Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Smart App Control blocks an app you trust, and there's no button to run it anyway. Switching it off takes four clicks, but the better question is what you lose and what should protect the machine instead. This guide covers both, from a single laptop to a company fleet.

What Smart App Control Does

Smart App Control is a Windows 11 feature that decides whether an app may run before it starts. It asks Microsoft's cloud reputation service about the file. If the service knows the app is safe, it runs, and if it knows the app is malicious, Windows blocks it. If the service isn't sure, Windows checks the code signature: a valid signature runs, and an unsigned or invalid one is blocked.

There's no "run anyway" link on that block. That's the design, and it's the reason people go looking for the off switch.

Under the hood it isn't a separate product. Microsoft built it on App Control for Business, the policy engine companies use to decide which code may run. Microsoft's Application Control for Windows page says so directly, and that detail matters later in this guide.

How to Turn Off Smart App Control

On a personal PC, the switch lives in Windows Security:

  1. Open Windows Security from the Start menu.
  2. Go to App & browser control.
  3. Select Smart App Control settings.
  4. Choose Off.

For years that was a one-way door. Once you turned Smart App Control off, the only way back was a clean install of Windows. Microsoft's own FAQ now says recent Windows updates let you turn it back on without reinstalling. The change rolled out gradually in 2026, so some PCs still show the setting greyed out until the update reaches them.

It also starts in a third state, evaluation mode. In evaluation, Windows watches how you use the PC and then decides for you whether to switch protection on or off. If the settings page shows evaluation, nothing is being blocked yet.

Before you switch it off, check two things. First, whether the blocked app has an update from the vendor, since a newer signed build often clears the block. Second, whether the file came from the vendor's own site rather than a mirror, because an unknown download is exactly what the feature is there to stop.

Why It Blocks Apps You Trust

Reputation takes time to build. A brand-new release, a niche utility, a tool your developer compiled yesterday or a small vendor's installer can all be unknown to the cloud service. Unknown plus unsigned means blocked.

Hardware vendors aren't immune either. XDA reported in April 2026 that Asus's Armoury Crate, the utility that ships with Asus machines, was blocked by Smart App Control at one point. Streamers hit the same wall with Streamer.bot in this r/Windows11 thread, even though the vendor confirmed the file is signed.

The top reply in that thread is blunt: turn it off. That's a fair call for a gaming rig. It's a weaker call for a laptop that holds company data.

What You Give Up When It's Off

Smart App Control stops a specific kind of attack: someone gets you to run a file nobody has seen before. Phishing attachments, fake installers and cracked software all work that way. Antivirus looks for known bad files. Smart App Control flips the question and only lets through what it can vouch for.

Turning it off leaves Microsoft Defender Antivirus in place, so the machine isn't unprotected. What goes is the extra check on unknown code, which matters most against new malware that no signature list has caught yet. If you want the background on how attackers turn a fresh bug into working code, our explainer on what an exploit is covers it.

PC Security Channel ran Smart App Control against live malware samples. The video shows what it caught, what slipped past, and where it gets in the way.

Why It's Already Off on Company PCs

On enterprise-managed devices, Smart App Control starts in evaluation mode and switches itself off within 48 hours unless the user turns it on first. Microsoft documents this on its Application Control page. So on a company laptop enrolled in management, the setting was probably never on to begin with.

If you want to set the state yourself across a fleet, Microsoft names the registry value. It's VerifiedAndReputablePolicyState, a DWORD under HKLM\SYSTEM\CurrentControlSet\Control\CI\Policy. After changing it, run CiTool.exe -r to refresh the policy.

ValueSmart App Control state
0Off
1Enforce
2Evaluation

A value of 0 on every machine is easy to push. The better move for a business is to keep the protection and make it yours.

App Control for Business: The Managed Version

Smart App Control has one weakness on a company PC: you can't tell it about your own apps. App Control for Business fixes that. It's the same engine, formerly called Windows Defender Application Control (WDAC), with a policy you write.

Microsoft ships the Smart App Control policy as a starting point. It sits at %windir%\schemas\CodeIntegrity\ExamplePolicies\SmartAppControl.xml, and the App Control Wizard bundles it too. Copy it, remove the option called Enabled:Conditional Windows Lockdown Policy, and add allow rules for your line-of-business apps. The same cloud reputation check is available in your policy under the name Intelligent Security Graph.

It isn't an antivirus replacement either. Microsoft's guidance is to run it alongside Defender Antivirus or another antivirus product, since application control decides what may start and antivirus inspects what's running.

App Control for Business runs on Windows Pro, Enterprise and Education, and you deploy it through Intune, Group Policy or a script. AppLocker is the older, simpler option. Practitioners in this r/Intune thread from September 2026 split between the two, and several say the hard part is managing the allow list, not writing the first policy.

Pair it with least privilege. A user without local admin rights can't install around your policy, which our guide to endpoint privilege management covers.

Roll It Out Without Breaking Line-of-Business Apps

Start in audit mode. The policy logs what it would have blocked without blocking anything, so you find the payroll plugin and the label printer driver before users do. The events land in the CodeIntegrity event log, and one reply in the r/Intune thread above pipes them into Azure Monitor for a central view.

Turn those events into allow rules, preferably by publisher rather than by file hash, so the next update doesn't break the rule. Then enforce on a small pilot ring for a week or two before the rest of the fleet. Keep an exception process with a named owner, because someone will need a tool you didn't plan for.

Checking the state on every machine is a one-line registry read. In OpenFrame, that can run as a scheduled script across endpoints, with an approval gate before anything changes.

Should You Turn It Off?

On a personal PC that keeps blocking tools you trust, turning Smart App Control off is a reasonable trade, and you can now turn it back on later. On a company PC, it's probably off already, and the real fix is App Control for Business with rules for your own apps.

Either way, decide on purpose rather than because a block dialog annoyed you. If you're tidying up Windows on company machines, our guide on how to debloat Windows 11 is the next read.

"Fae" Grace Meadows

"Fae" Grace Meadows

Lead AI Fairy

Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Smart App Control

On a personal PC, usually yes. Microsoft Defender Antivirus keeps running, so you lose the extra check on unknown, unsigned apps rather than all protection. On a company PC, replace it with an App Control for Business policy instead of leaving nothing in its place.
Yes, on an up-to-date PC. It used to need a clean install of Windows, but Microsoft says recent Windows updates let you turn it back on from Windows Security without reinstalling. The change rolled out gradually in 2026.
Either the update that allows turning it back on hasn't reached your PC yet, or the device is managed by your organization. On enterprise-managed devices, evaluation mode switches off within 48 hours, and the setting is controlled by policy rather than the user.
No. It decides whether an app may start, based on cloud reputation and code signing. Antivirus inspects files and behavior. Microsoft's guidance is to run application control alongside Defender Antivirus or another antivirus product.

About OpenFrame

In the cloud, on US soil. Your data stays stateside.
OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.