PowerShell blocks scripts by default — here's how to turn that off

When you try to run a script in PowerShell, you'll often see an error message saying the script cannot be executed because running scripts is disabled on your system. This is a security setting that prevents unknown or malicious scripts from running without your knowledge. To run your own scripts, you need to change this setting, which is called the execution policy.

The fix takes one command, but which command depends on whether you want to allow scripts just for yourself, just for this one session, or for everyone on the computer. Most people need the simplest option: allowing scripts to run for your user account only.

Key Takeaways

  • PowerShell's execution policy is a security setting that blocks scripts from running by default.
  • The command to allow scripts for your user account is Set-ExecutionPolicy -ExecutionPolicy RemoteSignedCurrentUser, typed into PowerShell as administrator.
  • If you only need to run a script once, you can allow it for that session only without changing the permanent setting.
  • Scripts downloaded from the internet may still be blocked even after changing the policy — you may need to unblock the file itself.
  • Changing the execution policy requires opening PowerShell as administrator; right-click the PowerShell icon and select "Run as administrator".

Enable scripts for your user account (the most common choice)

This method lets you run scripts whenever you want, but only for your own user account. Other users on the computer cannot run scripts unless they change their own policy. This is the safest middle ground for most people.

Open PowerShell as administrator. Right-click the PowerShell icon in your Start menu or taskbar and select "Run as administrator". A window will open with "Administrator" in the title bar.

Type this command exactly and press Enter:

Set-ExecutionPolicy -ExecutionPolicy RemoteSignedCurrentUser

PowerShell will ask you to confirm. Type Y and press Enter. You should see a message saying the execution policy has been changed. Close PowerShell and open it again normally (not as administrator) — you can now run scripts.

Allow scripts for just this PowerShell session

If you only need to run a script once, or you want to test something without making a permanent change, you can allow scripts for just the current session. When you close PowerShell, the setting goes back to blocked.

Open PowerShell as administrator and type this command:

Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope Process

Press Enter and confirm with Y. You can now run scripts in this window only. When you close PowerShell completely, the setting reverts to the default.

Unblock a script that's still being blocked

Even after changing the execution policy, scripts downloaded from the internet may still refuse to run. Windows marks downloaded files as "untrusted" to protect you. You need to unblock the file itself before PowerShell will run it.

Right-click the script file (the .ps1 file) and select "Properties". At the bottom of the window, you'll see a checkbox that says "Unblock". Check that box and click "Apply", then "OK". Now try running the script again.

If you prefer to do this from PowerShell instead, open PowerShell as administrator, then type this command (replace the path with your actual script location):

Unblock-File -Path "C:\Users\YourName\Documents\myscript.ps1"

Press Enter. The file is now unblocked and should run.

What each execution policy means

RemoteSignedCurrentUser (recommended for most people) allows you to run scripts you create yourself or scripts stored on your computer. Scripts downloaded from the internet are still blocked unless you unblock them manually. This is the safest option that still lets you work.

RemoteSigned is similar but applies to all users on the computer, not just you. Use this only if you're the only person who uses the computer and you want a single setting for everyone.

Unrestricted allows all scripts to run without any checks. This is not recommended because it removes all protection against malicious scripts.

Restricted is the default — no scripts run at all, only individual commands.

Troubleshooting: the command doesn't work

If you type the command and get an error, the most common reason is that PowerShell is not running as administrator. Close the window and right-click the PowerShell icon again, making sure you select "Run as administrator". The window title must say "Administrator" at the top.

If you see an error about "access denied" even when running as administrator, your computer may be managed by a workplace or school. In that case, the execution policy is controlled by a group policy that you cannot change yourself. Contact your IT department or system administrator.

If the command runs but scripts still won't execute, the script file itself may be blocked (see the section above on unblocking files). You can also check what your current execution policy is by typing Get-ExecutionPolicy and pressing Enter — it will show you what is currently set.

Running a script after you've enabled them

Once the execution policy is changed, you run a script by opening PowerShell (not necessarily as administrator this time) and typing the full path to the script file. If the script is in your Documents folder and is named "myscript.ps1", you would type:

C:\Users\YourName\Documents\myscript.ps1

Press Enter and the script will run. If you get an error saying the file is not recognized, make sure you've typed the path correctly and that the file actually exists in that location. You can also navigate to the folder in File Explorer, type powershell in the address bar at the top, and press Enter — PowerShell will open in that folder, and you can then type just the script name.

Frequently Asked Questions

Do I have to run PowerShell as administrator every time I want to run a script?

No. You only need to run it as administrator once to change the execution policy. After that, you can open PowerShell normally and run scripts. The policy change is permanent until you change it again.

Will changing the execution policy make my computer less secure?

RemoteSignedCurrentUser is designed to be safe. It still blocks scripts from the internet unless you manually unblock them, and it only affects your user account. It does not remove Windows Defender or any other security features.

What if I want to go back to blocking all scripts?

Open PowerShell as administrator and type Set-ExecutionPolicy -ExecutionPolicy Restricted. This returns you to the default blocked state.

Can I run a script without changing the execution policy at all?

Yes, but it requires typing a longer command each time. Open PowerShell and type powershell.exe -ExecutionPolicy Bypass -File "C:\path\to\script.ps1" (replacing the path with your actual script). This runs that one script without changing your permanent policy.

Why does PowerShell block scripts in the first place?

Scripts are powerful — they can delete files, change settings, or install software. Blocking them by default prevents malware or a malicious person from running dangerous code on your computer without your knowledge. The execution policy makes you take an intentional step to allow scripts, which reduces the risk.