Policy CSP - SmartScreen


SmartScreen policies

SmartScreen/EnableAppInstallControl
SmartScreen/EnableSmartScreenInShell
SmartScreen/PreventOverrideForFilesInShell

SmartScreen/EnableAppInstallControl

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to control whether users are allowed to install apps from places other than the Store.

Note

This policy will block installation only while the device is online. To block offline installation too, SmartScreen/PreventOverrideForFilesInShell and SmartScreen/EnableSmartScreenInShell policies should also be enabled.

ADMX Info:

  • GP English name: Configure App Install Control
  • GP name: ConfigureAppInstallControl
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Turns off Application Installation Control, allowing users to download and install files from anywhere on the web.
  • 1 – Turns on Application Installation Control, allowing users to only install apps from the Store.

SmartScreen/EnableSmartScreenInShell

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to configure SmartScreen for Windows.

ADMX Info:

  • GP English name: Configure Windows Defender SmartScreen
  • GP name: ShellConfigureSmartScreen
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Turns off SmartScreen in Windows.
  • 1 – Turns on SmartScreen in Windows.

SmartScreen/PreventOverrideForFilesInShell

Home Pro Business Enterprise Education Mobile Mobile Enterprise
cross mark check mark2 check mark2 check mark2 check mark2 cross mark cross mark

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to control whether users can ignore SmartScreen warnings and run malicious files.

ADMX Info:

  • GP English name: Configure Windows Defender SmartScreen
  • GP name: ShellConfigureSmartScreen
  • GP element: ShellConfigureSmartScreen_Dropdown
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Employees can ignore SmartScreen warnings and run malicious files.
  • 1 – Employees cannot ignore SmartScreen warnings and run malicious files.

Footnote:

  • 1 - Added in Windows 10, version 1607.
  • 2 - Added in Windows 10, version 1703.
  • 3 - Added in Windows 10, version 1709.
  • 4 - Added in Windows 10, version 1803.