In Windows 11, the ‘Programs and Features’ applet (also accessible via the modern Settings App as ‘Installed Apps’) provides users with direct administrative access to modify, repair, or uninstall installed software packages. While necessary for system administrators, granting standard users access to software removal utilities introduces a massive operational liability on provisioned corporate workstations, secure educational kiosks, or compliant point-of-sale terminals. Allowing an unauthorized user to uninstall core dependencies, security agents, or proprietary enterprise software instantly compromises the workstation’s integrity and breaks compliance mandates.
This guide explains how to completely disable ‘Programs and Features’ via Group Policy in Windows 11, enforcing a strict block that prevents users from modifying or uninstalling system applications.
Disable Programs and Features via Group Policy
To enforce a strict configuration that explicitly strips the operating system of its ability to spawn the uninstallation applets, we must deploy a user-level administrative template. Note that this requires Windows 11 Pro, Enterprise, or Education editions.
- Log into Windows 11 with an Administrator account.
- Press the Windows Key + R to open the Run dialogue box.
- Type
gpedit.mscand press Enter to launch the Local Group Policy Editor. - In the left-hand navigation pane, strictly follow this exact path:
User Configuration > Administrative Templates > Control Panel > Programs - In the right-hand pane, locate the policy named Hide “Programs and Features”.
- Double-click the policy to open its configuration window.
- Select the radio button next to Enabled. (By explicitly enabling this restriction, we instruct the Windows Shell to instantly intercept and block all requests to open the Programs and Features applet, effectively severing the user’s ability to invoke uninstallation routines).
- Click Apply, then click OK.
Verify the Configuration Lockdown
Group Policy changes modifying Control Panel and Settings applets require the operating system to update its local policy state.
Open Command Prompt as Administrator and run gpupdate /force. To verify the restriction is actively enforced, attempt to open the Control Panel and click on “Programs and Features”, or run appwiz.cpl from the Run dialogue. The operating system will immediately intercept the command and throw a fatal error dialog stating: “Your system administrator has disabled Programs and Features.” Consequently, the user is completely stripped of their ability to alter the software payload on the workstation. The terminal’s software inventory is now strictly secured and immutable.