用户在Windows 11/10上启动预装应用时可能会收到此应用已被系统管理员阻止的(This app has been blocked by your system administrator)错误消息。当 PC 连接到域网络时会出现此错误,并且管理员已使用AppLocker部署了对软件安装策略的限制。作为管理员,您可以通过以下方式绕过该错误并允许特定或所有用户运行程序。
管理员已(Administrator)阻止您运行此应用
此问题的主要原因是系统管理员设计的应用程序控制策略。许多系统管理员不允许用户(do not allow users to install or run various applications)在工作时间安装或运行各种应用程序。在大多数情况下,管理员使用AppLocker来阻止人们在所有计算机上打开Microsoft Store应用程序。(Microsoft Store)如果您受到该限制,并且您正在尝试打开Microsoft Store应用程序,您可能会收到特定错误。
但是,由于某些工作目的,很多时候您可能需要允许特定部门访问所有应用程序。在这种情况下,您需要创建一个新规则以允许您网络中的每个人或特定用户访问由Microsoft制作的应用程序。您的系统应该有远程服务器管理工(Remote Server Administration Tools)具。此外,您需要从基于Windows 11/10/8或基于Windows Server 2012 的域控制器创建规则。
此应用程序已被您的系统管理员阻止以保护您
要修复此应用程序已被您的系统管理员(This app has been blocked by your system administrator)错误阻止,请按照下列步骤操作 -
- 打开本地安全策略
- 在打包(Packaged)应用程序规则(Rules)部分创建新规则
首先,您需要在您的计算机上打开本地安全策略。(Local Security Policy)为此,您可以打开“开始”菜单(Start Menu)并搜索它。或者,您可以按Win+R,键入secpol.msc,然后按Enter按钮。之后,转到Application Control Policies > AppLocker > Packaged app Rules。您需要右键单击打包的应用程序规则(Packaged app Rules)按钮并选择创建新规则(Create New Rule )选项。
它应该会打开一个窗口,您可以在其中找到“下一步”(Next )按钮。它显示了有关在“本地安全策略”(Local Security Policy)面板中创建规则的所有基本信息。
在“权限(Permissions )”窗口中,您需要选择要执行的操作。这意味着您需要选择Allow或Deny。当您要让其他人运行已安装的程序时,您应该选择Allow。接下来,它会要求您选择用户或组。如果您想允许您网络中的每个人在各自的计算机上运行Microsoft Store应用程序,您应该使用Everyone。如果您要允许特定部门(销售、人力资源、会计等)或用户,您必须单击选择(Select )按钮,然后选择相应的用户名。
完成所有选择后,单击“下一步”(Next )按钮访问“发布(Publisher )者”选项卡。在这里,您可以看到两个主要选项-
- 使用(Use)已安装的打包应用程序作为参考
- 使用打包的应用安装程序作为参考
如果要选择特定应用程序,请选择第一个选项。如果要包含.appx文件或打包的应用程序安装程序文件作为示例或参考,则需要选择第二个选项。对于第二个选项,您必须拥有.appx文件的路径。
根据您的偏好,您需要单击“Select/Browse ”按钮来确认参考。选择应用程序或安装程序文件后,您应该会看到其他一些解锁选项 -
- 任何发布者:(Any publisher: )用户可以运行来自任何已签名发布者的程序。
- 发布者:(Publisher: )用户可以运行由一个特定发布者制作的应用程序。供您参考,如果发布者系统中有五个应用程序,用户可以运行所有这些应用程序。根据截图,是微软公司(Corporation)。
- 包名称:(Package name: )用户只能使用一个带有给定包名称的特定应用程序。虽然不会发生,但如果多个应用程序具有相同的包名称,用户可以运行所有这些应用程序。
- 包版本:(Package version: )如果您不想让用户更新和运行较新版本的应用程序,则应指定应用程序版本。
要选择任何特定规则,请勾选使用自定义值(Use custom values)复选框,然后使用左侧的控制杆选择一个选项。
最后,单击Next按钮访问Exceptions选项卡。当您想在不同情况下覆盖自定义规则时,此功能非常方便。您可以单击添加(Add )按钮来创建例外。
如果您不想创建例外,请单击“下一步”(Next )按钮为您的规则输入名称和描述。它将让您在将来认识规则。
完成后,单击创建(Create )按钮。现在您应该在打包应用程序规则(Packaged app Rules)部分看到新创建的规则。如果您想删除此规则,请右键单击它并选择Delete。之后,您必须确认删除。
就是这样!此提示应该可以帮助您修复 在 Windows 11/10 上阻止此应用程序的系统管理员错误。(Your system administrator error that has blocked this app)
相关阅读(Related read):由于公司政策,此应用程序已被阻止(This app has been blocked due to Company Policy)。
如何打开被Microsoft Security SmartScreen阻止的文件?
- 按(Press)开始(Start)按钮,然后搜索Windows Security,一旦出现就打开它
- 点击应用和浏览器控制
- 打开基于信誉的保护设置
- 点击保护历史
- 找到Microsoft 安全(Microsoft Security)阻止的应用
- 取消阻止(Unblock),您应该可以使用该应用程序。
因此,如果您想查看Microsoft Security或Windows Defender阻止的内容,可以在这里查看。
我的电脑不属于任何组织;为什么下载的文件被阻止?
这与您的 PC 无关,而是Microsoft Edge或Chrome功能阻止了不需要的应用程序,即报告为红色或新的应用程序。但是,如果您足够信任它们,您始终可以允许并使用它。
如何解除阻止被阻止的网站?
如果您尝试访问无法访问的网站,则应使用VPN绕过限制。如果您的 PC 使用Microsoft Family功能或任何其他软件受到限制,您需要请求管理员授予您访问权限。最后,如果浏览器被阻止,请检查另一个浏览器,如果出于安全原因它在任何地方都被阻止,最好不要访问它。
This app has been blocked by your system administrator
Users might get This app has been blocked by your system administrator error message when starting a pre-installed app on Windows 11/10. This error occurs when a PC is connected to a domain network, and the administrator has used the AppLocker to deploy a restriction over the software installation policy. Here is how you, as an administrator, can bypass that error and allow a specific or all users to run a program.
An Administrator has blocked you from running this app
The primary reason for this problem is an application control policy designed by the administrator of your system. Many system administrators do not allow users to install or run various applications during working hours. In most cases, administrators use AppLocker to prevent people from opening Microsoft Store apps on all the computers. You can get the specific error if you are under that restriction, and you are trying to open a Microsoft Store app.
However, many times you may need to allow a specific department to access all the apps due to some work purpose. In that case, you need to create a new rule to allow everyone or a particular user in your network to access apps made by Microsoft. Your system should have Remote Server Administration Tools. Also, you need to create the rule from either Windows 11/10/8-based or Windows Server 2012-based domain controller.
This app has been blocked for your protection by your system administrator
To fix This app has been blocked by your system administrator error, follow these steps-
- Open Local Security Policy
- Create a new rule in the Packaged app Rules section
At first, you need to open the Local Security Policy on your computer. For that, you can open the Start Menu and search for it. Alternatively, you can press Win+R, type secpol.msc, and hit the Enter button. After that, go to Application Control Policies > AppLocker > Packaged app Rules. You need to right-click on the Packaged app Rules button and select Create New Rule option.
It should open a window where you can find the Next button. It shows all the essential information about creating a rule in the Local Security Policy panel.
In the Permissions window, you need to select the action that you want to perform. That implies you need to choose either Allow or Deny. As you are going to let others run installed programs, you should select Allow. Next, it asks you to select the user or group. If you want to allow everyone across your network to run Microsoft Store apps on the respective computers, you should go with Everyone. If you’re going to allow a specific department (sales, HR, accounting, etc.) or user, you must click the Select button, and choose the corresponding username.
After making all the selections, click the Next button to visit the Publisher tab. Here you can see two primary options-
- Use an installed packaged app as a reference
- Use a packaged app installer as a reference
If you want to select a specific application, do choose the first option. You need to choose the second option if you’re going to include a .appx file or a packaged app installer file as an example or reference. For the second option, you must have the .appx file’s path.
Depending upon your preference, you need to click the Select/Browse button to confirm the reference. After choosing the app or installer file, you should see some other unlocked options-
- Any publisher: Users can run programs from any signed publisher.
- Publisher: Users can run apps made by one specific publisher. For your information, if the publisher has five apps in the system, users can run all of them. According to the screenshot, it is Microsoft Corporation.
- Package name: Users can use only one specific application that carries the given package name. Although it doesn’t happen, if multiple apps have the same package name, users can run all of them.
- Package version: If you do not want to allow users to update and run a newer version of an app, you should specify the app version.
To select any specific rule, make a tick in the Use custom values checkbox, and use the lever on the left side to choose an option.
At last, click the Next button to visit the Exceptions tab. This facility is handy when you want to override your custom rule in different situations. You can click the Add button to create an exception.
If you do not want to create an exception, click the Next button to enter a name and description for your rule. It will let you recognize the rule in the future.
After doing that, click the Create button. Now you should see the newly created rule in the Packaged app Rules section. In case you want to delete this rule, right-click on it and select Delete. Following that, you have to confirm the deletion.
That’s it! This tip should help you fix Your system administrator error that has blocked this app on Windows 11/10.
Related read: This app has been blocked due to Company Policy.
How to open a file blocked by Microsoft Security SmartScreen?
- Press the Start button, and search Windows Security, and open it once it appears
- Click on App and browser control
- Open Reputation-based protection settings
- Click on Protection History
- Locate the app which Microsoft Security blocked
- Unblock, and you should be able to use the app.
So if you want to see what Microsoft Security or Windows Defender is blocking, this is the place to check.
My PC is not part of any organization; why are the downloaded files being blocked?
It’s not about your PC, but it is Microsoft Edge or Chrome feature that blocked unwanted apps, i.e., apps reported to be rouge or new. However, you can always allow it and use it if you trust them enough.
How do I unblock a blocked website?
If you are trying to access a website that is not accessible, you should use a VPN to bypass the restriction. If your PC is restricted using the Microsoft Family feature or any other software, you need to ask the admin to give you access. Lastly, if the browser is blocking, check with another browser, and if it’s blocked everywhere for security reasons, it’s best not to access it.