Preventing the Use of Cmd.exe and Batch Files

You can tweak the registry to prevent users from running cmd.exe and batch files.

Bob Chronister

May 26, 2003

1 Min Read
ITPro Today logo in a gray background | ITPro Today

I need to prevent users from using cmd.exe to run applications and batch files. How can I do so?

Cmd.exe is a potential back door to many executable files. You can make a registry change to stop the use of cmd.exe and even stop batch files from running, although you should always be cautious about editing the registry.

Open a registry editor and go to the HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsSystem registry subkey. Add the DisableCMD value (of type REG_DWORD). You can set this value to 1 or 2. A setting of 1 will prevent users from running cmd.exe but will let users run batch files. A setting of 2 will prevent users from using cmd.exe and from running batch files.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like