Lock 7-Zip File Associations via Group Policy

While 7-Zip does not provide its own proprietary administrative policy templates (ADMX files), administrators can effectively lock down 7-Zip file associations across an enterprise using native Windows Group Policy templates. By leveraging the built-in Windows File Explorer administrative templates and a customized application association XML file, system administrators can enforce 7-Zip as the default handler for formats like .7z, .zip, and .rar, preventing end users from permanently changing these defaults.

Native 7-Zip Limitations

7-Zip is a standalone utility that does not ship with official Group Policy Administrative Templates (.admx or .adml). Inside the application interface, file associations are managed locally under Tools > Options, which writes to standard registry paths. However, since Windows 10 and Windows 11 enforce hash-protected User Choice registry keys, simply pushing registry values via Group Policy Preferences often results in Windows resetting the defaults to File Explorer.

The Supported Group Policy Solution

The standard, Microsoft-supported method to enforce 7-Zip file associations is using the Set a default associations configuration file policy provided in the standard Windows Administrative Templates.

Step 1: Export a Baseline Association File

  1. On a reference machine, install 7-Zip.
  2. Manually associate the desired extensions (such as .7z, .zip, .tar, .gz) with 7-Zip using Windows Settings or the 7-Zip interface.
  3. Open an elevated Command Prompt and export the configuration by running:
    dism /online /Export-DefaultAppAssociations:C:\Temp\AppAssoc.xml

Step 2: Clean and Edit the XML File

Open AppAssoc.xml in a text editor and remove all entries except the ones designated for 7-Zip. This prevents the policy from overwriting non-archive associations (like web browsers or PDF readers).

A focused configuration will look similar to this:

<?xml version="1.0" encoding="UTF-8"?>
<DefaultAssociations>
  <Association Identifier=".7z" ProgId="7-Zip.7z" ApplicationName="7-Zip File Manager" />
  <Association Identifier=".zip" ProgId="7-Zip.zip" ApplicationName="7-Zip File Manager" />
  <Association Identifier=".tar" ProgId="7-Zip.tar" ApplicationName="7-Zip File Manager" />
  <Association Identifier=".rar" ProgId="7-Zip.rar" ApplicationName="7-Zip File Manager" />
</DefaultAssociations>

Save this file to a read-only central share (e.g., \\domain\sysvol\domain\Policies\AppAssoc.xml) or copy it locally to targeted client machines via standard deployment tools.

Step 3: Apply the Administrative Policy

  1. Open the Group Policy Management Console (GPMC).
  2. Create or edit an existing Group Policy Object (GPO) linked to the target Organizational Unit (OU).
  3. Navigate to: Computer Configuration > Policies > Administrative Templates > Windows Components > File Explorer
  4. Locate and open the policy setting: Set a default associations configuration file.
  5. Set the policy to Enabled.
  6. Under Options, provide the path to the association XML file (either a local path like C:\Windows\System32\AppAssoc.xml or a UNC path).
  7. Apply the changes and close the editor.

Enforcement Behavior

Once the GPO is applied and gpupdate /force is run on client systems, the policy reads the XML file during user logon.

In Windows environments:

  • The specified archive formats are assigned to 7-Zip automatically.
  • While a user might change the default app temporarily during a single session, the policy reapplies the XML mapping on every subsequent logon, effectively locking down the file associations to organizational standards.