---
title: "Fix \"running scripts is disabled on this system\" in PowerShell"
canonical: https://saasranked.com/guides/running-scripts-is-disabled/
applies_to: Windows 11, Windows 10, Windows Server, Windows PowerShell 5.1, PowerShell 7
checked: 2026-10-04 (against Microsoft's documentation)
updated: 2026-10-04
---

# Fix "running scripts is disabled on this system" in PowerShell

Error: `File C:\Desktop\myscript.ps1 cannot be loaded because running scripts is disabled on this system. For more information, see about_Execution_Policies at http://go.microsoft.com/fwlink/?LinkID=135170.`

- In Windows PowerShell 5.1, Restricted is the default execution policy for Windows client computers; it permits commands but no scripts [1].
- Get-ExecutionPolicy -List shows the policy for each scope in order of precedence: MachinePolicy, UserPolicy, Process, CurrentUser and LocalMachine [3].
- Changing the LocalMachine scope needs PowerShell started with Run as administrator; the CurrentUser scope affects only the current user [2].
- A Group Policy setting overrides the execution policy in all scopes, and Set-ExecutionPolicy can't change it [1][2].
- Windows PowerShell 5.1 and PowerShell 6 or later store the policy separately, so a change in powershell.exe doesn't affect pwsh.exe [2].

PowerShell shows "running scripts is disabled on this system" when the execution policy is Restricted [5]. Restricted allows single commands but no scripts [1]. Run Get-ExecutionPolicy -List to see the policy in each scope [3]. Then set RemoteSigned for the current session or for your own account with Set-ExecutionPolicy [1]. Unblock a downloaded script with Unblock-File only after you check it is safe [4].

## What the error means

PowerShell's execution policy controls when it loads configuration files and runs scripts [1]. Under the **Restricted** policy, PowerShell runs single commands but no script files. That includes `.ps1` profiles and `.psm1` module files [1].

Microsoft ties this message to the **Restricted** policy [5]. In Windows PowerShell 5.1, Restricted is the default on Windows client computers [1]. The policy is not a security boundary. It is a safety feature that stops you from running scripts by accident [1].

## Before you start

- The fixes below change only the **Process** and **CurrentUser** scopes. Only the **LocalMachine** scope needs PowerShell started with **Run as administrator** [2].
- On a work PC, Group Policy may set the policy. That setting overrides all scopes, and Set-ExecutionPolicy can't change it [1][2].
- Windows PowerShell 5.1 (`powershell.exe`) and PowerShell 6 or later (`pwsh.exe`) keep separate settings. Run the fix in the shell that shows the error [2].
- Execution policies apply only on Windows. On Linux and macOS, the policy is **Unrestricted** and can't be changed [2].

## Fixes

1. **Check the current policy.** Open PowerShell and run this command. It lists the policy for each scope in order of precedence [3].

    ```powershell
    Get-ExecutionPolicy -List
    ```

    The **MachinePolicy** and **UserPolicy** rows come from Group Policy [1]. If either one shows a value other than **Undefined**, the fixes below can't override it [2].

2. **Allow scripts for this session only.** Set **RemoteSigned** for the **Process** scope. It affects only the current PowerShell session, and the setting is deleted when you close it [2].

    ```powershell
    Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope Process
    ```

    Run your script in the same window. The policy lasts until that window and its child processes close [1].

3. **Allow local scripts for your account.** Set **RemoteSigned** for the **CurrentUser** scope. This is the command Microsoft's docs use [1].

    ```powershell
    Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
    ```

    RemoteSigned runs scripts written on your computer. Scripts downloaded from the internet, including email and instant messaging, still need a signature from a trusted publisher [1]. The change is saved and takes effect at once, with no restart [1].

4. **Unblock a downloaded script you trust.** Under RemoteSigned, an unsigned script from the internet still fails. The error then says the file "is not digitally signed. The script will not execute on the system." [2] Read the script's code and check its source first [4]. Then unblock it, using your own file path:

    ```powershell
    Unblock-File -Path .\Start-ActivityTracker.ps1
    ```

    Unblock-File removes the **Zone.Identifier** stream that marks the file as downloaded [4]. It doesn't change the execution policy [2].

## If nothing works

If **MachinePolicy** or **UserPolicy** is set, the policy comes from the **Turn on Script Execution** Group Policy setting [1]. It overrides PowerShell's own settings in all scopes [1]. Ask your Group Policy administrator to change it [2].

Don't switch to **Unrestricted** or **Bypass** to make the error go away. Unrestricted lets unsigned scripts run, with a risk of running malicious scripts [1]. Bypass blocks nothing and gives no warnings or prompts [1].

To undo the change for your account later, set the scope back to **Undefined** [1]:

```powershell
Set-ExecutionPolicy -ExecutionPolicy Undefined -Scope CurrentUser
```

## Questions

**Should I set the execution policy to Unrestricted or Bypass?** Not to fix this error. Unrestricted lets unsigned scripts run, with a risk of running malicious scripts [1]. Bypass blocks nothing and shows no warnings; it is designed for scripts built into a larger application with its own security model [1].

**Is the execution policy a security boundary?** No. Microsoft calls it defense in depth, because users can bypass it by typing the script contents at the command line [1]. It sets basic rules so you don't break them by accident [1].

**Why didn't my change take effect?** A scope with higher precedence can override it: Process beats CurrentUser, which beats LocalMachine [1]. A Group Policy setting beats all of them [1]. Run Get-ExecutionPolicy -List to see every scope [3].

**Do I need to restart PowerShell after changing the policy?** No. The change is effective immediately [1]. A policy set for the Process scope is lost when you close that session [1].

## Sources

1. [about_Execution_Policies (PowerShell 5.1)](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/about_execution_policies?view=powershell-5.1), Microsoft Learn, accessed 2026-10-04
2. [Set-ExecutionPolicy](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-executionpolicy), Microsoft Learn, accessed 2026-10-04
3. [Get-ExecutionPolicy](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/get-executionpolicy), Microsoft Learn, accessed 2026-10-04
4. [Unblock-File](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/unblock-file), Microsoft Learn, accessed 2026-10-04
5. [Can't run scripts in Azure Active Directory module for Windows PowerShell](https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/user-prov-sync/cannot-run-scripts-powershell), Microsoft Learn, accessed 2026-10-04

Checked against Microsoft's documentation on 4 Oct 2026.
