Updated: October 2026
Smart App Control blocks an app you trust, and there's no button to run it anyway. Switching it off takes four clicks, but the better question is what you lose and what should protect the machine instead. This guide covers both, from a single laptop to a company fleet.
What Smart App Control Does
Smart App Control is a Windows 11 feature that decides whether an app may run before it starts. It asks Microsoft's cloud reputation service about the file. If the service knows the app is safe, it runs, and if it knows the app is malicious, Windows blocks it. If the service isn't sure, Windows checks the code signature: a valid signature runs, and an unsigned or invalid one is blocked.
There's no "run anyway" link on that block. That's the design, and it's the reason people go looking for the off switch.
Under the hood it isn't a separate product. Microsoft built it on App Control for Business, the policy engine companies use to decide which code may run. Microsoft's Application Control for Windows page says so directly, and that detail matters later in this guide.
How to Turn Off Smart App Control
On a personal PC, the switch lives in Windows Security:
- Open Windows Security from the Start menu.
- Go to App & browser control.
- Select Smart App Control settings.
- Choose Off.
For years that was a one-way door. Once you turned Smart App Control off, the only way back was a clean install of Windows. Microsoft's own FAQ now says recent Windows updates let you turn it back on without reinstalling. The change rolled out gradually in 2026, so some PCs still show the setting greyed out until the update reaches them.
It also starts in a third state, evaluation mode. In evaluation, Windows watches how you use the PC and then decides for you whether to switch protection on or off. If the settings page shows evaluation, nothing is being blocked yet.
Before you switch it off, check two things. First, whether the blocked app has an update from the vendor, since a newer signed build often clears the block. Second, whether the file came from the vendor's own site rather than a mirror, because an unknown download is exactly what the feature is there to stop.
Why It Blocks Apps You Trust
Reputation takes time to build. A brand-new release, a niche utility, a tool your developer compiled yesterday or a small vendor's installer can all be unknown to the cloud service. Unknown plus unsigned means blocked.
Hardware vendors aren't immune either. XDA reported in April 2026 that Asus's Armoury Crate, the utility that ships with Asus machines, was blocked by Smart App Control at one point. Streamers hit the same wall with Streamer.bot in this r/Windows11 thread, even though the vendor confirmed the file is signed.
The top reply in that thread is blunt: turn it off. That's a fair call for a gaming rig. It's a weaker call for a laptop that holds company data.
What You Give Up When It's Off
Smart App Control stops a specific kind of attack: someone gets you to run a file nobody has seen before. Phishing attachments, fake installers and cracked software all work that way. Antivirus looks for known bad files. Smart App Control flips the question and only lets through what it can vouch for.
Turning it off leaves Microsoft Defender Antivirus in place, so the machine isn't unprotected. What goes is the extra check on unknown code, which matters most against new malware that no signature list has caught yet. If you want the background on how attackers turn a fresh bug into working code, our explainer on what an exploit is covers it.
PC Security Channel ran Smart App Control against live malware samples. The video shows what it caught, what slipped past, and where it gets in the way.
Why It's Already Off on Company PCs
On enterprise-managed devices, Smart App Control starts in evaluation mode and switches itself off within 48 hours unless the user turns it on first. Microsoft documents this on its Application Control page. So on a company laptop enrolled in management, the setting was probably never on to begin with.
If you want to set the state yourself across a fleet, Microsoft names the registry value. It's VerifiedAndReputablePolicyState, a DWORD under HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy. After changing it, run CiTool.exe -r to refresh the policy.
| Value | Smart App Control state |
|---|---|
| 0 | Off |
| 1 | Enforce |
| 2 | Evaluation |
A value of 0 on every machine is easy to push. The better move for a business is to keep the protection and make it yours.
App Control for Business: The Managed Version
Smart App Control has one weakness on a company PC: you can't tell it about your own apps. App Control for Business fixes that. It's the same engine, formerly called Windows Defender Application Control (WDAC), with a policy you write.
Microsoft ships the Smart App Control policy as a starting point. It sits at %windir%\schemas\CodeIntegrity\ExamplePolicies\SmartAppControl.xml, and the App Control Wizard bundles it too. Copy it, remove the option called Enabled:Conditional Windows Lockdown Policy, and add allow rules for your line-of-business apps. The same cloud reputation check is available in your policy under the name Intelligent Security Graph.
It isn't an antivirus replacement either. Microsoft's guidance is to run it alongside Defender Antivirus or another antivirus product, since application control decides what may start and antivirus inspects what's running.
App Control for Business runs on Windows Pro, Enterprise and Education, and you deploy it through Intune, Group Policy or a script. AppLocker is the older, simpler option. Practitioners in this r/Intune thread from September 2026 split between the two, and several say the hard part is managing the allow list, not writing the first policy.
Pair it with least privilege. A user without local admin rights can't install around your policy, which our guide to endpoint privilege management covers.
Roll It Out Without Breaking Line-of-Business Apps
Start in audit mode. The policy logs what it would have blocked without blocking anything, so you find the payroll plugin and the label printer driver before users do. The events land in the CodeIntegrity event log, and one reply in the r/Intune thread above pipes them into Azure Monitor for a central view.
Turn those events into allow rules, preferably by publisher rather than by file hash, so the next update doesn't break the rule. Then enforce on a small pilot ring for a week or two before the rest of the fleet. Keep an exception process with a named owner, because someone will need a tool you didn't plan for.
Checking the state on every machine is a one-line registry read. In OpenFrame, that can run as a scheduled script across endpoints, with an approval gate before anything changes.
Should You Turn It Off?
On a personal PC that keeps blocking tools you trust, turning Smart App Control off is a reasonable trade, and you can now turn it back on later. On a company PC, it's probably off already, and the real fix is App Control for Business with rules for your own apps.
Either way, decide on purpose rather than because a block dialog annoyed you. If you're tidying up Windows on company machines, our guide on how to debloat Windows 11 is the next read.

"Fae" Grace Meadows
Lead AI Fairy
Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.
