Policy CSP - SmartScreen


SmartScreen policies

SmartScreen/EnableAppInstallControl
SmartScreen/EnableSmartScreenInShell
SmartScreen/PreventOverrideForFilesInShell

SmartScreen/EnableAppInstallControl

Windows Edition Supported?
Home cross mark
Pro check mark2
Business check mark2
Enterprise check mark2
Education check mark2

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to control whether users are allowed to install apps from places other than the Store.

Note

This policy will block installation only while the device is online. To block offline installation too, SmartScreen/PreventOverrideForFilesInShell and SmartScreen/EnableSmartScreenInShell policies should also be enabled.

This policy setting is intended to prevent malicious content from affecting your user's devices when downloading executable content from the internet.

ADMX Info:

  • GP English name: Configure App Install Control
  • GP name: ConfigureAppInstallControl
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Turns off Application Installation Control, allowing users to download and install files from anywhere on the web.
  • 1 – Turns on Application Installation Control, allowing users to only install apps from the Store.

SmartScreen/EnableSmartScreenInShell

Windows Edition Supported?
Home cross mark
Pro check mark2
Business check mark2
Enterprise check mark2
Education check mark2

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to configure SmartScreen for Windows.

ADMX Info:

  • GP English name: Configure Windows Defender SmartScreen
  • GP name: ShellConfigureSmartScreen
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Turns off SmartScreen in Windows.
  • 1 – Turns on SmartScreen in Windows.

SmartScreen/PreventOverrideForFilesInShell

Windows Edition Supported?
Home cross mark
Pro check mark2
Business check mark2
Enterprise check mark2
Education check mark2

Scope:

  • Device

Added in Windows 10, version 1703. Allows IT Admins to control whether users can ignore SmartScreen warnings and run malicious files.

ADMX Info:

  • GP English name: Configure Windows Defender SmartScreen
  • GP name: ShellConfigureSmartScreen
  • GP element: ShellConfigureSmartScreen_Dropdown
  • GP path: Windows Components/Windows Defender SmartScreen/Explorer
  • GP ADMX file name: SmartScreen.admx

The following list shows the supported values:

  • 0 – Employees can ignore SmartScreen warnings and run malicious files.
  • 1 – Employees cannot ignore SmartScreen warnings and run malicious files.

Footnotes:

  • 1 - Available in Windows 10, version 1607.
  • 2 - Available in Windows 10, version 1703.
  • 3 - Available in Windows 10, version 1709.
  • 4 - Available in Windows 10, version 1803.
  • 5 - Available in Windows 10, version 1809.
  • 6 - Available in Windows 10, version 1903.
  • 7 - Available in Windows 10, version 1909.
  • 8 - Available in Windows 10, version 2004.