Lock 7-Zip File Associations via Group Policy
While 7-Zip does not provide its own proprietary administrative
policy templates (ADMX files), administrators can effectively lock down
7-Zip file associations across an enterprise using native Windows Group
Policy templates. By leveraging the built-in Windows File Explorer
administrative templates and a customized application association XML
file, system administrators can enforce 7-Zip as the default handler for
formats like .7z, .zip, and .rar,
preventing end users from permanently changing these defaults.
Native 7-Zip Limitations
7-Zip is a standalone utility that does not ship with official Group
Policy Administrative Templates (.admx or
.adml). Inside the application interface, file associations
are managed locally under Tools > Options, which
writes to standard registry paths. However, since Windows 10 and Windows
11 enforce hash-protected User Choice registry keys, simply pushing
registry values via Group Policy Preferences often results in Windows
resetting the defaults to File Explorer.
The Supported Group Policy Solution
The standard, Microsoft-supported method to enforce 7-Zip file associations is using the Set a default associations configuration file policy provided in the standard Windows Administrative Templates.
Step 1: Export a Baseline Association File
- On a reference machine, install 7-Zip.
- Manually associate the desired extensions (such as
.7z,.zip,.tar,.gz) with 7-Zip using Windows Settings or the 7-Zip interface. - Open an elevated Command Prompt and export the configuration by
running:
dism /online /Export-DefaultAppAssociations:C:\Temp\AppAssoc.xml
Step 2: Clean and Edit the XML File
Open AppAssoc.xml in a text editor and remove all
entries except the ones designated for 7-Zip. This prevents the policy
from overwriting non-archive associations (like web browsers or PDF
readers).
A focused configuration will look similar to this:
<?xml version="1.0" encoding="UTF-8"?>
<DefaultAssociations>
<Association Identifier=".7z" ProgId="7-Zip.7z" ApplicationName="7-Zip File Manager" />
<Association Identifier=".zip" ProgId="7-Zip.zip" ApplicationName="7-Zip File Manager" />
<Association Identifier=".tar" ProgId="7-Zip.tar" ApplicationName="7-Zip File Manager" />
<Association Identifier=".rar" ProgId="7-Zip.rar" ApplicationName="7-Zip File Manager" />
</DefaultAssociations>Save this file to a read-only central share (e.g.,
\\domain\sysvol\domain\Policies\AppAssoc.xml) or copy it
locally to targeted client machines via standard deployment tools.
Step 3: Apply the Administrative Policy
- Open the Group Policy Management Console (GPMC).
- Create or edit an existing Group Policy Object (GPO) linked to the target Organizational Unit (OU).
- Navigate to:
Computer Configuration > Policies > Administrative Templates > Windows Components > File Explorer - Locate and open the policy setting: Set a default associations configuration file.
- Set the policy to Enabled.
- Under Options, provide the path to the association
XML file (either a local path like
C:\Windows\System32\AppAssoc.xmlor a UNC path). - Apply the changes and close the editor.
Enforcement Behavior
Once the GPO is applied and gpupdate /force is run on
client systems, the policy reads the XML file during user logon.
In Windows environments:
- The specified archive formats are assigned to 7-Zip automatically.
- While a user might change the default app temporarily during a single session, the policy reapplies the XML mapping on every subsequent logon, effectively locking down the file associations to organizational standards.