Friday, July 2, 2021

9:49 PM

Restricting Browser Access on Shared Windows PCs

Updated September 2026: in 2021 I wanted to restrict the browser on a Windows laptop used by staff, so only authorised people could open it, but found "EXE locker" apps broke the browser. I have rewritten it into a guide to controlling what staff can do on shared Windows PCs using Windows' own tools.

I used a Windows laptop in my business and wanted the browser to open only for employees who authenticated. The third-party "EXE locker" tools I tried would lock the browser's program file, which simply made the browser hang. There are better ways, built into Windows.

Why do app locker tools often fail with browsers?

Browsers run several processes and update themselves frequently, replacing their program files. Tools that lock a single executable file clash with that, causing freezes or breaking updates. They also often ask for broad system access, which is a security risk in itself.

What does Windows offer instead?

  • Separate user accounts: give each person their own standard (non-administrator) account with a password or PIN. Browser history, logins and access stay separate.
  • Kiosk mode (assigned access): lock an account so it can run only one app, such as a single browser for a counter PC.
  • Microsoft Family Safety: for small setups, restricts apps and websites per account.
  • Group Policy or Intune: on Windows Pro and business editions, controls which apps each user can run.

Which approach suits a small business?

Separate standard accounts cover most needs: each employee signs in, and nobody sees another's browser data. Use kiosk mode for a PC that should only ever run one app. Business editions of Windows with Intune suit larger teams.

How do you keep shared PCs secure?

Keep Windows and the browser updated, use a password manager rather than saved passwords on shared accounts, and never give staff administrator rights they do not need. Sign out at the end of each shift.

How do you set up a standard account?

In Settings, go to Accounts, then Other users, and add an account for each employee. Leave the account type as Standard user. Each person then signs in with their own password or PIN, and cannot install software or change system settings without an administrator.

Should you still use third-party lockers?

Only well-known, reputable tools, and only after trying the built-in options. Built-in controls are more reliable and do not need extra software with deep system access.

Keep reading