diff --git a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs
index 39b7b0962f..02cad71a97 100644
--- a/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs
+++ b/src/System.Management.Automation/engine/remoting/commands/EnterPSHostProcessCommand.cs
@@ -2,16 +2,18 @@
// Licensed under the MIT License.
using System;
-using System.Diagnostics;
using System.Collections.Generic;
using System.Collections.ObjectModel;
+using System.Diagnostics;
+using System.Diagnostics.CodeAnalysis;
using System.Globalization;
using System.Management.Automation;
using System.Management.Automation.Host;
using System.Management.Automation.Internal;
-using System.Management.Automation.Runspaces;
using System.Management.Automation.Remoting;
-using System.Diagnostics.CodeAnalysis;
+using System.Management.Automation.Runspaces;
+using System.Management.Automation.Security;
+using System.Text;
namespace Microsoft.PowerShell.Commands
{
@@ -113,6 +115,19 @@ namespace Microsoft.PowerShell.Commands
///
protected override void EndProcessing()
{
+ // Check if system is in locked down mode, in which case this cmdlet is disabled.
+ if (SystemPolicy.GetSystemLockdownPolicy() == SystemEnforcementMode.Enforce)
+ {
+ WriteError(
+ new ErrorRecord(
+ new PSSecurityException(RemotingErrorIdStrings.EnterPSHostProcessCmdletDisabled),
+ "EnterPSHostProcessCmdletDisabled",
+ ErrorCategory.SecurityError,
+ null));
+
+ return;
+ }
+
// Check for host that supports interactive remote sessions.
_interactiveHost = this.Host as IHostSupportsInteractiveSession;
if (_interactiveHost == null)
diff --git a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx
index bd712339b7..9ad52f6743 100644
--- a/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx
+++ b/src/System.Management.Automation/resources/RemotingErrorIdStrings.resx
@@ -1667,4 +1667,7 @@ All WinRM sessions connected to PowerShell session configurations, such as Micro
Information about the process could not be read: '{0}'.
+
+ Enter-PSHostProcess cmdlet is disabled because an application control policy such as 'AppLocker' or 'Windows Defender Application Control' is in enforcement.
+
diff --git a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1 b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1
index a09e22492d..09293bd695 100644
--- a/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1
+++ b/test/powershell/Modules/Microsoft.PowerShell.Security/ConstrainedLanguageRestriction.Tests.ps1
@@ -1164,6 +1164,31 @@ try
}
}
+ Describe "Enter-PSHostProcess cmdlet should be disabled on locked down systems" -Tags 'Feature','RequireAdminOnWindows' {
+
+ It "Verifies that Enter-PSHostProcess is disabled with lock down policy" {
+
+ $expectedError = $null
+ try
+ {
+ Invoke-LanguageModeTestingSupportCmdlet -SetLockdownMode
+ $ExecutionContext.SessionState.LanguageMode = "ConstrainedLanguage"
+
+ Enter-PSHostProcess -Id 5555 -ErrorAction Stop
+ }
+ catch
+ {
+ $expectedError = $_
+ }
+ finally
+ {
+ Invoke-LanguageModeTestingSupportCmdlet -RevertLockdownMode -EnableFullLanguageMode
+ }
+
+ $expectedError.FullyQualifiedErrorId | Should -BeExactly 'EnterPSHostProcessCmdletDisabled,Microsoft.PowerShell.Commands.EnterPSHostProcessCommand'
+ }
+ }
+
# End Describe blocks
}
finally