How to Block Untrusted Fonts in Windows 11
Blocking untrusted fonts in Windows 11 stops malicious font files from running hidden code and breaking into your system. Windows 11 includes a built-in security feature that blocks these unsafe files from loading outside of your system folders.
You can set this feature to either warn you when a bad font tries to open or block it completely so your PC stays safe. This protection helps stop cyber attackers from using fake font files downloaded from the internet to compromise Windows 11.
You can block untrusted fonts in Windows 11 by using the Local Group Policy Editor or Registry Editor. Navigate to Computer Configuration Administrative Templates System Mitigation Options in the Group Policy Editor and enable “Untrusted Font Blocking.” Alternatively, use the Registry Editor to create or modify the “MitigationOptions_FontBlocking” DWORD value.
What Are Fonts and Untrusted Fonts?
Typography styles define how text appears on screen. Untrusted fonts originate outside the official Windows directory, frequently hiding on unverified third-party websites.
Loading unverified typefaces from external locations can compromise operating system stability and open security vulnerabilities.

Why Block Untrusted Fonts?
Attackers sometimes hide harmful code inside font files to run it on your PC. Windows 11 includes a native protection mechanism called Blocking Untrusted Fonts that intercepts these files before they execute.
How to Control Untrusted Fonts in 🪟 Windows 11
You can control untrusted fonts in Windows 11 by choosing between blocking unsafe typefaces or just logging when apps try to load them. The On setting blocks unsafe fonts and records attempts to use them, while the Audit setting only logs these attempts without blocking execution. This helps protect your PC from bad files hiding in custom fonts.
- On – Blocks unsafe fonts from loading outside the trusted font folder and records these events.
- Audit – Does not block fonts but keeps a log of apps that use untrusted fonts.
- Exclude apps – Lets you allow certain apps to use untrusted fonts, even if blocking is on.
Method 1Use the Local Group Policy Editor
You can block untrusted fonts using the Local Group Policy Editor in Windows 11 Pro and Enterprise editions. Press the Windows key plus R, type gpedit.msc, and press Enter to open the editor. Then go to Computer Configuration, Administrative Templates, System, and Mitigation Options to turn on the font blocking setting.
- Press Windows key + R, type
gpedit.msc, and press Enter to open the Local Group Policy Editor. (If you don't know how to open it, see this guide: How to open Local Group Policy Editor) - In the editor, go to:
Computer Configuration > Administrative Templates > System > Mitigation Options - On the right side, find and double-click
Untrusted Font Blocking. - Choose one of these options:
- Not Configured (default) – No fonts are blocked.
- Enabled – Blocks untrusted fonts and logs events.
- Disabled – Same as Not Configured, no fonts are blocked.
- Click OK to save your changes and close the window.

Method 2Use the Windows Registry Editor
You can block untrusted fonts using the Registry Editor if you use Windows 11 Home, which lacks the Group Policy Editor. Press the Windows key plus R, type regedit, and press Enter to open the editor with admin privileges. Then go to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\MitigationOptions to change the registry value.
- ⚠️ Requires admin privileges – Press Windows key + R, type
regedit, and press Enter to open the Registry Editor. (If you need help, see: How to open Windows Registry Editor) - In Registry Editor, go to this folder:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\MitigationOptions - If you don't see the MitigationOptions folder, right-click
Windows NT, selectNew > Key, and name itMitigationOptions. - Right-click on the right side of the MitigationOptions folder and select
New > DWORD (32-bit) Value. - Name this new value:
MitigationOptions_FontBlocking - Double-click this new value to edit it. Set the base to Hexadecimal and use one of these values:
1000000000000– Turn on blocking.2000000000000– Turn off blocking.3000000000000– Audit only (log events, don't block).
- Click OK and close the Registry Editor.
- Restart your computer for the changes to take effect.

Summary
- Blocking untrusted fonts helps protect your Windows 11 PC from harmful files.
- You can control this setting using either the Local Group Policy Editor or the Registry Editor.
- Choose to block, audit, or allow untrusted fonts based on your needs.
- Remember to restart your PC after making changes.
- If you want to learn more about fonts on Windows 11, check out this easy guide on how to install fonts in Windows 11.
Blocking untrusted fonts on Windows 11 helps protect your PC from harmful files by stopping unsafe typefaces from loading into memory. You can turn on this security feature using either the Local Group Policy Editor or the Registry Editor, depending on your Windows edition. Remember to restart your computer after you finish making changes.
Microsoft - Block Untrusted Fonts
Leave a comment below to share feedback or ask questions about the configuration process.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!