Operating room developers Windows systems created an option that limits what users can do on the computer. These restrictions are set independently by any user who has access to the administrator account on the computer.

Instructions

  1. To set any ban on a computer, administrator rights are required. To manage restrictions, you need to open the special section “Local Security Settings”, to do this, use the Win+R key combination and enter secpol.msc, press Enter.
  2. Go to Software Restriction Policy

    and in the “Object Type” command group, select the “Assigned File Types” command. The window will load a list of file formats that relate to the executable code.

  3. To prohibit the use of programs, you must exclude from this list corresponding types. For example, to prohibit the use Excel programs select the corresponding item in the existing list and execute the “Delete” command, also delete the program shortcut, it has LNK format. Save the changes by clicking on the OK button.

  4. Go to the “Enforce” section and in the “Enforce restriction policies” drop-down list, check the “For everyone except local administrators” command.

    Go to the “Security Levels” directory and select the “Unrestricted” section, select the “Default” value and save the settings with the OK button.

  5. Open the Security Levels category and select the Unlimited option. Select the Default option and click OK.
  6. After completing all the described steps, all users except administrators will be able to use only authorized applications. All programs are installed in the Program Files or SystemRoot directory. If you installed programs yourself in other folders, then they need to be added to the allowed list.
  7. Open the Additional Rules window and click in the empty space in the Name section. Click the “Create path rule” option and specify the path to the program directory.
  8. To prevent other users from adding additional software to the specified folders, you need to set an additional restriction. Call for desired folder context menu and press " General access and Security", on the "Security" page, set the permission for the desired users.
  9. Click "Advanced" and open the "Permissions" tab. Specify users and click “Edit”, in the loaded window, mark the allowed actions for these users.

Video: How to prevent installation of programs in Windows 7

Unchecky is a free program to prevent potentially unwanted software (PUP) from being installed on your computer. Quite often, there are situations when various programs, toolbars, etc., penetrate the computer in a not entirely direct way.

The Unchecky program removes checkmarks during the installation of programs on the computer and rejects installation offers unwanted programs.

Many users have probably encountered this situation many times when they discovered new programs on their computer. Moreover, such applications were installed in a secret way, often without any explicit knowledge of the user.

Manufacturers of programs, the usefulness of which is not always obvious, of various toolbars for browsers, also of dubious value, very often integrate their applications into installers, mainly free programs. Of course, for installation in a similar way, they also offer completely useful programs, but such programs can be installed, if necessary, on your computer in the usual way.

Manufacturers of free programs who supplement their installers with such additional software thus earn money, often for the development of their product, receiving money for this from the producers of other additionally installed programs.

You've probably often encountered a situation where, when installing a program, the installation wizard prompts you to install additional software. In such cases, it is often suggested to install various software (PUP - Potentially Unwanted Program), which is not at all necessary for the user.

More experienced users, already taught by bitter experience, always carefully monitor the contents of the installation wizard windows during installation new program to your computer. Less experienced users sometimes do not pay attention to this. Then they are surprised that new programs or toolbars appear on their computer in browsers that they did not install.

Manufacturers often cheat by offering the user a choice to install the program. For example, options often offered include: normal or quick installation (recommended) and custom installation (for advanced users).

  • Quick installation (recommended) - in this case, along with the installation of the program, automatic installation additional applications.
  • Custom installation (for experienced users) - you yourself can uncheck the boxes where you will be asked to install additional programs.

In some cases, even if you clear all the boxes next to unwanted software, additional programs are still installed.

You could just put up with installing some programs. Moreover, they can then be deleted from the computer. But some “malicious” applications install toolbars in browsers, change settings or home page browser. Removing such unwanted programs is often very difficult.

The free Unchecky program is designed to prevent unwanted programs from being installed on your computer. The program has Russian language support.

Unchecky download

Unchecky installation

After running the executable file, the “Install Unchecky” window will open. To install the program on your computer, you will need to click on the “Install” button.

If you want to install the Unchecky program not in the default folder, but in another folder, then, before installing the application on your computer, you will need to click on the “More settings” button.

In the window that opens, you can change the folder for installing the program. Using the "Browse..." button you can select a different folder if you are not satisfied with the default folder selection.

Immediately after the installation of the program is completed, a window will open with a message that the Unchecky program service has started. Click on the “Done” button in this window.

The Unchecky program service runs in background. When you install a new program on your computer, Unchecky will monitor the progress of the new application's installation, protecting your computer from the installation of potentially unwanted software.

If necessary, you can open the Unchecky program window from the program shortcut on the Desktop.

The main “Unchecky” window informs you that “The Unchecky Service has started.”

If necessary, you can pause the program. To do this, you will need to click on the “Suspend” button.

After this, a window will open warning you about stopping the Unchecky service. You can restart the service after restarting the system. To do this, you will need to click on the “Resume” button.

Unchecky settings

You can enter the program settings after clicking on the “Settings” button. Here you can select the language for the program interface. The Unchecky utility supports a fairly large number of languages.

In this window you can also enter advanced settings by clicking on the “Advanced settings” button.

In the new “Advanced Settings” window you can change some program settings. The author of the program does not recommend changing the settings, especially if you do not know what they are for. Changing the settings will make Unchecky less effective.

All settings take effect after restarting the service.

After installing the Unchecky program on your computer, additional rules added there by the Unchecky program will be written to the “hosts” file, which is located in the “Windows” folder. These rules are used to block the installation of unwanted software on a user's computer.

Blocking the installation of potentially unwanted programs

Now, when installing new programs on your computer, all offers to install additional programs will be rejected. During the process of installing new programs on your computer, you will not need to make unnecessary mouse clicks while rejecting unnecessary, additional and advertising offers.

If, when installing a new program on your computer, the installer of the installed program contains offers to install additional programs, then you will see the Unchecky program window that opens.

In this case, you will be warned about installing a potentially unwanted program. In the notification area, you will see a message from Unckecky indicating that offers to install potentially unwanted programs have been rejected. You can click on this post for details.

If there are several such offers to install additional software, then several Unchecky program windows will be opened one by one, in which you will be informed about the refusal of these offers.

This way, the potentially unwanted program will not be installed on your computer.

The Unchecky program basically reliably blocks potentially unwanted programs from entering your computer. In some cases, extraneous software It can still be installed on your computer. The developer of the Unchecky program, Michael Maltsev (RaMMicHaeL), is making efforts to improve his program to provide a more reliable barrier against such penetration.

Conclusions of the article

The free Unchecky program prevents the installation of potentially unwanted programs on the user's computer. Unchecky automatically unchecks boxes during the installation of third-party software.

Unchecky - protection against installation of unwanted programs (video)

Good day.

There are often situations when several users work on one computer at once. And it often happens that some of them constantly install a variety of software on the device, not only “opening the door” for viruses, but also simply clogging HDD. The seventh version of the Microsoft operating system provides several tools that allow you to limit the possibilities described above. In this article I will tell you how to prevent other users from installing programs on Windows 7. Believe me, this move will significantly increase safety.

Group Policy Editor(to contents)

One of the most simple ways Restricting movements of other users is the use of group policies. To achieve the desired effect, we perform several actions:

Let's go to " Start" and then in " Execute" Alternatively, you can simply press the combination “ Win+R».

Then we write “ gpedit.msc».

The window we need will open, where we need to go to “ Administrative Templates».

Here we are interested in " Windows Installer».

Under the line " State" find " Deny installer" Open and select the checkbox on “ Disable».

This will completely prohibit the installation of any software on the unit. To return everything to its place, you need to toggle the checkbox back. Another effective way is to reinstall the operating system and first format the main disk.

Ban a specific account(to contents)

Windows x64 also provides the ability to ban a specific user. To do this you need to take several steps:

Open " Execute" and write " mmc».

Then we go to the “ File" and select " Add equipment...».

The panel we need will appear.

Select " Group policies" And " Add».

A new window will open where we indicate “ Review" We need a tab " Users" Then we indicate a suitable user. We confirm our intentions.

Now we repeat all the points that were indicated in the previous method. But now the ban will only apply to a specific other user.

Parental control(to contents)

This method is considered to be as simple and convenient as possible for implementation. It allows you to limit movements if the user installs a lot of unnecessary software from the Internet. You need to perform a number of actions:

Let's go to " Start" And " Control Panel».

We are interested in " user accounts».

We indicate the user to whom the ban should apply.

Then select " Restrictions on running programs».

A console will appear where we select the items that we want to prohibit.

If suitable security is not on the list, we go to “ Review", where we find what we need.

As you can see, this makes it possible to quickly and easily limit the installation ability of an ordinary user.

Registry Editor(to contents)

An equally effective way is to use “ Registry Editor" Where is this tool located and how to use it? It's simple:

Click " Win+R" As a result, the menu “ Execute».

We indicate in the line “ regedit.exe».

A window will appear, on the left side of which we go to the directory “ HKEY_CURRENT_USER" and then in " Software».

Afterwards we are interested in “ Microsoft" And " Windows».

As a result, we need the directory " DisallowRun».

On the right side of the window, right-click and create a text parameter. We give it a name " 1 ", and inside we add the name of the application that needs to be blocked. In this case, it must match the executive file with the extension *.exe.

If you need to ban more than one program, accordingly we create additional parameters, which we call numbers in order, and inside we indicate the applications.

Afterwards, no software downloaded automatically for free from the Internet will be able to be installed.

It is worth noting that this tool allows you to prohibit the installation of any applications without a password.

It is important to take into account that depending on the assembly, some points may differ slightly. For example, the “Maximum” and “Home Basic” versions are different. Despite this, users will definitely understand the sequence of actions.

Due to the fact that the operating system itself provides a lot of tools, additional software on this topic, although it was developed, still did not receive mass approval, and therefore is simply not popular. At the same time, we did not consider turning it off using the program.

If suddenly after reading the article you still have some questions, you can watch a video on this topic.

I hope you achieve your desired goals. Subscribe and tell others.

How to prevent a user from installing Windows 7 programs

Many system administrators, laboratory assistants and people responsible for the performance of computers in computer clubs, classes and even at home are faced with the need to prohibit the installation of applications on Windows 7. This can be done using third party applications, for example, WinGuard Pro 2016, but we will try to implement a ban on installing programs using the “seven” tools.

Blocking the installer's work

To prevent any user from installing programs, you need to block the Windows Installer using the Group Policy Editor.

  • Enter “gredit.msc” in search bar or the “Run” window (called via “Win ​​+ R”).
  • We follow the path: “ Local computer» → “Computer Configuration” and double-click on “Administrative Templates”.

  • Select the check boxes for applications that are allowed to run.
  • If a product is missing, use the “Browse” button.

    After the user's next login, the ban will take effect.

    Prevent installation of programs - Windows XP

    Hello everyone! It was decided to do it in the office impossible installation programs to all users from other accounts. I searched the entire Internet, but I still couldn’t find anything that would satisfy all the requirements.
    1) Prohibition of installing programs using secpol.msc: if configured this way, then all user accounts, even “Administrator”, will be affected by the policy;
    2) Prohibition of installing and launching programs using the registry editor (using the example here): the same thing, it is impossible to install programs from the “Administrator” account;
    3) A regular limited account does not give anything

    How else can you limit the user's actions?

    Added after 21 hours 51 minutes
    Guys, seriously, how can you restrict a user’s actions to install programs if a limited account does not restrict anything?

    Prohibition on installation of new equipment
    Good day. Need your advice. The situation is as follows: there are two on the cop.

    Cancellation of the ban on installing programs
    At installing Visual C++ Redistributable message appears that installation.

    How to disable installation of programs for individual users?
    I have a problem - there are gamers in the family. They play half the night and sleep half the day. Fine.

    Preventing some programs from running
    Please tell me how to disable permission for some programs for the user.

    Allowing and prohibiting programs from running
    Hello, the boss has set the task to do this on users’ computers.

    Windows XP Home Edition 2002 prevents programs from starting
    How to administer Windows XP Home Edition 2002 to prevent it from starting.

    Now I tested it on a virtual machine. I created Admin and User (corresponding rights). I run under User installation programs. I gave User rights, went into Group Policy, User Configuration, put several programs on a white sheet, changed the User account type, logged in under it, tried to run the installation as Admin - beard... and all programs stopped under Administrator run, but I only need it under User

    Added after 53 minutes
    In the Security tab, I put a complete ban on one folder in the “Users” group, now I can’t get access as an admin! There is no admin in the user group. what kind of space I had to just add the user separately. but the question of the user launching programs without harming the administrator is still open

    Added after 21 minutes
    Is it possible to create a white sheet in group policies and user configurations only for the user?

    Added after 19 hours 21 minutes
    So. ok, I solved the problem with launching programs by simply delineating rights on folders, now the user cannot launch exe files... how can I disable msi, only so that the admin can launch them?

    Added after 1 hour 55 minutes
    Even after paying attention to the message in this thread, I didn’t understand where to take away the rights to run the registry and command line from the USER

    www.cyberforum.ru

    Windows 7 Life

    Not a day without incident!

    Limiting Application Usage in Windows 7

    1. Disable or restrict the use of Windows Installer using Group Policy.

    Windows Installer(msiexec.exe) is a tool for installing, maintaining, and uninstalling Windows system software.

    In order to block the installation of applications for all users, open the Group Policy editor (gpedit.msc) and open the section Computer Configuration – Administrative Templates – Windows Components – Windows Installer Installer). On the right side of the Settings window, select the line Disable Windows Installer and double-click on it. Meaning Disable– disables the ability to install programs, value Enable turns it on. Everything is simple here.

    You can prohibit the installation of applications for a specific user (account) by creating the appropriate snap-in. To do this, open the console mmc(from the Start menu - Search) and from the File menu, select Add Snap-in. A list of all available system components will open. Select Group Police, click the right arrow to add, and then click the Browse button. Select the Users tab you want account and click Ok, and then Finish.

    After this, repeat the steps I described above, only now the ban on installing programs will apply only to the selected user.

    2) Always install with elevated privileges.

    In the Group Policy Editor, go to User Configuration - Administrative Templates - Windows Components. Scroll down and select Windows Installer and Allwaus install with elevated privileges(Always install with elevated privileges).

    This setting instructs Windows Installer to use system permissions when installing any program on the system.

    This setting applies to elevated privileges for all programs. These privileges are typically reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or available in Add or Remove Programs in Control Panel. This setting allows users to install programs that require access to directories that the user may not have permission to view or change.

    Note: If you disable this option or do not configure it, the system will enforce permissions current user(or administrator) when installing programs, i.e. with normal rights. This setting appears in the Group Policy Editor in both Computer Configuration and User Configuration. For this setting to take effect, it must be set in both sections.

    3) Don't run specified applications for Windows.

    In the Group Policy Editor, go to User Configuration - Administrative Templates - System.

    Here in the sidebar on the right, double click Do not run specified Windows applications (Do not run specified Windows applications), and in the new window that opens, select Included. Now under Options select the command Show(Show). Click Add and in the new window enter the path that opens the application you want to block, in this case: msiexec.exe.

    This will prohibit Windows operation Installer, which is located in C:\Windows\System32\msiexec.exe.

    When this setting is enabled, users can't run programs that you add to the blocked apps list.

    Note: If users have access to command line (cmd.exe), this setting does not prevent them from launching programs in a command prompt window.

    Almost every setting in Windows OS, in addition to Group Policies, is duplicated in the system registry editor. But not many people know that there is an online MSDN service on the network, which contains structured reference information on setting up a huge number of Windows functions through the system registry. It’s convenient to use, you just need to know English language. In addition, there is also a similar reference book in Excel document format, which you can download here.

    First make a backup of the registry branch below, or create a restore point.

    Open Registry Editor ( regedit.exe) and go to the next section:

    Create in section DisallowRun a string parameter named 1 and set its value to the name of the program's EXE file.

    Note: if section DisallowRun is missing, create it.

    For example, if you want to limit msiexec, create a string parameter 1 and set its value to msiexec.exe. If you want to limit more programs, then simply create more string parameters named 2, 3 and so on, and set their values ​​in the EXE program. Restart your computer.

    In Control Panel, open the User Accounts – Manage Another Account applet. Select the desired user account and set Parental Controls for it:

    In the next window, enable Parental Controls and Program Launch Restrictions:

    After building the list, select those programs that the user is allowed to run. If on the list required program is missing, you can add it manually by clicking the Browse button.

    Note: There are some conditions for allowing/blocking applications from running using Parental Controls. First, the user account for which you are introducing restrictions must be with Ordinary rights. Secondly, setting up Parental Controls must be done from an account that has the rights Administrator, which is obvious. And thirdly, the Administrator account must be password protected.

    OK it's all over Now. I wish you success in applying the tips I talked about in this article.

    volginartem.wordpress.com

    How to prevent unwanted programs from installing on Windows

    Is it annoying when software suddenly appears on your computer that you didn’t actually install? Here are some universal ways to prevent such situations.

    For most users, various additional messengers, toolbars, application managers from Mail.ru, Yandex, Amigo are useless and even unwanted software. Well, who likes it when Google search suddenly replaced by another address, stuffed with advertising? Unfortunately, the installation of such creations cannot always be tracked. But it can be prevented. Let's look at the main methods.

    Prohibition of hidden installation of programs

    One of the methods of combating hidden installation of programs (for example, when a browser is installed along with the game) is Unchecky. This program removes all additional, often invisible to the user, checkboxes with unwanted offers during the installation of a program. The utility is also capable of finding running file third party hidden programs and notify the user about it.

    Unchecky does not require any specific knowledge to use and configure. The user can only configure the program tray icon. Almost perfect, but sometimes Unchecky still leaks fresh nasty things onto your hard drive.

    You don’t have to install anything unnecessary and make do with the tools built into the operating system. Thus, Windows 7 Ultimate and Professional and Windows 8 and 8.1 have the AppLocker utility. It allows you to create a list of applications that are prohibited for installation.

    Instead of lengthy manipulations of creating your own list, you can also download a ready-made Locker settings file and install it, for which you will need to do the following:

  • go to the menu “Control Panel” → “Administration” → “Services”;
  • set the “Application Identity” service to autostart mode and click “Start”;
  • go to the menu “Control Panel” → “Administration” → “ Local politics security" → "Application management policies";
  • select the AppLocker option, call right click mouse menu, select “Import policy”, open the Locker.xml file from the archive.
  • Restricting access to your account

    There is a slightly simpler method (it also works for the previously mentioned versions of Windows):

  • go to the menu “Control Panel” → “User Accounts” → “Manage another account” → “Create a (new) account”;
  • select the account name (for example, User), check the box next to “Regular access (Users)” and click on the “Create account” button;
  • restart your computer.
  • During further work, you can safely use the new account - not a single malicious program will be able to install. True, the account will have to be set up from scratch and very often a window will appear asking you to run it with administrator rights.

    “Sandbox” in this context is a separate dedicated system area, option virtual machine. Processes running there can only affect their own environment, limited by access rights. At the same time, she herself operating system is not affected in any way. Thus, you can work with any files. If the application turns out to be safe, you can install it. If some executable file entails something unwanted, just rollback it and do not install it in the OS.

    The easiest way to organize such a space is Sandboxie. This program allows you to run the browser, downloaded files in sandbox mode, and also works with links, so nothing will pass by. If something unwanted gets in, you can clean it up and use your computer as if nothing had happened. There is something similar in some antivirus programs, for example in avast! Premier Antivirus or Kaspersky Internet Security.

    What to do if unwanted programs are installed

    If an unwanted program (not a virus) has been installed on your computer, you should use the simple AdwCleaner utility.

    1. Install and run the program.
    2. Click the Scan button.
    3. Click Clean at the end of the scan on the final report screen.

    Of course, there are other equally simple and convenient ways avoid installing unwanted and malware on Windows. But do not forget that the best thing is attentiveness and straight hands.

    The issue of computer system security has always been the most important for the user. As you know, viruses that penetrate inside a gadget can bring a lot of discomfort to its owner. There are no ways to 100% protect your desktop from malware, but there are ways to maximize your resistance to them.

    The most accessible one is to prohibit the installation of programs in Windows 7. This can be achieved absolutely free, and the program that will help with this is already available on most versions of Windows. The principle of operation is outrageously simple: no programs can be downloaded without the user's permission. And then you will not encounter such a problem as the appearance, as well as other problems that viruses bring. How to do it? Let's figure it out.

    How to set a limit

    First you need to open the “Local Security Policy” window. To do this, go to “Start” – “Control Panel” – “System and Security”. Next, go to “Administration”, and there you will see “Local Security Policy” - “Software Restriction Policy”. Right-click on this line and create a new software restriction policy.

    Now you need to set some settings for new policy. To do this, click on the “Application” line and check the box in the same places as in the picture below.

    After that, go to the “Assigned file types” item and feel free to delete the LNK extension. Then we go to additional folder“Security levels”, we see the “Prohibited” sub-item on the right side of the window and assign it by default (with the right mouse button).

    That's all, now all users from your computer will be able to run only those programs that you install or the system will do it for you. Usually they are located in the Program Files and SystemRoot folders, but they can be “scattered” in other folders. If this is your case, then I advise you to add these programs to the list of allowed ones. To do this, in turn, go to “Additional rules” – “Name”, right-click on the empty field. Among the other commands, select “Create a path rule” and set the path to the folder where the required program is located.

    As you can see, there is absolutely nothing complicated in these actions. It may take a few minutes to follow these rules, but think about how much you will increase the security of your computer. It wouldn’t be a shame to set aside a couple of minutes of your precious time for this, don’t you agree?

    You can increase the security of your computer if you install . This will be a good addition to the steps described above!

    Video to help

    If, out of necessity, a desktop computer or laptop is used by not one, but several users, it is quite natural that each of them can install on the system the programs that he needs for everyday work or entertainment. This can lead to unpredictable consequences, which relate to possible disruption of the functionality of the operating system.

    Prohibiting the installation of programs in Windows XP and in systems of a higher rank for one or more users at a general level can be quite simple. However, the most logical solution, which consists in excluding users from the administrator group or increasing the level of UAC control, in the seventh Windows versions and later modifications of the system have no effect, since in them you can still use the installer to start as an administrator. Despite this, several options for setting a ban can still be applied.

    Does it require a ban on software installation?

    First, let's take a brief look at why and why such bans need to be introduced by the administrator.

    The problem here is not even that the user can install completely unnecessary software, but rather that during the installation of some applications, a huge amount of so-called affiliate software can very often be installed (which is often ignored by many users due to their inattention). In addition, some viruses (for example, advertising ones) are very successfully disguised as such applets.

    And in general, installation of unnecessary software products leads to clutter hard drive and to a decrease in computer performance in the case when installed programs register their own settings in the system startup and in system registry. And without special knowledge and skills, produce the maximum complete removal installed applications can be extremely difficult, and Windows tools It's best not to count.

    How to prevent installation of programs on Windows 7 in Group Policy settings?

    Since we will further discuss the seventh modification of the system, we will start from its basic settings and parameters. But the solutions provided can be similarly applied in later versions of the OS. So, how can you prevent the installation of programs on Windows 7 for all users at a general level, including possible installations initiated by the applications themselves, for example, during an update? This can be done through group policies. Access to the editor is carried out by the gpedit.msc command, which is registered in the “Run” menu (you must check the box at the point where you can run the task with administrator rights).

    The editor should use the Administrative Templates and Windows components, and then select the installer prohibition item from the list. After this, double-click to edit this parameter, set it to enabled and apply the changes.

    Actions with equipment

    In Windows 7, access to setting bans on any actions performed by a potential user of the system can also be obtained through the so-called snap-in management console (mmc).

    Here, first through the file menu you need to select adding a new snap-in, then in the list available tools Select group policies and use the Add button to add them to the list in the window on the right. In the new window that opens, use the browse button to open another window, go to the “Users” tab and mark the user for whom the ban should apply.

    Once the snap-in code is added through the “File” menu, it must be saved using the standard method of assigning the registered admin name as the name. After this, you need to repeat the above steps, but in this case, installation of programs in Windows 7 will be prohibited only for the selected user.

    Note: if necessary, you can create several snap-ins or set bans for all registered users.

    How to prevent a user from installing Windows 7 programs using parental control settings?

    To set bans, you can use another method, which, according to most experts, is the simplest and does not require special knowledge system tools. How to prevent installation of programs on Windows 7 and higher systems using this tool? To do this, in the “Control Panel” you need to use the account management section and select the installation item parental controls.

    Next, the user for whom the ban will be set is simply marked, and the corresponding parameter for restricting the launch of programs is activated. The system will automatically create a list of applications that can be blocked, but if the program is not found, you can specify the path to it yourself using the browse button.

    But, judging by the advice of experts, you need to clearly understand that the disadvantage of this technique is that you can only limit the start of installed applications, and not those that the user is going to install, although, if desired, you can add Windows installers to the list.

    Setting a ban in the registry

    Speaking about how to prohibit the installation of programs on Windows 7 regarding limiting the launch of the applications themselves or the system installer, you can apply no less effective way, which consists of changing the key specifically responsible for this in the registry (regedit).

    The section is called DisallowRun and is located along the path shown in the image above. To set a ban you just need to create new parameter and specify the path to the executable EXE file, and then reboot the computer device.

    Note: the parameter is created separately for each application; if necessary, you can set additional key values ​​(2, 3, 4), but the ban itself will apply to all users who do not have administrator privileges in the system.

    Brief summary

    To sum up all of the above, apparently many have already realized that setting restrictions on the launch of installed applications is the simplest, but far from the best solution. If for some reason you need to ban the installation of programs, it is best to use group policies or the snap-in management console, as confirmed by most computer security experts.

    But in any case, actions with these editors must be performed only when logged into an administrator account or using the appropriate rights to change the system configuration. You can use the App Locker utility as a third-party tool, but its actions are almost exactly the same as managing policies and snap-ins (only the settings are imported and not installed manually), so it was not considered.