|
Article ID: 27012
|
Creation Date: 10/1/2026 2:11 PM
|
Product: SiteKiosk Online Client
|
Attachment: -
|
|
ArticleType: FAQ
|
Version: -
|
Language: English
|
|
Views: 116
|
Last Modification Date: -
|
Platform: Windows
|
|
|
Level: Closed
|
Modified By: -
|
|
|
FAQ: Should I enable or disable Smart App Control?
Microsoft acknowledges that Smart App Control may not be suitable for all usage scenarios and may interfere with legitimate tasks. In its Smart App Control FAQ under “Why is Smart App Control on?”, Microsoft explains that certain legitimate tasks performed by corporate users, developers, or others may not work well with Smart App Control enabled and that Windows may automatically disable the feature in such cases. For more information, see the Microsoft Smart App Control FAQ:
https://support.microsoft.com/en-us/windows/security/threat-malware-protection/smart-app-control-frequently-asked-questions
For a dedicated kiosk system, where reliable and uninterrupted operation is important, we recommend disabling Smart App Control if it repeatedly blocks components required by SiteKiosk.
If the SiteKiosk Client does not start or cannot run properly due to an application control policy, you may find messages such as the following in the SiteKiosk log: This file is blocked by an application control policy
- Disable Smart App Control in Windows
On Windows 11, log on with an administrator account and navigate to:
Settings > Privacy & security > Windows Security > App & browser control > Smart App Control settings
Smart App Control can be disabled from there.
- Disable Smart App Control remotely using SiteKiosk Online
As an alternative, Smart App Control can be disabled remotely using PowerShell through the SiteKiosk Online Recovery Shell.
In your SiteKiosk Online team, navigate to:
Monitoring > [Client] > Administration > Recovery Shell
First, check the current Smart App Control state:
Get-MpComputerStatus | Select-Object SmartAppControlState
If Smart App Control is enabled, you can disable it with:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\CI\Policy" -Name "VerifiedAndReputablePolicyState" -Type DWord -Value 0
Then restart the system:
- Optional diagnostic data
You may also check whether optional diagnostic data is enabled in Windows and consider disabling it if it is not required in your environment. According to Microsoft's Smart App Control FAQ, Smart App Control depends on optional diagnostic data. Microsoft lists disabled optional diagnostic data as one of the reasons why Smart App Control may be turned off.
For more information, see the Microsoft Smart App Control FAQ:
https://support.microsoft.com/en-us/windows/security/threat-malware-protection/smart-app-control-frequently-asked-questions