The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
Hi @Anonymous
Thank you for posting your question in Microsoft Q&A.
As your description, the issue “blocked by software restriction policies” is not related to PowerShell’s execution policy. Your current execution policy (RemoteSigned at LocalMachine) correctly allows local scripts.
Based on my research, this issue typically points to Software Restriction Policies (SRP) configured via Group Policy or Local Security Policy. SRP is a separate Windows security feature from PowerShell execution policy and can block scripts based on path rules, hash rules, or other criteria, even if PowerShell’s execution policy is permissive.
If possible, could you try to:
Check for Active SRP on the Server
Run this on the Exchange server:
gpresult /h c:\gpresult.html
Open the HTML file and search for "Software Restriction Policies". Look under Computer Settings > Security Settings to see if any SRP is applied and what rules exist.
Alternatively, open Local Security Policy (secpol.msc) and navigate to Security Settings > Software Restriction Policies.
If the node exists but no rules are shown, SRP should not block scripts unless a default disallow rule is configured.
Create Explicit Allow Rules
In Group Policy Management Console (or local secpol.msc if local policy):
Navigate to Computer Configuration > Policies > Windows Settings > Security Settings > Software Restriction Policies > Additional Rules.
Right-click > New Path Rule.
Add these paths one by one, setting Security Level to Unrestricted:
C:\Program Files\Microsoft\Exchange Server\V15\bin\RemoteExchange.ps1
C:\Program Files\Microsoft\Exchange Server\V15\bin\CommonConnectFunctions.ps1
C:\Program Files\Microsoft\Exchange Server\V15\bin\*.ps1
C:\Program Files\Microsoft\Exchange Server\V15\bin\*.ps1xml (for the type files)
Or broader: C:\Program Files\Microsoft\Exchange Server\V15\bin* (allows everything in the bin folder)
Apply the GPO to the Exchange server OU, run gpupdate /force, and reboot or restart the shell.
Check for Zone Blocking
If Exchange files were copied/downloaded (for example, during patching), they may have a Zone.Identifier marking them as internet-sourced.
Run this command as admin:
Get-Item "C:\Program Files\Microsoft\Exchange Server\V15\bin\*" -Stream *
Look for Zone.Identifier streams on .ps1 or .ps1xml files.
If present, unblock via:
Unblock-File -Path "C:\Program Files\Microsoft\Exchange Server\V15\bin\*.ps1"
Unblock-File -Path "C:\Program Files\Microsoft\Exchange Server\V15\bin\*.ps1xml"
After applying allow rules and unblocking files, restart the server (or at least IIS/PowerShell sessions) and test the Exchange Management Shell again.
References: Troubleshoot software restriction policies - Windows Server | Microsoft Learn
Please note that this summary is based on my own findings and may not fully address your concerns. To help you reach your goal more effectively, I recommend engaging with tech community forumsfor a deeper technical dive or to connect with individuals who have relevant experience and expertise. Some approaches may behave differently or be restricted depending on your specific environment and configuration. These forums include many experienced developers and Microsoft specialists who can assist with troubleshooting and guidance.
Apologies for redirecting you to the related development team support. As moderators in this community, we do not have access to your specific tenant configuration, and my testing environment is limited. Therefore, my guidance is based on available Microsoft documentation and resources. That said, I’ll do my best to provide additional insight where possible.
If you have any additional concerns, feel free to comment below. I would be more than happy to assist.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.