What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a PowerShell script will not run—or Set-ExecutionPolicy seemed to have no effect—check the effective policy and every scope before changing anything. The winning scope is the first defined one in this order: MachinePolicy, UserPolicy, Process, LocalMachine, then CurrentUser. For a downloaded script blocked under RemoteSigned, verifying and unblocking that file may be more appropriate than changing a broader policy.

How do I check the effective execution policy?

Run these commands in PowerShell:

Get-ExecutionPolicy
Get-ExecutionPolicy -List

Get-ExecutionPolicy reports the policy that applies to the current session. The -List form shows the setting for each scope, in precedence order. Compare the two: a command may have changed a scope successfully while a higher-priority scope continues to determine the effective policy.

To inspect one scope directly, use, for example:

Get-ExecutionPolicy -Scope CurrentUser

Which execution-policy scope takes precedence?

When multiple scopes have defined values, the first applicable scope in this list wins:

  1. MachinePolicy
  2. UserPolicy
  3. Process
  4. LocalMachine
  5. CurrentUser
Scope What it affects How it is set and how long it lasts
MachinePolicy All users of the computer Set through Group Policy; highest precedence. Set-ExecutionPolicy cannot change it.
UserPolicy The current user Set through Group Policy; second-highest precedence. Set-ExecutionPolicy cannot change it.
Process The current PowerShell process/session Stored in $env:PSExecutionPolicyPreference; discarded when the session closes. It outranks the non-Group-Policy scopes.
LocalMachine All users on the computer Saved in the all-users PowerShell configuration. This is the default target scope when using Set-ExecutionPolicy.
CurrentUser The current user only Saved in the user-specific PowerShell configuration; lowest precedence.

Although LocalMachine is the default target for a setting command, it does not outrank CurrentUser. Group Policy scopes outrank both. On Windows Vista or later, changing LocalMachine requires an elevated PowerShell session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What do the execution-policy names mean?

Policy Practical effect
Restricted Allows individual commands but prevents scripts from running.
RemoteSigned Requires trusted signatures for scripts and configuration files marked as downloaded from the internet; locally written files do not need signatures.
AllSigned Requires trusted signatures for all scripts and configuration files, including local ones.
Unrestricted Allows unsigned scripts, but warns before running files outside the local intranet zone.
Bypass Blocks nothing and shows no warnings or prompts.
Default or Undefined These describe default or removed settings; they are not equivalent guarantees of script safety.

Execution policy is a safety feature that controls conditions for loading PowerShell configuration files and running scripts. Microsoft explicitly says it is not a security system that restricts user actions: for example, a user can bypass it by entering script contents directly at the command line. Do not treat an execution policy as a security boundary. Microsoft Learn: about_Execution_Policies

Why is a downloaded script blocked under RemoteSigned?

Windows can mark a file as originating from the internet. Under RemoteSigned, an unsigned script carrying that mark may be blocked even if an unsigned script created locally can run.

  1. Read and verify the script before allowing it to run.
  2. If you trust the file and its internet-origin mark is the problem, unblock that file rather than changing the machine-wide policy:
    Unblock-File -Path <path>
  3. Check the effective policy again if needed:
    Get-ExecutionPolicy

Unblock-File removes the file’s block; it does not change the execution policy. Microsoft documents this remedy for the unsigned downloaded-file case. Microsoft Learn: about_Execution_Policies

Why did Set-ExecutionPolicy not change what happens?

First inspect all scopes with Get-ExecutionPolicy -List, then compare those values with Get-ExecutionPolicy. A setting command can succeed against a lower-priority scope without changing the policy currently in force. In particular, MachinePolicy, UserPolicy, and Process all outrank LocalMachine, while LocalMachine outranks CurrentUser.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To set a user-only policy on Windows, the command can specify that scope explicitly:

Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser

If a Group Policy scope is defined, changing another scope will not override it. MachinePolicy and UserPolicy must be managed through the applicable Group Policy administration, not with Set-ExecutionPolicy. In a managed environment, contact the administrator responsible for that policy. Microsoft Learn: Set-ExecutionPolicy

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can I set a policy for only one PowerShell session?

Yes. A process-level setting applies to that PowerShell process and its child sessions, then disappears when the session closes. You can supply it when launching PowerShell:

pwsh.exe -ExecutionPolicy <PolicyName>

This does not override MachinePolicy or UserPolicy; Group Policy still takes precedence. The Process scope is also higher than LocalMachine and CurrentUser. Microsoft Learn: about_Execution_Policies

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What if PowerShell reports an AuthorizationManager check failure?

Microsoft documents an environment-specific case affecting some PowerShell 6 conditions on Windows Server Core and Nano Server. Zone validation can rely on Windows Desktop Shell APIs that are unavailable or not ready in those environments. The documentation notes that Bypass or AllSigned does not require the zone check; this is a documented compatibility issue, not a general reason to weaken policy. Microsoft Learn: about_Execution_Policies

Why does execution-policy behavior differ on Linux or macOS?

PowerShell execution policies are enforced only on Windows. On Linux and macOS, Get-ExecutionPolicy reports Unrestricted, while Set-ExecutionPolicy is unsupported; without Windows Security Zones, behavior effectively corresponds to Bypass. Windows-specific remedies such as removing an internet-origin mark should not be expected to change execution-policy enforcement on those platforms. Microsoft Learn: about_Execution_Policies

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.