GiliSoft EXE Lock

Control who can launch selected Windows desktop applications

Apply password verification or direct blocking, then test every shortcut and executable path.

GiliSoft EXE Lock illustration for Lock Desktop Apps

How to Lock Desktop Apps on Windows 11

By GiliSoft • Updated September 29, 2026

The best method depends on whether access should follow a Windows account, an organization policy, or a password rule for selected programs on one PC.

Quick answer

Use separate Windows accounts or organization policy when access should follow the user. For selected desktop programs on one Windows 11 PC, GiliSoft EXE Lock can require a password or directly block the program. Add the actual EXE, not only its shortcut, and test all launch paths.

Choose the app-locking method by environment

SituationMethodWhy
Family accountFamily Safety or standard accountAccess follows the person and account
Managed organizationAppLocker or approved policyCentral rules, auditing, and support
One shared PCEXE LockPassword verification or direct blocking for selected apps
Sensitive documentsFile permissions or encryptionProtects the data rather than only the application

Before locking a desktop application

  • Set and verify the EXE Lock administrator password and recovery email.
  • Test a nonessential program before applying the rule broadly.
  • Identify the real EXE path and any secondary launcher or updater.
  • Do not block Windows shell, sign-in, security, update, or recovery components.
  • Decide whether authorized users should see a password prompt.

Lock a desktop app on Windows 11

  1. Open EXE Lock and set recovery details.

    Confirm the password and recovery email before adding programs.

  2. Add the desktop application's executable.

    Browse to the installed EXE instead of selecting only a shortcut.

  3. Choose the launch policy.

    Use Password Verification for approved access or Direct Block when it should not run.

  4. Test alternate launch paths.

    Try the Start menu, taskbar, shortcut, file association, and direct EXE path.

  5. Review updates and blocked attempts.

    Retest after application updates or path changes.

Add a Windows 11 desktop application to EXE Lock
Add the underlying executable and review its current rule.
Choose an EXE Lock launch policy
Choose password verification or direct blocking according to the user workflow.

App-locking limits to understand

Locking an executable controls launching that program on the protected PC. It does not encrypt the program's documents, remove cloud access, or prevent an untrusted administrator from changing the computer. Use file protection and account security for the underlying data.

Frequently asked questions

Can I lock a Windows 11 app without uninstalling it?

Yes. Account controls, policy, or EXE Lock can restrict launching while leaving the application installed.

Can I put a password on a desktop app?

A dedicated EXE lock can show a password prompt for selected traditional desktop applications. Test the actual executable and every launch path.

Does Windows 11 include AppLocker?

AppLocker availability and management depend on Windows edition and organization configuration. Check the target PC before designing around it.

What is the difference between Password Verification and Direct Block?

Password Verification permits authorized launch after a password. Direct Block prevents launch in that configured workflow.

Will the rule survive an application update?

It may require retesting if the executable name, path, launcher, or installation changes.

Lock one nonessential desktop app and test every launch path

Confirm recovery, updates, shortcuts, and authorized access before protecting important applications.