Virtual Component Process Allow List
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Server 2008 R2 or Windows 7
Path in the GPO console
Computer Configuration\Administrative Templates\System\App-V\Virtualization Description
Specifies a list of process paths (may contain wildcards) which are candidates for using virtual components (shell extensions, browser helper objects, etc). Only processes whose full path matches one of these items can use virtual components.
Registry
SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization Value name: ProcessesUsingVirtualComponents
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/AppVirtualization/VirtualComponentsAllowList Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Virtual Component Process Allow List
; State: Enabled
; Supported on: At least Windows Server 2008 R2 or Windows 7
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization]
"ProcessesUsingVirtualComponents"=dword:00000001
"ProcessesUsingVirtualComponents"=hex(7):00,00
; REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/AppVirtualization/VirtualComponentsAllowList
Data type: String
Value:
<enabled/>
<!-- Virtualization_JITVAllowList_Prompt: enter one value per line before copying this XML payload. --> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization' -Name 'ProcessesUsingVirtualComponents' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization' -Name 'ProcessesUsingVirtualComponents' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. SCCM scripts
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization' -Name 'ProcessesUsingVirtualComponents' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization' -Name 'ProcessesUsingVirtualComponents' -Expected @() -Kind MultiString)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Virtual Component Process Allow List
# State: Enabled
# Supported on: At least Windows Server 2008 R2 or Windows 7
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\AppV\Client\Virtualization'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'ProcessesUsingVirtualComponents' -Value @() -Type MultiString
# REG_MULTI_SZ: one string per input line; edit in regedit if you need richer formatting. Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.