Serious Discussion Does enabling Smart App Control prevent unblocking files downloaded from internet?

@Andy Ful - Here is a block of a shortcut, but it is not the usual SAC block notification. This seems like some recent SAC development.
1760820465802.png

Shortcut execution attempt was via SUA. The same shortcut execution is not blocked when run from Administrator account.
 
Last edited:
That last sentence makes me wonder if "Send optional diagnostic data" is needed for SAC to properly function.
Yes, it's a requirement. Although I believe if you disable optional diag data, SAC won't function properly and won't show as disabled.
 
  • Like
Reactions: Gandalf_The_Grey
@Andy Ful - Here is a block of a shortcut, but it is not the usual SAC block notification. This seems like some recent SAC development.
View attachment 292093
Shortcut execution attempt was via SUA. The same shortcut execution is not blocked when run from Administrator account.

If you use two accounts, shortcuts may run two different executables. On SUA the executable has MotW.
 
If you use two accounts, shortcuts may run two different executables. On SUA the executable has MotW.
Windows Security internals, expected behaviors, documentation are like a witches' coven brew of inadequacies. It is no surprise that so many IT Pros struggle with it all because even the teams at Microsoft who are responsible for creating the documentation are unaware of Windows Security internals - nor do the teams that develop and support Windows Security know them all either - which means they cannot advise the separate/siloed documentation teams on all the necessary details.

If people did not know, Microsoft internally is extremely fragmented at various levels and siloed. In many instances, one division, program, project, team doesn't know what any of the others are doing. This is how Microsoft has always worked as a company.
 
If you use two accounts, shortcuts may run two different executables. On SUA the executable has MotW.
Removing MotW will stop the block; but why the message looks different from the usual block messages of SAC? Is it the SUA?
 
  • Like
Reactions: Andy Ful
I was able before, whiel SAC was off, to unblock files downloaded from internet through properties; after enabling I, I can not.
When tick unblock and click OK and reopen properties, I found unblock as it is.
Trying to repeat the steps one more time yields an error message.
The first tweak I do when I install Windows is to disable this stupid file classification.

When you download any file, Windows places a BLOCKED marker on it. This is a significant issue for developers when users report that a program fails to install or, despite installation, doesn't function correctly. The same applies to drivers.

It is a nuisance because Windows does not distinguish between safe and harmful files. It just blocks everything you download, which is why you sometimes get the warning that says, "Are you sure you want to open this file?

To prevent Windows from automatically blocking downloaded files, check this guide: Enable or Disable Block Files Downloaded from Internet in Windows
 
When you download any file, Windows places a BLOCKED marker on it
It is the mark of the web; it is good for security, as it asks MD to scan the file immediately after download and asks SAC to treat it differently if its extension is potentially dangerous.
To prevent Windows from automatically blocking downloaded files, check this guide: Enable or Disable Block Files Downloaded from Internet in Windows
It is not a good idea to do so; you may manually remove motw (ublock) a certain file, if it is blocked by SAC while you are dead sure it is safe.
 
  • Like
Reactions: Andy Ful
The first tweak I do when I install Windows is to disable this stupid file classification
I consider people who uses SAC on their work or home pc to be a masochist cause they derive pleasure from inflicting SAC upon them and I believe that the person behind SAC to be the most sadistic one ever worked in Microsoft.
 
I consider people who uses SAC on their work or home pc to be a masochist cause they derive pleasure from inflicting SAC upon them and I believe that the person behind SAC to be the most sadistic one ever worked in Microsoft.

It is not for people who use a computer for gaming or install not-so-popular applications.
However, it can be a good option for many people who use computers for simple tasks like web browsing, document editing, watching videos, etc.
Many useful applications can be used with SAC, for example:

https://malwaretips.com/threads/applications-that-work-well-with-smart-app-control.131260/

It is possible that we on MT are masochists by spending too much time on tweaking and seeking the best protection.:)
The alternative is using any AV + SAC and spending more time on finding software that works well with SAC.
 
I consider people who uses SAC on their work or home pc to be a masochist cause they derive pleasure from inflicting SAC upon them and I believe that the person behind SAC to be the most sadistic one ever worked in Microsoft.
leonardo dicaprio mental illness GIF
 
  • Love
Reactions: Brahman
It is the mark of the web; it is good for security, as it asks MD to scan the file immediately after download and asks SAC to treat it differently if its extension is potentially dangerous.

It is not a good idea to do so; you may manually remove motw (ublock) a certain file, if it is blocked by SAC while you are dead sure it is safe.
That is the job of the Antivirus, not this automatic blocking that blocks everything right and left without knowing anything. I have seen many people having an entire collection of pictures all with that blocked status marker, every time they open a pic they have to confirm that they are sure they want to open it. If you don't mind, feel free to keep it enabled. Not my cup of tea. I've been using computers since 30 years with this setting turned off and not once had I had a virus. My Antivirus blocks malicious files, not a stupid automatic classification to block everything that comes from the web blindly.

I also work in a computer company and we have so many support tickets of people installing a program and it not working properly. For example, for Dell Alienware computers, there is a utilityh they use called the Alienware Command Center, if you install it without first unblocking the file whihc most people don't do since they have no clue that any file they download is blocked, it install, but it never runs when they try to launch it.
 
I have seen many people having an entire collection of pictures all with that blocked status marker, every time they open a pic they have to confirm that they are sure they want to open it
I have it on downloaded image files with no problem; it only matters for office files (eg, docx) where it makes Word open in protected mode.
I've been using computers since 30 years with this setting turned off and not once had I had a virus
I know people used PC for the same period without AV (MD turned off) and not once had they had a virus too.
I also work in a computer company and we have so many support tickets of people installing a program and it not working properly
Agree; however, I have learned which programs (and even which activators) can work nicely with SAC.