Windows OS Hub
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux

 Windows OS Hub / Windows 11 / Block Specific Keyboard Shortcuts with Keyboard Filter on Windows

October 3, 2026

Block Specific Keyboard Shortcuts with Keyboard Filter on Windows

In this article, we will show how to enable and configure the built-in Keyboard Filter feature in Windows to prevent users from using certain keyboard shortcuts. You may encounter the task of blocking specific keyboard shortcuts on various embedded devices, public computers running in Kiosk Mode, as well as operator terminals and industrial workstations.

The Keyboard Filter can be used to prevent the accidental use of certain key combinations and system hotkeys. For example, it can prevent users from closing or switching away from an open app window by using shortcuts such as Ctrl+Alt+Del, Alt+F4, or Alt+Tab. It can also prevent users from opening the Task Manager (Ctrl+Shift+Esc), using clipboard copy and paste shortcuts (Ctrl+C and Ctrl+V), or from using other key combinations.

The Keyboard Filter can be used to block specific keyboard shortcuts on a physical keyboard, the Windows on-screen keyboard, and touchscreens. However, it doesn’t work in RDP sessions.

Input filtering using the Keyboard Filter feature is only supported in the Enterprise, Education, IoT Enterprise, and LTSC editions of Windows. It is not supported in the Professional edition without an edition upgrade.

You can install the Keyboard Filter component through the classic Windows Features dialog (optionalfeatures) by selecting it under Device Lockdown. Or you can enable this feature using PowerShell:

Enable-WindowsOptionalFeature -Online -FeatureName Client-KeyboardFilter

Enable Keyboard Filter on Windows 11

This section also contains the Unified Write Filter, another lockdown feature that protects the physical disk from changes (write operations).

Restart the computer after adding the feature. Make sure that the Microsoft Keyboard Filter service (MsKeyboardFilter) is running and configured to start automatically:

Set-Service -Name MsKeyboardFilter -StartupType Automatic -Status Running

Set MsKeyboardFilter service to start automatically

Next, you need to define which keys and/or key combinations should be prevented from being sent to the operating system.

A list of predefined Windows keyboard shortcuts is stored under the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter . By default, all keyboard shortcuts are permitted (the value is set to Allowed). To block a specific keyboard shortcut, change its value to Blocked.

You can edit the value manually using the Registry Editor or change it from the command prompt. For example, to block the Alt+Tab keyboard shortcut, run the following command:

reg add "HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter" /v "Alt+Tab" /t REG_SZ /d "Blocked" /f

Block specific keyboard shortcuts on Windows with KeyboardFilter

Set the value to Blocked for any keyboard combinations you want to prevent users from using. The changes take effect after restarting the computer or restarting the MsKeyboardFilter service.

Once the keyboard filter is activated, pressing a blocked keyboard shortcut will have no effect.

This registry key contains several additional global settings that control keyboard shortcut filtering:

  • DisableKeyboardFilterForAdministrators – set this value to 1 if you want keyboard shortcut blocking rules to be ignored by local administrators. The default value is 0.
  • ForceOffAccessibility – set this value to 1 to prevent users from accessing Windows accessibility keyboard features, such as Sticky Keys, Magnifier, or Narrator.
  • BreakoutKeyScanCode — specifies the keyboard key that is used to log out of the current user session. The default value is 5B which is the hexadecimal scan code for the left Windows key. Pressing the left Win key five times will take the user to the Windows sign-in screen. This is useful if you have enabled the Keyboard Filter feature and blocked the Ctrl+Alt+Del combination and other methods of exiting the user’s session.

You can also enable or disable specific predefined keyboard shortcuts via WMI. The following PowerShell function provides a simple way to block or unblock standard keyboard shortcuts:

function Disable-Predefined-Key {
param (
[Parameter(Mandatory=$true)]
[string]$Id,
[Parameter(Mandatory=$true)]
[bool]$State
)
$key = Get-CimInstance -Namespace "root\standardcimv2\embedded" -ClassName "WEKF_PredefinedKey" -Filter "Id = '$Id'"
if ($key) {
$key.Enabled = $State
Set-CimInstance -CimInstance $key
Write-Host "Keyboar filter set to $State for: $Id" -ForegroundColor Green
} else {
Write-Error "$Id is not a valid predefined key."
}
}

To block a specific shortcut, run:

Disable-KeyboardKey -Id "Alt+F4" -State 1

To allow a keyboard shortcut:

Disable-KeyboardKey -Id "Alt+F4" -State 0

List all predefined keyboard shortcuts and their current status:

Get-CimInstance -Namespace root\standardcimv2\embedded -ClassName WEKF_PredefinedKey

List the predefined keyboard shortcuts with current state using PowerShell

You can also create custom keyboard shortcuts to block. To do this, create a subkey called CustomFilters under the KeyboardFilter registry key.

For example, to block the Ctrl+C and Ctrl+V key combinations, run the following command:

reg add "HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter\CustomFilters" /v "Ctrl+C" /t REG_SZ /d "Blocked" /f
reg add "HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter\CustomFilters" /v "Ctrl+V" /t REG_SZ /d "Blocked" /f

You can block a specific key on the keyboard. For example, to prevent the Z key on the keyboard from being used:

reg add "HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter\CustomFilters" /v "Z" /t REG_SZ /d "Blocked" /f

Block custom keybaord shorctuts via registry

To block a specific key, create a value under HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter\CustomScancodes . The value name should contain the key’s hexadecimal scan code, and the value should be set to Blocked. For example, the following registry rule blocks the left Windows key by its hexadecimal scan code:

reg add "HKLM\SOFTWARE\Microsoft\Windows Embedded\KeyboardFilter\CustomScancodes" /v "E05B" /t REG_SZ /d "Blocked" /f

You can view the list of active Keyboard Filter policies under the Event Viewer Application and Services Logs -> Microsoft -> Windows -> KeyboardFilter -> Operational. Look for an event with Event ID 10207 from the KeyboardFilter source with description:

The Keyboard Filter Service has found the following enabled policies.

Switch to the event Friendly View mode to see the list of blocked keyboard shortcuts.

View active keyboard filter policies in the Event Viewer

Keyboard Filter is a useful Windows feature for restricting the use of keyboard shortcuts, blocking specific keys, and preventing users from entering certain characters.

0 comment
0
Facebook Twitter Google + Pinterest
Questions and AnswersWindows 10Windows 11
previous post
Fix ‘This App Has Been Blocked by Your Administrator’ in Windows

Related Reading

How to Move (Migrate) Windows Shares to a...

February 26, 2026

SMB over QUIC: Mount File Share over Internet...

December 24, 2025

Security Warnings When Opening RDP Files in Windows...

April 20, 2026

Monitor Windows Log Files in Real Time with...

March 26, 2026

Automate Software and Settings Deployment with WinGet Configure...

August 24, 2026

CrowdSec on Windows: From Installation to Threat Blocking

July 6, 2026

Remove the Max Path Length Limit (260-Characters) on...

November 19, 2025

Updating UEFI Secure Boot Certificates on Windows Devices...

April 27, 2026

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • How to Set Task Priority in Windows Task Scheduler

    September 22, 2026
  • AutoStart Program at RDP Logon in Windows RDS

    September 8, 2026
  • How to Convert Windows Machine into a Proxmox VM

    August 30, 2026
  • Enable or Disable Fast User Switching in Windows 11

    August 18, 2026
  • How to Hide Wi-Fi Network in Windows with WLAN Filters (Blacklist and Whitelist)

    August 14, 2026
  • Invalid Signature Detected: Check Secure Boot Policy [Fix]

    August 5, 2026
  • Windows Installer Service Could Not Be Accessed? How to Fix It

    July 28, 2026
  • Why Windows Reports No Internet Access: How Connectivity Detection Works

    July 26, 2026
  • Inactive TS Ports in Windows: Causes and Fixes

    July 20, 2026
  • Add Wireless Wi-Fi Profiles on Windows Devices via Export/Import or GPO

    July 13, 2026

Follow us

  • Facebook
  • Twitter
  • Youtube
  • Telegram
Popular Posts
  • Converting Windows 10 to Enterprise LTSC Without Losing Data
  • How to Remove ‘Some Settings are Managed by Your Organization’ on Windows 11 or 10
  • Remove the Max Path Length Limit (260-Characters) on Windows
  • Installing Windows without USB/DVD or Other External Drives
  • How to Pause (Delay) Update Installation on Windows 11 and 10
  • Run an External Program (Command) with Args from PowerShell
  • Fix: Can’t Open a Downloaded Word/Excel File
Footer Logo

@2014 - 2026 - Windows OS Hub. All about operating systems for sysadmins


Back To Top