GPO policy: "Configure Windows Defender SmartScreen" (for the Windows Shell / Explorer) under Computer Configuration > Administrative Templates > Windows Components > Windows Defender SmartScreen > Explorer. Controls whether SmartScreen is enforced for file downloads and unrecognized application execution via Windows Explorer. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\System:EnableSmartScreen (REG_DWORD). Related policy ShellSmartScreenLevel controls whether users can bypass warnings. CIS Benchmark (L1) recommends Warn (value 1) or Warn+Prevent Bypass (value 2 via ShellSmartScreenLevel). Reference: Policy CSP - SmartScreen (EnableSmartScreenInShell)
Values
| Enum Value | Description |
|---|---|
|
|
SmartScreen turned off (registry value 0 or policy disabled). No SmartScreen checks are performed for downloaded files or unrecognized applications. |
|
|
SmartScreen warns but allows bypass (registry value 1). Users see a warning about suspicious downloads or unrecognized apps but can choose to proceed. CIS L1 base recommendation. |
|
|
SmartScreen warns and prevents bypass (registry value 2 via ShellSmartScreenLevel=Block). Users see a warning and cannot override it to run unrecognized applications. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"OFF"