NETWORK ADMINISTRATIONSWindows server

Prevent users from modifying Exploit Protection in Windows Security


If you want to prevent users from modifying Exploit protection settings in Windows Security, this tutorial will guide you through the steps. It is possible to block other users from changing the preset settings if you do not want them to.

The Exploit protection functionality helps users protect their computers from the malware that uses various security exploits to invade your computer. It works well to protect a user’s PC. Windows 10 and allows users to add or remove an app from the Exploit protection settings in Windows Security.

Let’s assume that you are handing over your computer to your friend or kid for a couple of days, and you do not want to allow them to change any setting. You have two options. First, you can hide the App & browser control window. Second, you can disable Exploit protection settings individually.

Prevent users from modifying Exploit protection settings via GPEDIT

To prevent users from modifying Exploit protection settings in Windows 10, follow these steps-

  1. Press Win+R.
  2. Type gpedit.msc and hit the Enter button.
  3. Go to App and browser protection in Computer Configuration.
  4. Double-click on the Prevent users from modifying settings.
  5. Select the Enabled option.
  6. Click on Apply and OK.

Let’s learn more about these steps in detail.

At first, press the Win+R button to open the Run prompt. Type gpedit.msc and press the Enter button to open Local Group Policy Editor. After that, navigate to this path-

Computer Configuration > Administrative Templates > Windows Components > Windows Security > App and browser protection

Here you will see a setting called Prevent users from modifying settings. Double-click on it and select the Enabled option.

How to prevent users from modifying Exploit protection settings

At last, click on Apply and OK buttons, respectively.

You can do the same with Registry Editor as well. If you are planning to Registry Editor, it is recommended to backup all Registry files and create a System Restore point.

Block users from adding or removing apps in Exploit protection settings via REGEDIT

To block users from adding or removing apps in Exploit protection settings, follow these steps-

  1. Press Win+R.
  2. Type regedit and hit the Enter button.
  3. Click the Yes button.
  4. Navigate to Windows Defender Security Center in HKLM.
  5. Right-click on it > New > Key.
  6. Name it as App and Browser protection.
  7. Right-click on it > New > DWORD (32-bit) Value.
  8. Name it as DisallowExploitProtectionOverride.
  9. Double-click on it to set the Value dataas 1.
  10. Click OK to save the change.

Let’s delve into these steps in detail.

At first, press Win+R, type regedit, and press the Enter button. Click on the Yes button in the UAC popup window. After that, navigate to the following path-

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindows Defender Security Center

Right-click on Windows Defender Security Center > New > Key and name it as App and Browser protection. After that, right-click on App and Browser protection > New > DWORD (32-bit) Value and name it as DisallowExploitProtectionOverride.

How to prevent users from modifying Exploit protection settings

Double-click on it to set the Value data as 1.

Prevent users from modifying Exploit Protection settings in Windows Security

Click the OK button to save the change.

Hope this guide helps.

How to prevent users from modifying Exploit protection settings

Source link

Alice AUSTIN

Alice AUSTIN is studying Cisco Systems Engineering. He has passion with both hardware and software and writes articles and reviews for many IT websites.

Leave a Reply

Your email address will not be published. Required fields are marked *