EXE Lock User Guide

How to Configure GiliSoft EXE Lock on Windows

Control which desktop EXE programs and supported Microsoft Store/UWP apps can launch on Windows 11 and Windows 10, then choose whether each protected app is blocked directly or released after password verification.

Desktop EXE appsStore/UWP appsDirect BlockPassword Verification
Protected TargetsDesktop App (.exe)Microsoft Store App
GiliSoft EXE Lock software box
Launch PolicyDirect BlockPassword Verification

Choose the right app launch policy

The two policies have different user experiences. Decide whether an app should be completely unavailable or available only after an authorized person approves the launch.

Direct Block

Prevents the selected application from starting without presenting a release-password workflow. Use it when ordinary users should not run the app.

Good fit: prohibited games, unapproved browsers, system utilities, and software that should stay unavailable.

Password Verification

Requests the release password before the protected app can open. An authorized parent, teacher, manager, or administrator can approve access.

Good fit: finance tools, administration software, remote-access apps, and programs that are allowed only with supervision.

1. Configure passwords, recovery email, and the App Whitelist

Protect administration before adding lock rules

  1. Open Settings.
  2. Change the startup and release password from the default or trial configuration.
  3. Set an email address for password recovery.
  4. Review the App Whitelist and System Protected Items.
  5. Add approved desktop or Store apps that should never be placed on the lock list.
Do this first: confirm the password and recovery email before sharing the PC or enabling a large set of app rules.
Startup passwordControls access to EXE Lock management.
Release passwordApproves launches under Password Verification.
WhitelistKeeps trusted and system-sensitive apps away from lock rules.
EXE Lock password recovery whitelist and system protected item settingsSettings: passwords, recovery email, user whitelist, and system-protected items

2. Add traditional Windows desktop EXE applications

EXE Lock Desktop Apps EXE target listDesktop Apps: add traditional programs and verify the executable path

Protect the executable that actually launches the program

  1. Open Desktop Apps (EXE).
  2. Click Add, or use the supported drag-and-drop area.
  3. Select the program executable or shortcut target.
  4. Confirm the displayed application name and full path.
  5. Select the app and apply the intended launch policy.
Some applications use a launcher and a separate main executable. Test the normal shortcut after adding the target to confirm that the correct process is protected.

3. Add Microsoft Store and UWP applications

Use the dedicated Store Apps list

  1. Open Store Apps (UWP).
  2. Find the supported Store app target in the detected list.
  3. Select one or more apps intended for protection.
  4. Apply the same Direct Block or Password Verification policy.
  5. Test the app from its normal Start menu entry.

Store/UWP apps use package identities and protected Windows locations, so they should be managed from this dedicated section rather than added as ordinary desktop EXE files.

EXE Lock Store Apps UWP application target listStore Apps: manage supported modern Windows app targets separately

4. Apply Direct Block or Password Verification

EXE Lock Direct Block and Password Verification policy settingsLock Policy: choose the launch behavior applied to protected targets

Use one clear rule for the selected targets

  1. Open Lock Policy.
  2. Choose Direct Block when no launch should be permitted.
  3. Choose Password Verification when authorized users may release an app.
  4. Save the policy and return to the app list.
  5. Launch one protected app to verify the expected behavior.
Test with the Windows account that will use the PC. A successful administrator test does not replace testing the ordinary user experience.

5. Verify protection, use Temporary Unlock, and review logs

Confirm results from the Dashboard

  1. Check that Protection Status is Running.
  2. Review the number of protected Desktop Apps and Store Apps.
  3. Test a protected application and check Blocked Attempts.
  4. Use Temporary Unlock for maintenance or approved short-term access without deleting the target rules.
  5. Review Recent Intercept Logs and the full Logs area for process, action, time, and result.

Logs help distinguish a working block rule from an incorrect target path and provide evidence when a trusted application needs an exception.

EXE Lock dashboard with protection status temporary unlock blocked attempts and intercept logsDashboard: protection status, target counts, Temporary Unlock, and recent events

Recommended EXE Lock rollout order

Start with one test application. Expanding gradually makes it easier to confirm paths, password behavior, Store app targeting, and whitelist exceptions.

Set management password.
Add recovery email.
Review whitelist.
Choose launch policy.
Add one test app.
Verify launch and logs.
Add remaining targets.

EXE Lock troubleshooting and FAQ

Why can a protected desktop app still open?

Confirm the exact executable path. The shortcut may start a launcher while the main application runs from another EXE file.

Why can I not find a Microsoft Store app?

Refresh the Store Apps list and confirm the application is installed for the Windows account. Only supported detected Store/UWP targets appear there.

What if an app update changes its path?

Review the displayed target after major updates. Remove an outdated entry and add the current executable or package target if needed.

How do I release apps temporarily?

Use Temporary Unlock from the Dashboard for maintenance or approved access, then restore normal protection without rebuilding the app list.

What if a trusted application is blocked?

Use the event details to identify the process, remove it from the protected target list where appropriate, or add it to the App Whitelist.

What if the release password is forgotten?

Use the configured recovery email path. Set and verify that email before relying on Password Verification on a shared PC.

Control app launches on shared Windows PCs

Use EXE Lock to manage desktop EXE and supported Store/UWP targets with direct blocking, supervised password release, temporary unlock, and activity records.

View GiliSoft EXE Lock
×Expanded EXE Lock settings screenshot
×Expanded EXE Lock Desktop Apps screenshot
×Expanded EXE Lock Store Apps screenshot
×Expanded EXE Lock policy screenshot
×Expanded EXE Lock dashboard screenshot