort.

If Smart App Control is off and grayed out, it was turned off at some point or the PC did not qualify during evaluation; on older versions it can only be turned back on with a reset of Windows, while recent versions allow turning it on again from the same page.

Test unknown programs in Windows Sandbox

On Windows 11 Pro and Enterprise, Windows Sandbox gives a disposable, isolated copy of Windows for trying a program you are unsure about. Turn it on in Settings > System > Optional features > More Windows features, check Windows Sandbox, and restart. Open Sandbox from Start, copy the installer into it, and run it there. When you close Sandbox, everything inside is deleted. It is the safest way for an administrator to check an unfamiliar program before installing it for real.

Windows Sandbox is not available on Windows 11 Home and needs virtualization turned on in the PC's firmware. On Home, a second spare standard account is a reasonable, if weaker, way to try a program without touching your main files.

Kiosk mode for single-purpose PCs

For a PC that should run one app only, such as a family recipe screen, a shop counter or a reception sign-in, Windows offers kiosk mode (assigned access). In Settings > Accounts > Other users, choose Set up a kiosk, create a kiosk account and pick the app. That account then runs only that app full screen; nothing else can be opened or installed. Sign out with Ctrl + Alt + Delete to return to normal accounts.

Kiosk setup from Settings is available on Windows 11 Pro, Enterprise and Education. It is the strongest lock on this page, but it suits only PCs that truly do one job.

Browser extensions and web downloads

Unwanted software often arrives through the browser: extensions that inject ads, or downloads from fake sites. Restrict extensions with the browser's own policies or family settings, as our guide to blocking Edge extensions shows, and keep Microsoft Defender SmartScreen on in Windows Security > App & browser control > Reputation-based protection, with Potentially unwanted app blocking turned on for both apps and downloads.

Many browsers also let families block downloads of executable files entirely through policies or family settings, which stops installers from being saved in the first place.

In Microsoft Edge, child accounts in Family Safety get Kids Mode and filtered browsing, and extension installs can be limited through Edge policies on Pro editions.

Windows 10 differences

On Windows 10, the same layers apply: standard accounts, the Choose where to get apps setting under Settings > Apps > Apps & features, Family Safety, and the same Group Policy paths on Pro. Smart App Control is a Windows 11 feature only. Windows 10 reached end of support in October 2025, so a locked-down Windows 10 PC also misses security updates unless enrolled in Extended Security Updates; combine restrictions with a plan to upgrade.

Everything else on this page, from standard accounts to Store approvals, works the same way on both versions, so a mixed household can use one plan.

Keep User Account Control on

User Account Control (UAC) is the prompt that asks for permission or an administrator password before changes. Turning it off, as some old guides suggest, removes the main barrier between standard users and installs. Keep it at the default level or higher in Control Panel > User Accounts > Change User Account Control settings. If the slider is grayed out, a policy controls it; our guide to UAC grayed out explains why.

For extra strictness, set UAC to Always notify, which prompts even for administrator accounts whenever programs try to change settings; it is a good choice for the main administrator account on family PCs.

Create a restore point before installing for others

When you approve an install for someone else, take a moment to create a System Restore point first, especially for utilities, drivers or games with anti-cheat software. If the install causes problems, rolling back is quicker than troubleshooting. Our guide to System Restore shows how.

Restore points cover system files, drivers, the registry and installed programs, but not your personal documents, so they are a safety net for installs rather than a backup. Creating one takes under a minute and costs nothing, which makes it an easy habit to keep.

"Just for me" installs that get through

Some programs install into the user's own profile, under %LocalAppData%\Programs, without administrator rights. Chat apps, code editors and some games do this. Standard accounts cannot stop them. The Store-only setting, Smart App Control, App Control policies, or Family Safety's app limits can. If such an app slips through, an administrator can remove it from the user's account, or the user can uninstall it from Installed apps in their own account.

Per-user apps appear only in that user's Start menu and Installed apps, so check each account rather than only your own when reviewing what has arrived.

Stop programs installing other programs

Unwanted software often arrives inside the installer of something wanted: a free converter that also installs a toolbar, or an updater that adds new tools later. Standard accounts block many of these, but administrators installing software must still read each setup screen and choose Custom install. Turn on Potentially unwanted app blocking in Windows Security so Defender catches known bundles. And remove auto-updaters for programs you no longer use; they are a quiet route for new software.

A good rule: if an installer shows a pre-checked offer for software you did not ask for, uncheck it, and if it will not let you decline, cancel and find another program.

Review what was installed

Once restrictions are in place, check periodically. In each account, Settings > Apps > Installed apps, sorted by install date, shows new arrivals. Family Safety's activity reports show apps used by children. Event Viewer's Application log records MSI installs with source MsiInstaller and event 11707. A quick monthly look keeps surprises small; our guide to uninstalling programs covers removing anything unwanted.

A short monthly review also catches apps installed legitimately but no longer needed, which keeps the PC lean as well as safe.

Sorting by date is the quickest view: anything installed since your last check sits at the top, and anything you do not recognize deserves a quick search before you decide whether to keep it.

Signs that something was installed without permission

  • New icons in Start, the taskbar or the tray that nobody recognizes.
  • A changed browser home page or search engine.
  • New pop-ups or ads, especially outside the browser.
  • The PC running hot or fans spinning when idle, a classic sign of hidden cryptocurrency miners.
  • Unknown entries in Settings > Apps > Startup.

Any of these deserves a look at Installed apps, sorted by date, and a Microsoft Defender full scan.

Do not wait for all of them at once; one clear sign is enough reason to check.

Removing what slipped through

Uninstall unknown programs from Settings > Apps > Installed apps in each account, reset browsers that were changed, and remove unknown extensions. Run a Microsoft Defender full scan, then a Microsoft Defender Offline scan, which catches threats that hide while Windows runs. Check startup apps and scheduled tasks for anything that would reinstall what you removed. Then put the restrictions on this page in place, so it does not happen again.

If anything resists removal or keeps coming back, change the passwords for the affected accounts from another device as well, in case the unwanted program captured them.

A simple plan for a small office

Small offices without an IT department can still control installs with very little effort. The steps below take about an hour for a handful of PCs and avoid most of the problems that bring a small business to a standstill.

  1. Choose one person, or an outside IT helper, to hold administrator rights on every PC.
  2. Create a standard account for each employee, using their work Microsoft account or a local account.
  3. On each PC, set Choose where to get apps to Microsoft Store only or to warn before non-Store installs.
  4. Turn on Smart App Control where it is available, and Potentially unwanted app blocking everywhere.
  5. Keep a short shared list of approved programs and where to download them.
  6. Agree a simple way to ask for new software, such as an email to the administrator.
  7. Review installed apps on each PC once a month, using the Installed apps list sorted by date.

Once the office grows past ten or so PCs, Microsoft Intune with Business Premium licenses makes the same rules central and automatic, so nobody has to visit each desk.

Which method fits which situation

Situation Best method Edition needed
Family PC with childrenStandard accounts plus Family SafetyAny
Shared PC for adultsStandard accounts plus app source settingAny
Relative who only browsesS mode or Store-only settingAny
Small officeStandard accounts plus Group PolicyPro
Single-purpose screenKiosk modePro or higher
Company fleetIntune with App Control for BusinessPro, Enterprise or Education

Start with the lightest method that fits, then add a layer only when a real problem shows up. Most families never need anything beyond the first two rows.

Remember that the layers stack: a family PC can use standard accounts, Family Safety and the app source setting together, with no conflict between them.

The portable app gap

Standard accounts stop programs that need to install into Program Files or change system settings, but they do not stop portable apps, programs that run straight from a downloaded folder or USB stick without installing. A standard user can download a portable browser, game or tool into their Downloads folder and run it. For most families that is an acceptable gap, since portable apps cannot change the system or other accounts.

If it matters, the app source setting and Smart App Control both check portable programs when they first run, and Microsoft Defender scans them like any other file. On Pro editions, AppLocker or App Control for Business can block programs running from user folders such as Downloads and AppData, which closes the gap completely. That is a step for offices; at home, the warnings plus a monthly look at what is in each user's Downloads folder are usually enough.

Microsoft account or local account for family members

Family Safety features such as app approvals, content ratings and activity reports need each child to sign in with a Microsoft account that belongs to your family group. Local accounts can still be standard users, which blocks most installs, but they get none of the Family Safety controls. For adults on a shared PC, either type works; a Microsoft account adds password recovery and OneDrive, while a local account keeps things simple for visitors.

To add a child, open Settings > Accounts > Family, choose Add someone, and create or invite their account. Windows makes child accounts standard users by default, so the main lock is in place the moment they sign in.

Approving installs when you are not home

Family Safety sends app and game requests to the Family Safety app on your phone, so you can approve or decline from anywhere. For desktop programs that need an administrator password, Quick Assist, built into Windows, lets you connect to the family PC from your own PC with the other person's permission and type the password into the prompt yourself. You never have to read the password over the phone, and the session ends as soon as either side closes it.

Only use Quick Assist with people you know who contacted you, never with a caller who claims to be from Microsoft or a bank. Scammers ask victims to start Quick Assist precisely because it is trusted.

Do third-party security suites help?

Many paid security suites add parental controls, application control or "trusted programs" lists. They can help, but they overlap with what Windows already offers, and two sets of controls can conflict or confuse family members. For most homes, Windows' own layers, standard accounts, the app source setting, Smart App Control, Defender and Family Safety, cover the job at no extra cost. Consider a suite only if it offers a specific feature you need that Windows lacks, and remove any trial suite that came with the PC if you are not going to pay for it.

Why older advice on this page changed

Years ago, guides to blocking installs mostly meant hiding the Add or Remove Programs page, blocking installs from CD or DVD, or turning off Windows Installer through policy. Those tricks made sense when software arrived on discs and every program used the Windows Installer. Today most programs are downloaded, many installers do not use Windows Installer at all, and Store apps and per-user installs bypass the old switches entirely. Hiding the Programs page only stops people uninstalling things; it does nothing to stop new installs.

The modern approach on this page works at a different level: it controls who has the right to install system-wide, where programs may come from, and which programs Windows trusts to run. That is why standard accounts, the app source setting and Smart App Control replace the old disc-era policies, and why the old ones are only worth keeping on very old PCs that still use them.

What users see when an install is blocked

It helps to tell family members what to expect, so a block does not look like an error. A standard user who runs a desktop installer sees a User Account Control prompt asking for an administrator password. With the app source setting on Store only, Windows shows a message that the app is not from the Microsoft Store and offers to look for a Store alternative. Smart App Control shows that it blocked a program that might be unsafe. A child's Store request shows a note that a parent has been asked.

None of these messages mean the PC is broken. Explain each one in advance, and agree that the right response is to ask, not to search for a way around it.

How to undo the restrictions later

Every layer on this page can be reversed, so nothing here is a permanent decision. To give someone install rights again, change their account to administrator in Settings > Accounts > Other users. To allow downloads from anywhere, set Choose where to get apps back to Anywhere. Family Safety settings change from the Family Safety app or website, and a child account can be removed from the family group once they are adults. Group Policy settings go back to Not configured, and kiosk accounts are removed from the same Settings page that created them.

The two exceptions are S mode, which cannot be turned back on once switched off, and Smart App Control on older Windows 11 versions, which needs a reset to turn on again. Think twice before switching either of those off on a PC where they are doing their job well.

Before reversing any layer, note what you changed and why, so you can put it back quickly if the original problem returns. A short note in the same password manager entry as the administrator password is an easy place to keep it.

If you have Windows 11 Home

Windows 11 Home lacks Group Policy, AppLocker, Windows Sandbox and kiosk setup from Settings, but it still has everything most households need. Standard accounts, the Choose where to get apps setting, Smart App Control, Family Safety and Potentially unwanted app blocking all work on Home. You do not need to upgrade to Pro just to stop unwanted installs; the Pro-only tools mostly matter for offices.

Guides that tell Home users to enable Group Policy with unofficial scripts are best avoided. The policies may appear but often do not apply as expected, and the scripts themselves come from unknown sources, which defeats the purpose of locking the PC down.

Letting someone install just once

Sometimes a trusted family member needs to install one program, such as homework software from school. Rather than handing over the administrator password, sit with them and type it into the User Account Control prompt yourself. If you cannot be there, you can temporarily change their account to administrator in Settings > Accounts > Other users, let them install, and change it back to standard straight after. Set a reminder so the temporary change does not become permanent by accident.

For children, Family Safety's Ask to buy and app approval requests handle this from your phone, which is usually easier than either option.

Lock-down checklist

  • Everyone except the maintainer uses a standard account.
  • The administrator password is strong, private and stored safely.
  • User Account Control is on, ideally at Always notify for the administrator.
  • The app source setting matches how the PC is used.
  • Smart App Control is on where available.
  • Potentially unwanted app blocking is on in Windows Security.
  • Children have child accounts in Family Safety with Store approvals.
  • Game launchers have their own family settings turned on.
  • Installed apps are reviewed monthly.
  • A restore point exists before any approved install.

If every item is checked, unwanted installs become rare, and the few that slip through are caught quickly.

For IT admins: controlling software at scale

Least privilege. Remove local administrator rights from users; use Windows LAPS to manage the local administrator password, and provide an approved app catalog through Intune's Company Portal.

Allow-listing. Deploy App Control for Business with managed installer rules so apps deployed by Intune are trusted automatically, and audit before enforcing. Block MSI user installs and per-user installs by policy where appropriate.

Requests. Give users a simple way to request software, such as a form or the Company Portal; blocks work best when there is an easy, legitimate route to what people need.

Blocking software installs: frequently asked questions

How do I stop someone installing programs on my PC?

Give them a standard user account and keep the only administrator password to yourself.

Can standard users install software?

Not most desktop programs. Some per-user apps and Store apps can install without administrator rights.

How do I allow only Microsoft Store apps?

Settings, Apps, Advanced app settings, Choose where to get apps, The Microsoft Store only.

How do I stop my child installing games?

Use a child account with Family Safety's Ask a parent setting and a standard account.

Does Windows Home have Group Policy?

No. Use standard accounts, Store-only and Family Safety on Home.

How do I block MSI installers?

On Pro, enable Turn off Windows Installer and Prohibit User Installs in Group Policy.

Can I block programs from USB drives?

On Pro, Removable Disks: Deny execute access blocks running programs from USB drives.

What is App Control for Business?

An allow-list technology that lets only approved apps run. Powerful, best for organizations.

Should I turn off UAC?

No. UAC is what requires an administrator password for installs.

Why did an app install without an admin password?

It installs per user. Use Store-only or Smart App Control to block such installers.

How do I see what was installed recently?

Installed apps, sorted by install date, in each user account.

Does Smart App Control block installs?

It blocks unsigned or unknown apps, including many installers, when it is on.

How do I make myself a standard user safely?

Create a separate administrator account first, then change your daily account to Standard.

What does the old "Add a program from CD-ROM" policy do?

It hid an option in the old Control Panel; modern Windows needs the methods above instead.

Can I block browser extensions?

Yes, with browser policies or family settings. Our extensions guide shows how.

Will these settings block Windows updates?

No. Windows Update installs as the system, not as the user.

Can I approve installs remotely?

Family Safety sends Store requests to a parent's phone for approval.

How do I stop crypto miners and fake game mods?

Standard accounts, Store-only, Defender with potentially unwanted app blocking, and teaching where to download safely.

Do these work on Windows 10?

Yes. Paths differ slightly, with Choose where to get apps under Apps and features.

What if I forget the administrator password?

Keep a second administrator account or a written recovery plan; resetting without one is difficult.

Can teenagers bypass a standard account?

Not without the administrator password. Keep it private and do not save it in the browser.

Is AppLocker available on Pro?

AppLocker management is mainly for Enterprise and Education; App Control policies have wider support.

Should I use third-party parental control software?

Family Safety covers most needs built in. Third-party tools add features but also intercept traffic and need trust.

Ethan's sister's desktop has stayed clean for months now. The teenagers still get the apps they need; they just ask first, and most requests take a tap on her phone to approve. The mistake that had caused everything was simple and common: every account was an administrator. Restricting installs is less about locks and more about roles. One person holds the key, everyone else uses the PC freely, and new software arrives only when someone decides it should.

📌 If you keep one line from this page

Standard accounts for everyone, one private administrator, and Store-only apps stop nearly every unwanted install.

Add Family Safety approvals for children, and policies or App Control only where you need more.

Revision note. Written October 2, 2026, rewriting our 2015 CD-ROM policy tip into a complete guide to controlling installs on Windows 11 and 10. May your PC run only what you chose.

Related