How to Manage 7-Zip Configuration with GPO

Managing 7-Zip settings across an enterprise network can be streamlined using Active Directory Group Policy Objects (GPO). While 7-Zip does not natively include pre-built Administrative Templates (.admx files), administrators can centrally enforce configuration settings, context menus, and file associations by targeting 7-Zip's registry keys through Group Policy Preferences (GPP) or deploying default application association XML files. This guide details how to locate these configuration parameters and deploy them domain-wide.

Understanding 7-Zip Registry Architecture

7-Zip stores its configuration parameters primarily within the Windows Registry rather than standalone configuration files. Settings are divided into two main scopes:

  • User Preferences: Stored under HKEY_CURRENT_USER\Software\7-Zip. This path controls the File Manager interface, options, language, and context menu behaviors.
  • System and Shell Integrations: Stored under HKEY_LOCAL_MACHINE\Software\7-Zip or within the root file extension handlers in HKEY_CLASSES_ROOT.

Step 1: Capture the Desired Settings

The most reliable way to obtain the precise values you want to push via GPO is to configure a single reference machine manually:

  1. Open 7-Zip File Manager as an administrator.
  2. Navigate to Tools > Options.
  3. Configure your desired options (e.g., enable the cascading context menu, specify context menu items, or set memory limits).
  4. Open the Windows Registry Editor (regedit.exe) and navigate to HKEY_CURRENT_USER\Software\7-Zip.
  5. Identify the keys you modified:
    • CascadedMenu (DWORD): Controls whether the Windows context menu collapses 7-Zip items into a single sub-menu (1 for enabled, 0 for disabled).
    • ContextMenu (DWORD): A bitmask determining which specific operations appear in the shell menu (such as "Extract here", "Add to archive", or "Test").
    • Path (String): Stored under the FM subkey to control default file navigation.

Step 2: Configure Group Policy Preferences

Once you have identified the registry values, deploy them across your domain using Group Policy Preferences.

  1. Open the Group Policy Management Console (gpmc.msc) on a Domain Controller or management workstation.
  2. Create a new GPO (e.g., "7-Zip Configuration Policy") or edit an existing policy linked to the target Organizational Unit (OU).
  3. If managing user-level settings, expand:
    • User Configuration > Preferences > Windows Settings > Registry
  4. Right-click Registry, select New, and click Registry Item.
  5. Configure the properties for each setting:
    • Action: Select Update (this applies the setting without overwriting the entire key).
    • Hive: Select HKEY_CURRENT_USER.
    • Key Path: Enter Software\7-Zip\FM (or Software\7-Zip depending on the value).
    • Value name: Enter the target value name (e.g., CascadedMenu).
    • Value type: Select the appropriate data type (e.g., REG_DWORD).
    • Value data: Enter the desired value (e.g., 1).
  6. Click Apply and then OK. Repeat this process for any additional registry keys.

Step 3: Manage 7-Zip File Associations

In modern versions of Windows, file associations cannot be set reliably via standard registry writes alone due to Windows User Choice Hash protections. To enforce 7-Zip as the default handler for formats like .7z, .zip, and .rar, deploy a Default Application Association XML file:

  1. On your reference PC, set 7-Zip as the default application for the chosen extensions via Windows Settings > Apps > Default apps.
  2. Open PowerShell as an administrator and export the current association configuration:
    Dism.exe /Online /Export-DefaultAppAssociations:C:\Temp\AppAssoc.xml
  3. Open AppAssoc.xml in a text editor and remove all entries except the file types you want 7-Zip to handle (e.g., .7z, .zip, .tar, .gz).
  4. Save the pruned file to a network share that is readable by all domain computers (e.g., \\yourdomain.com\NETLOGON\AppAssoc.xml).
  5. In your GPO, navigate to:
    • Computer Configuration > Administrative Templates > Windows Components > File Explorer
  6. Double-click Set a default associations configuration file.
  7. Set the policy to Enabled and enter the UNC path to your network-stored XML file.
  8. Click OK.

Step 4: Verification and Deployment

  1. On a target client workstation within the target OU, open Command Prompt as an administrator and force a policy update:
    gpupdate /force
  2. Log out and log back into the client workstation to allow the user policies and default application associations to apply.
  3. Open the Registry Editor to ensure the keys have appeared under HKEY_CURRENT_USER\Software\7-Zip.
  4. Right-click a supported archive file to confirm that the context menu and associations match your configured policies.