Guide
Execution policy
Why a script is blocked, what each policy means, and what to change (if anything).
Execution policy is not antivirus. It is a seatbelt that stops you from running unsigned scripts by accident. Group Policy can lock it. A determined user can bypass it. Treat it as a hint, not a security boundary.
See the current policy
Get-ExecutionPolicy -List
The effective policy is the first one in this order that is not Undefined:
- MachinePolicy (Group Policy)
- UserPolicy (Group Policy)
- Process (this window only)
- CurrentUser
- LocalMachine
Common values
| Policy | Meaning |
|---|---|
| Restricted | No scripts. Interactive commands still work. |
| RemoteSigned | Local scripts run. Downloaded scripts need a signature. |
| AllSigned | Every script needs a trusted signature. |
| Bypass | Do not block. Use for one process, not as a lifestyle. |
| Unrestricted | Runs everything, warns on downloaded files. |
What you start with depends on which PowerShell you open:
- Windows PowerShell 5.1 (
powershell.exe) on Windows 10 and 11 starts atRestricted, so no scripts run until you change it. - PowerShell 7 (
pwsh.exe) installs withRemoteSignedfor the whole machine.
The two keep separate settings. Changing the policy in one does not change it in the other, which is the usual reason for "I changed it and it still fails." Run the command below in the PowerShell you actually use.
RemoteSigned for CurrentUser is a reasonable choice for most people.
Change it (CurrentUser only)
Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
If MachinePolicy or UserPolicy is set, this will not win. Talk to whoever manages the machine.
One-shot bypass
To run a single script you trust, without changing policy:
powershell -ExecutionPolicy Bypass -File .\folder-inventory.ps1 -Path .\docs -OutputPath .\files.csv
Still read the script first. Bypass is not a substitute for that.